Back to skill

Security audit

Didichuxing

Security checks across malware telemetry and agentic risk

Overview

This is a ride-hailing guidance skill with disclosed enterprise API examples, and no evidence of hidden execution, persistence, destructive behavior, or data exfiltration.

Before using the enterprise API examples, confirm your organization is authorized for DiDi Enterprise API access, store client secrets in a proper secrets manager, avoid logging phone numbers, locations, tokens, and billing data, and apply consent, retention, and regional privacy requirements. For personal travel advice and fare estimation, the skill is proportionate to its purpose.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The skill includes enterprise API examples that handle client credentials, employee phone numbers, location data, and billing queries, but the surrounding documentation does not warn about privacy, data minimization, consent, retention, or secure handling obligations. In an agent-skill context, users may copy this pattern directly into production workflows and transmit employee personal and trip data to external services without adequate legal or security controls.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.