Back to skill

Security audit

Didichuxing

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Didi travel and enterprise API guide, with no hidden execution, persistence, or unrelated data handling found.

Before installing, treat this as guidance and example code. Do not paste real client secrets, employee phone numbers, trip locations, or billing data into any API workflow unless your organization has authorized Didi Enterprise access and you have reviewed the API behavior.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The natural-language instructions, headings, examples, and assistant persona are overwhelmingly specified in Chinese, and the file does not state that users may interact in other languages or choose their preferred locale. Under the policy for language/locale constraints, this is a violation unless the skill offers opt-in choice or clearly documents a justified region-specific limitation.

External Transmission

Medium
Category
Data Exfiltration
Content
"car_type": car_type,  # 1=快车, 2=专车, 3=豪华车
            "city": "北京"
        }
        return requests.post(url, headers=headers, json=payload).json()

    def get_bill_list(self, start_date: str, end_date: str,
                      department_id: str = None) -> dict:
Confidence
70% confidence
Finding
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Static analysis

No suspicious patterns detected.