Back to skill

Security audit

物流查询助手

Security checks for vulnerabilities and agentic risk

Overview

The skill tracks packages as advertised, but it unsafely asks users to paste an API key into chat and save it inside the skill file.

Review before installing. Use this only if you are comfortable sending tracking numbers to Track123, and do not paste an API key into chat or store it in SKILL.md; configure the key through a protected secret store or environment variable instead. Rotate any Track123 key that was already pasted into a conversation or written into the skill file.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:63
Finding

Track123 API Key Collected Through Chat and Persisted in Plaintext

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 63–65
Vulnerability Type: Plaintext credential storage and insecure secret handling
Risk Level: Medium

Relevant instruction, translated into English:

text
API Key configuration (required only for the first use)

If the curl command below still contains `$TRACK123_API_KEY`, ask the user
to visit https://www.track123.com/api, open Dashboard, select the API tab,
copy the key, and paste it here. After receiving it, replace
`$TRACK123_API_KEY` in this Skill file with the real key.

Technical Analysis

The Skill explicitly instructs the agent to ask the user to paste an API credential into the conversation and then replace the $TRACK123_API_KEY placeholder in SKILL.md with the actual secret.

This creates two insecure copies of the credential:

  1. The API key is exposed in conversation history and any associated telemetry or logs.
  2. The API key is permanently embedded in a plaintext project file.

Secrets stored in Skill instructions may subsequently be exposed through repository commits, backups, project archives, file-reading tools, diagnostic output, or later sessions with access to the same workspace. The issue is an insecure coding and configuration practice rather than evidence of an intentionally malicious credential-exfiltration mechanism.

Attack Path

  1. The Skill detects that $TRACK123_API_KEY has not been replaced.
  2. It asks the user to paste a valid Track123 API key into the conversation.
  3. The user provides the credential, causing it to enter conversation records and potentially platform logs.
  4. The agent writes the supplied key directly into SKILL.md.
  5. An attacker or unauthorized user obtains access to the project directory, repository history, backup, shared archive, conversation history, or diagnostic logs.
  6. The attacker extracts the plaintext API key and uses it to issue requests against the Track ...[truncated 833 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the instruction to paste the API key into the conversation or modify SKILL.md.
  2. Read TRACK123_API_KEY exclusively from a process environment variable or an approved secret manager at runtime.
  3. Configure the execution environment to inject the secret without exposing it to prompts, generated responses, command output, or source files.
  4. If a local configuration file is unavoidable, store it outside the Skill package, restrict its filesystem permissions, and exclude it from version control and project archives.
  5. Avoid printing curl commands with expanded credentials and ensure request headers are redacted from logs and error messages.
  6. Add automated secret scanning to repository and packaging workflows.
  7. Rotate any Track123 API key that has already been pasted into a conversation or written into the Skill file, and review API activity for unauthorized use.
  8. Apply the least privilege and lowest practical quota to the Track123 credential.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill explicitly tells the user to paste an API key into the conversation and then persist it by replacing a placeholder in the skill file. This is dangerous because secrets entered in chat may be logged, replayed, exposed to operators, or reused outside the user's intent, and the persistence step compounds the exposure.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs the agent to ask the user for an API key and then modify SKILL.md to persist that secret. Persisting user-supplied credentials in a skill file is unnecessary for package tracking, creates a durable secret-handling risk, and could expose the key to later users, logs, exports, or other tooling that can read the skill contents.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger definition is broad enough that ordinary package-related conversation or arbitrary number strings may invoke the skill unexpectedly. Unexpected activation can cause tracking numbers or surrounding context to be sent to third-party services without the user clearly intending to use this skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The example trigger phrases are everyday language like '到了吗' or '帮我查一下包裹' without scope limits, making accidental invocation likely. In this context, accidental invocation matters because the skill is designed to send tracking data to external services and potentially ask for credentials.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill sends tracking numbers and logistics data to an external API but provides no user-facing notice or consent flow. Tracking numbers and shipment events can reveal purchase behavior, addresses, locations, or timing information, so transmitting them externally without warning creates a privacy and data-governance risk.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill describes a one-time setup flow that changes the skill file during normal user interaction, which conflicts with the declared runtime behavior of answering tracking queries. This blurs trust boundaries between conversation data and code/configuration, increasing the chance of unsafe persistence of secrets or unintended modification of the skill definition.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

This instruction causes two forms of external exposure: the user is told to obtain and paste a secret, and the skill is set up to send that secret and tracking data to a third-party API. Because the secret is handled in-band and then persisted, compromise of chat logs or skill files could enable unauthorized API use and access to shipment data.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

API Key 配置(仅首次需要)

若下方 curl 命令中仍含 $TRACK123_API_KEY,请用户访问 https://www.track123.com/api → Dashboard → API 标签页 → 复制 Key 并粘贴到这里。收到后,将本 Skill 文件中的 $TRACK123_API_KEY 替换为真实 Key 值。

第一步 — 注册快递单号:

bash

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The import endpoint sends the tracking number to an external service, creating a real data-transmission surface. In a logistics skill this transmission is functionally relevant, but it is still a privacy-sensitive operation because tracking numbers can be linked to shipments, people, and delivery locations.

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

第一步 — 注册快递单号:

bash
curl -s -X POST "https://api.track123.com/gateway/open-api/tk/v2/track/import" \
  -H "Track123-Api-Secret: $TRACK123_API_KEY" \
  -H "accept: application/json" \
  -H "content-type: application/json" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The query endpoint also transmits tracking identifiers and retrieves detailed logistics events from an external provider. The skill context makes this expected, but not harmless: it still exposes potentially sensitive shipment metadata to a third party without any visible safeguards in the instructions.

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

第二步 — 查询物流状态:

bash
curl -s -X POST "https://api.track123.com/gateway/open-api/tk/v2/track/query" \
  -H "Track123-Api-Secret: $TRACK123_API_KEY" \
  -H "accept: application/json" \
  -H "content-type: application/json" \

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The entire skill description, triggers, and output instructions are presented only in Chinese, and the examples assume Chinese-language interaction. There is no opt-in for language choice or documentation that the skill is intentionally limited to Chinese-speaking users or a Chinese-only deployment context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.