Back to skill

Security audit

错敏信息检测

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent sensitive-information checking purpose, but its URL-fetching path has material SSRF containment gaps that warrant review before installation.

Install only after reviewing whether the runtime has access to internal networks or cloud metadata services. Avoid URL scanning in privileged or private-network environments unless outbound egress is sandboxed, and treat all scanned text or fetched page content as sent to UCAP. Pin dependencies and avoid enabling browser mode without strong network isolation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
ucap-sensitive-check-skill/main.py:327
Finding

Automatic Redirect Handling and DNS TOCTOU Permit SSRF

Content
View full analysis
list: """ Convert a hostname into a list of IP addresses. """ results = [] if HAS_DNSPYTHON: for rtype in ("A", "AAAA"): try: answers = dns.resolver.resolve(hostname, rtype, lifetime=5) for rdata in answers: try: results.append(ipaddress.ip_address(str(rdata))) except ValueError: pass except Exception: pass else: try: infos = socket.getaddrinfo(hostname, None, socket.AF_UNSPEC, socket.SOCK_STREAM, 0, socket.AI_ADDRCONFIG) for info in infos: addr = info[4][0] try: results.append(ipaddress.ip_address(addr)) except ValueError: pass except Exception: pass return results ``` ```python response = requests.get(url, headers=headers, timeout=15, verify=True, allow_redirects=True) response.raise_for_status() # Validate again after redirects final_url = response.url if final_url != url: is_safe2, err2 = validate_url_security(final_url) if not is_safe2: return {"code": -100, "message": f"Page redirect security check failed: {err2}", "data": None} ``` ### Technical Analysis The initial URL is resolved and checked before the HTTP request. However, `requests.get()` is invoked with `allow_redirects=True`, so the library follows redirects before the final URL is validated. If a public HTTPS endpoint returns a redirect to a priv ...[truncated 2055 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
ucap-sensitive-check-skill/main.py:392
Finding

Browser Mode Whitelist Does Not Restrict Page-Initiated Subrequests

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
ucap-sensitive-check-skill/requirements.txt:1
Finding

Unpinned and Unverified Third-Party Dependencies Create Supply-Chain Risk

Content
View full analysis
=2.31.0 dnspython>=2.4.0 beautifulsoup4>=4.12.0 ``` The documentation also instructs users to install an unversioned global npm package: ```bash npm install -g agent-browser ``` ### Technical Analysis The Python dependency constraints specify only minimum versions. Consequently, future installations may retrieve releases that were not reviewed as part of this audit. No lock file or cryptographic hashes are present to bind installation to known artifacts. The browser dependency is installed globally without a version. A mutable npm release or compromised transitive dependency could execute lifecycle scripts during installation. Global installation can increase impact when the command is run with elevated privileges. There is no evidence that the currently named packages are malicious. The confirmed issue is the lack of reproducibility and integrity controls, which unnecessarily expands exposure to future upstream compromise, registry account takeover, or malicious transitive dependency updates. ### Attack Path 1. A direct or transitive dependency is compromised upstream, or a maintainer publishes a malicious future release. 2. A user follows the documented installation process. 3. The package manager selects the latest version satisfying the open-ended constraint or the latest `agent-browser` release. 4. Package installation or runtime imports execute the newly retrieved code. 5. The malicious dependency operates with the privileges and network access of the installer or Skill process. ### Impact Assessment A compromised dependency could execute arbitrary code, access environment variables such as `UCAP_USERKEY`, read files available to the process, al ...[truncated 365 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (21)

Cloud Metadata Access

High
Category
Server-Side Request Forgery
Confidence
90% confidence
Finding

Code accesses a cloud instance metadata endpoint (e.g. 169.254.169.254). A single request can return temporary IAM credentials, making this a high-value SSRF target for credential theft.

Content

Scanner excerpt · skill.md (reported line 49)May include surrounding context.

md
| 协议校验 | 默认仅允许 HTTPS,拒绝 http / ftp / file 等协议 |
| 主机名预检 | 拒绝直接以私有 IP 写入的 URL |
| **DNS 解析后 IP 检查** | 对域名进行 DNS 解析,检查所有 IP 是否为私有/保留网段 |
| 云元数据屏蔽 | 屏蔽 169.254.169.254、metadata.google.internal 等云平台元数据地址 |
| 重定向后校验 | 对页面最终落地 URL 重新执行完整安全检查 |

### ⚠️ 动态模式安全风险(需要显式启用 + 强制白名单)

Cloud Metadata Access

High
Category
Server-Side Request Forgery
Confidence
90% confidence
Finding

Code accesses a cloud instance metadata endpoint (e.g. 169.254.169.254). A single request can return temporary IAM credentials, making this a high-value SSRF target for credential theft.

Content

Scanner excerpt · ucap-sensitive-check-skill/main.py (reported line 96)May include surrounding context.

python
| 协议校验 | 默认仅允许 HTTPS,拒绝 http / ftp / file 等协议 |
| 主机名预检 | 拒绝直接以私有 IP 写入的 URL |
| **DNS 解析后 IP 检查** | 对域名进行 DNS 解析,检查所有 IP 是否为私有/保留网段 |
| 云元数据屏蔽 | 屏蔽 169.254.169.254、metadata.google.internal 等云平台元数据地址 |
| 重定向后校验 | 对页面最终落地 URL 重新执行完整安全检查 |

### ⚠️ 动态模式安全风险(需要显式启用 + 强制白名单)

Cloud Metadata Access

High
Category
Server-Side Request Forgery
Confidence
90% confidence
Finding

Code accesses a cloud instance metadata endpoint (e.g. 169.254.169.254). A single request can return temporary IAM credentials, making this a high-value SSRF target for credential theft.

Content

Scanner excerpt · skill.md (reported line 49)May include surrounding context.

md
| 协议校验 | 默认仅允许 HTTPS,拒绝 http / ftp / file 等协议 |
| 主机名预检 | 拒绝直接以私有 IP 写入的 URL |
| **DNS 解析后 IP 检查** | 对域名进行 DNS 解析,检查所有 IP 是否为私有/保留网段 |
| 云元数据屏蔽 | 屏蔽 169.254.169.254、metadata.google.internal 等云平台元数据地址 |
| 重定向后校验 | 对页面最终落地 URL 重新执行完整安全检查 |

### ⚠️ 动态模式安全风险(需要显式启用 + 强制白名单)

Cloud Metadata Access

High
Category
Server-Side Request Forgery
Confidence
90% confidence
Finding

Code accesses a cloud instance metadata endpoint (e.g. 169.254.169.254). A single request can return temporary IAM credentials, making this a high-value SSRF target for credential theft.

Content

Scanner excerpt · ucap-sensitive-check-skill/main.py (reported line 97)May include surrounding context.

python
| 协议校验 | 默认仅允许 HTTPS,拒绝 http / ftp / file 等协议 |
| 主机名预检 | 拒绝直接以私有 IP 写入的 URL |
| **DNS 解析后 IP 检查** | 对域名进行 DNS 解析,检查所有 IP 是否为私有/保留网段 |
| 云元数据屏蔽 | 屏蔽 169.254.169.254、metadata.google.internal 等云平台元数据地址 |
| 重定向后校验 | 对页面最终落地 URL 重新执行完整安全检查 |

### ⚠️ 动态模式安全风险(需要显式启用 + 强制白名单)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill title and all user-facing invocation examples are presented only in Chinese, and there is no indication that users may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Internal Network Request

Medium
Category
Server-Side Request Forgery
Confidence
70% confidence
Finding

Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.

Content

Scanner excerpt · skill.md (reported line 62)May include surrounding context.

md
| 风险 | 说明 |
|------|------|
| 页面 JS 内网请求 | 恶意网页可能包含 `fetch("http://192.168.1.1/admin")` 等代码 |
| SSRF 绕过 | 虽然目标 URL 安全检查通过,但 JS 可能发起其他内网请求 |

**动态模式安全配置示例**:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill stores a credential-like userKey in the process environment for later reuse without an explicit warning at the call site. In shared runtimes, child processes, debugging tools, or co-located code may read inherited environment variables, increasing the chance of unintended credential exposure.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code comments claim browser mode is protected by whitelist enforcement, but the actual guard only checks whether ALLOWED_DOMAINS is non-empty and does not verify that the requested hostname is in that whitelist before opening it in the browser. In a skill that fetches attacker-controlled URLs and may execute page JavaScript, this creates a meaningful SSRF/network access gap despite the surrounding defensive language.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · ucap-sensitive-check-skill/main.py (reported line 460)May include surrounding context.

python
browser_opened = False
    try:
        # 1. 启动浏览器
        result = subprocess.run(
            ["agent-browser", "launch"],
            capture_output=True,
            text=True,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
89% confidence
Finding

This subprocess call opens a user-influenced URL in an external browser automation tool. Although it is not shell injection, it can trigger outbound requests and JavaScript execution in browser mode, and the whitelist control is incomplete because browser mode only checks that a whitelist exists, not that the target URL matches it at the point of use.

Content

Scanner excerpt · ucap-sensitive-check-skill/main.py (reported line 475)May include surrounding context.

python
browser_opened = True

        # 2. 打开目标 URL
        result = subprocess.run(
            ["agent-browser", "open", url],
            capture_output=True,
            text=True,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · ucap-sensitive-check-skill/main.py (reported line 492)May include surrounding context.

python
_time.sleep(wait_time)

        # 4. 获取页面内容
        result = subprocess.run(
            ["agent-browser", "snapshot"],
            capture_output=True,
            text=True,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · ucap-sensitive-check-skill/main.py (reported line 509)May include surrounding context.

python
final_url = url  # agent-browser snapshot 不返回最终 URL,这里简化处理

        # ── 二次检查:页面重定向后的最终 URL ──────────────────────────
        result = subprocess.run(
            ["agent-browser", "evaluate", "window.location.href"],
            capture_output=True,
            text=True,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · ucap-sensitive-check-skill/main.py (reported line 551)May include surrounding context.

python
finally:
        if browser_opened:
            try:
                subprocess.run(
                    ["agent-browser", "close"],
                    capture_output=True,
                    text=True,

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

This request sends potentially sensitive user-provided or remotely fetched page content to an external network service. In this skill's context, the transmission is the primary business function, but it is still security-relevant because it can export secrets and internal data beyond the local trust boundary.

Content

Scanner excerpt · ucap-sensitive-check-skill/main.py (reported line 596)May include surrounding context.

python
if userKey:
            headers["userKey"] = userKey

        response = requests.post(
            url=url,
            headers=headers,
            json=request_data,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The function transmits supplied content, including content fetched from arbitrary URLs, to an external UCAP service without an explicit user-facing consent or disclosure at the execution point. In a sensitive-information scanning skill, that means potentially confidential internal documents, prompts, tokens, or personal data can be exfiltrated to a third party simply by invoking the skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

User-visible docstrings, return messages, and test output are written only in Chinese throughout the file, with no indication of language selection or opt-in. This can violate language/locale policy when a skill effectively constrains interaction to a single language without offering the user a choice.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The dependency is specified with a lower-bound version only (requests>=2.31.0), which makes builds non-reproducible and allows future installs to resolve to unexpected versions. This increases supply-chain risk and makes it impossible to verify whether deployed environments are using versions affected by known advisories.

Content

Scanner excerpt · ucap-sensitive-check-skill/requirements.txt (reported line 1)May include surrounding context.

text
requests>=2.31.0
dnspython>=2.4.0
beautifulsoup4>=4.12.0

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
92% confidence
Finding

requests has multiple known advisories, and because the manifest does not pin an exact version, there is no reliable way to determine whether the installed package is a fixed or vulnerable release. In a network-capable skill, uncertainty around the HTTP client version is more concerning because flaws in request handling, redirect behavior, or credential exposure could affect real outbound traffic.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The dependency is not strictly pinned (dnspython>=2.4.0), so installations may pull different versions over time. This weakens reproducibility and complicates assurance that only reviewed, non-vulnerable releases are installed.

Content

Scanner excerpt · ucap-sensitive-check-skill/requirements.txt (reported line 2)May include surrounding context.

text
requests>=2.31.0
dnspython>=2.4.0
beautifulsoup4>=4.12.0

Unverifiable Dependency: dnspython has 2 known advisory(ies) (CVE-2023-29483 (Potential DoS via the Tudoor mechanism in eventlet and dnspython); CVE-2023-29483 (Potential DoS via the Tudoor mechanism in eventlet and dnspython)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
90% confidence
Finding

dnspython has known advisories, and the unpinned requirement prevents verification that the runtime version includes the necessary fixes. Given this skill appears to perform network-related operations, uncertainty in DNS library behavior could increase exposure to denial-of-service or resolver-related issues.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

Using beautifulsoup4>=4.12.0 leaves the resolved version unconstrained above the minimum, creating a dependency integrity and change-management risk. While not an immediate exploit by itself, it can introduce vulnerable or incompatible versions without code changes.

Content

Scanner excerpt · ucap-sensitive-check-skill/requirements.txt (reported line 3)May include surrounding context.

text
requests>=2.31.0
dnspython>=2.4.0
beautifulsoup4>=4.12.0

Static analysis

No suspicious patterns detected.