T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/jst_erp.mjs:120- Finding
ERP API calls do not enforce recorded user consent
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This ERP skill is mostly purpose-aligned, but it stores and uses sensitive ERP credentials through a broad API caller without enforcing its own consent and endpoint limits in code.
Install only if you are comfortable storing Jushuitan ERP credentials locally and letting the skill make authenticated API calls. Use least-privileged, read-only ERP tokens where possible, avoid passing secrets in shell commands, review profiles.json handling, and prefer a version that enforces consent and an endpoint allowlist in code.
scripts/jst_erp.mjs:120ERP API calls do not enforce recorded user consent
scripts/jst_erp.mjs:52Caller-controlled API paths allow access beyond the documented read-only scope
scripts/jst_erp.mjs:94Secrets are accepted through exposed command-line arguments
Referenced artifact was not completely inspected
- 保存方式:使用文件写入工具(如 `create_file` 或 `file_replace`),在当前 skill 根目录下创建或更新 `profiles.json` 文件。文件路径为 `<skill_root>/profiles.json`,skill 根目录即本 `SKILL.md` 所在的目录。
Referenced artifact was not completely inspected
- agent 可以直接运行 `scripts/jst_erp.mjs public-ip` 获取并告诉用户。
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
app_secret: args["app-secret"],
access_token: args["access-token"],
refresh_token: args["refresh-token"] || profiles[name]?.refresh_token || "",
env: args.env || profiles[name]?.env || "prod",
updated_at: new Date().toISOString(),
};
saveProfiles(profiles);
The skill instructs the agent to perform network-relevant actions such as retrieving the public IP and accessing external ERP services, but it declares no explicit tool scope or allowed-tools boundary. This creates a least-privilege violation: an agent runtime may permit broader tool or network use than users expect, increasing the chance of unintended outbound access, data exfiltration, or unsafe execution paths involving sensitive ERP credentials.
The skill enables implicit invocation without any stated trigger constraints, exclusions, or user-confirmation boundaries. Because this skill handles ERP connectivity and merchant operational analysis, automatic invocation could expose or act on sensitive business data in contexts where the user did not clearly intend to use this integration.
The file’s instructions, examples, and expected outputs are entirely Chinese-language, which effectively forces a specific language/locale for skill operation. The policy allows this only when the skill offers user choice or clearly documents a justified regional constraint, neither of which appears here.
The callApi function sends access_token, app_key, signature material, and biz data to remote Jushuitan API endpoints via HTTP POST. The code performs this transmission without a user-facing warning, confirmation, or inline disclosure near the call path, so users may not realize potentially sensitive business data is being sent off-host.
The public-ip command performs an external request to api.ipify.org that is unrelated to the stated ERP data connection and analysis purpose. Unrelated network-capable features expand the attack surface, disclose environmental metadata, and can be repurposed for reconnaissance in environments where users expect only ERP operations.
The script stores app_key, app_secret, access_token, and potentially refresh_token in a local profiles.json file without any explicit disclosure or consent flow warning users that long-lived credentials will persist on disk. Even with restrictive file permissions, local persistence raises exposure risk from backups, shared environments, compromised accounts, or accidental inclusion in the skill directory.
The generic call command accepts arbitrary --path values and forwards authenticated requests using stored JuShuiTan credentials, enabling access well beyond the narrowly described analysis scenarios. In skill context, this effectively turns the tool into a broad API proxy, increasing the chance of unauthorized or overly broad data access, state changes, or misuse of merchant credentials.
Detected: suspicious.exposed_secret_literal