Back to skill

Security audit

三剪客 · Chatbox 接入算力集市

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it says, but it explicitly offers to provide users with an API key through private contact, which conflicts with its own safer key-handling guidance.

Review before installing. Use only an API key you create yourself at the provider, set a low quota, and do not accept or share reusable keys through WeChat or private chat. If you run the verification or generator scripts, expect them to read your local A7W key and send authenticated requests to api.a7w.cn; the generator is designed not to embed the key in the Chatbox import link.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (57)

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly invites users to contact the author privately to obtain a working API key and example setup, which steers them away from the documented secure onboarding process. This creates a high-risk social-engineering path for credential sharing, unauthorized account use, and dependency on an untrusted intermediary for access to paid AI services.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Offering to directly provide users with an API key bypasses the provider's normal identity, billing, and audit controls and encourages unsafe credential handling outside the documented flow. Shared keys let the distributor monitor usage, revoke access, or shift billing and abuse risk onto unsuspecting users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README explicitly instructs users to run scripts that read an API key from local files or environment variables and send authenticated requests to api.a7w.cn, but it does not clearly warn that credentials and request metadata will be transmitted to a third-party service. In a security-sensitive skill, omitting that disclosure can cause users to run networked validation/config-generation steps without understanding the privacy and credential exposure implications.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill advertises and relies on capabilities such as environment variable access, file read/write, and network access via local scripts, but it does not declare any explicit tool scope or permissions boundaries. In an agent ecosystem, undeclared capabilities reduce transparency and can cause the host or user to grant broader access than intended, increasing the chance of credential exposure or unintended outbound requests.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document tells users not to use anyone else's API key and says the skill will not use or include shared keys, but later offers a 'working API key' via private contact. This contradiction undermines the documented security model and normalizes credential sharing, which can expose users to misuse, surveillance, billing fraud, or revocation of access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire skill document is written as Chinese-only operational guidance, including setup steps and warnings, with no indication that users may choose another language or that the scope is intentionally limited to Chinese-speaking users. Under the stated policy, a forced language/locale without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 14)May include surrounding context.

md
https://docs.chatboxai.app/en/guides/providers/import-config

关键点(已实测):Chatbox 的 apiPath 默认 `/v1/chat/completions`,
所以 apiHost 必须填到 `https://api.a7w.cn/api`。
填成 `https://api.a7w.cn/api/v1` 会双拼成 /api/v1/v1/chat/completions → 404。

只读调用 /v1/models 拉真实模型清单,不产生对话费用。"""

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 17)May include surrounding context.

md
https://docs.chatboxai.app/en/guides/providers/import-config

关键点(已实测):Chatbox 的 apiPath 默认 `/v1/chat/completions`,
所以 apiHost 必须填到 `https://api.a7w.cn/api`。
填成 `https://api.a7w.cn/api/v1` 会双拼成 /api/v1/v1/chat/completions → 404。

只读调用 /v1/models 拉真实模型清单,不产生对话费用。"""

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 28)May include surrounding context.

md
https://docs.chatboxai.app/en/guides/providers/import-config

关键点(已实测):Chatbox 的 apiPath 默认 `/v1/chat/completions`,
所以 apiHost 必须填到 `https://api.a7w.cn/api`。
填成 `https://api.a7w.cn/api/v1` 会双拼成 /api/v1/v1/chat/completions → 404。

只读调用 /v1/models 拉真实模型清单,不产生对话费用。"""

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 120)May include surrounding context.

md
https://docs.chatboxai.app/en/guides/providers/import-config

关键点(已实测):Chatbox 的 apiPath 默认 `/v1/chat/completions`,
所以 apiHost 必须填到 `https://api.a7w.cn/api`。
填成 `https://api.a7w.cn/api/v1` 会双拼成 /api/v1/v1/chat/completions → 404。

只读调用 /v1/models 拉真实模型清单,不产生对话费用。"""

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
https://docs.chatboxai.app/en/guides/providers/import-config

关键点(已实测):Chatbox 的 apiPath 默认 `/v1/chat/completions`,
所以 apiHost 必须填到 `https://api.a7w.cn/api`。
填成 `https://api.a7w.cn/api/v1` 会双拼成 /api/v1/v1/chat/completions → 404。

只读调用 /v1/models 拉真实模型清单,不产生对话费用。"""

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 7)May include surrounding context.

md
https://docs.chatboxai.app/en/guides/providers/import-config

关键点(已实测):Chatbox 的 apiPath 默认 `/v1/chat/completions`,
所以 apiHost 必须填到 `https://api.a7w.cn/api`。
填成 `https://api.a7w.cn/api/v1` 会双拼成 /api/v1/v1/chat/completions → 404。

只读调用 /v1/models 拉真实模型清单,不产生对话费用。"""

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

md
https://docs.chatboxai.app/en/guides/providers/import-config

关键点(已实测):Chatbox 的 apiPath 默认 `/v1/chat/completions`,
所以 apiHost 必须填到 `https://api.a7w.cn/api`。
填成 `https://api.a7w.cn/api/v1` 会双拼成 /api/v1/v1/chat/completions → 404。

只读调用 /v1/models 拉真实模型清单,不产生对话费用。"""

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

md
https://docs.chatboxai.app/en/guides/providers/import-config

关键点(已实测):Chatbox 的 apiPath 默认 `/v1/chat/completions`,
所以 apiHost 必须填到 `https://api.a7w.cn/api`。
填成 `https://api.a7w.cn/api/v1` 会双拼成 /api/v1/v1/chat/completions → 404。

只读调用 /v1/models 拉真实模型清单,不产生对话费用。"""

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

md
https://docs.chatboxai.app/en/guides/providers/import-config

关键点(已实测):Chatbox 的 apiPath 默认 `/v1/chat/completions`,
所以 apiHost 必须填到 `https://api.a7w.cn/api`。
填成 `https://api.a7w.cn/api/v1` 会双拼成 /api/v1/v1/chat/completions → 404。

只读调用 /v1/models 拉真实模型清单,不产生对话费用。"""

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

md
https://docs.chatboxai.app/en/guides/providers/import-config

关键点(已实测):Chatbox 的 apiPath 默认 `/v1/chat/completions`,
所以 apiHost 必须填到 `https://api.a7w.cn/api`。
填成 `https://api.a7w.cn/api/v1` 会双拼成 /api/v1/v1/chat/completions → 404。

只读调用 /v1/models 拉真实模型清单,不产生对话费用。"""

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

md
https://docs.chatboxai.app/en/guides/providers/import-config

关键点(已实测):Chatbox 的 apiPath 默认 `/v1/chat/completions`,
所以 apiHost 必须填到 `https://api.a7w.cn/api`。
填成 `https://api.a7w.cn/api/v1` 会双拼成 /api/v1/v1/chat/completions → 404。

只读调用 /v1/models 拉真实模型清单,不产生对话费用。"""

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

md
https://docs.chatboxai.app/en/guides/providers/import-config

关键点(已实测):Chatbox 的 apiPath 默认 `/v1/chat/completions`,
所以 apiHost 必须填到 `https://api.a7w.cn/api`。
填成 `https://api.a7w.cn/api/v1` 会双拼成 /api/v1/v1/chat/completions → 404。

只读调用 /v1/models 拉真实模型清单,不产生对话费用。"""

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

md
https://docs.chatboxai.app/en/guides/providers/import-config

关键点(已实测):Chatbox 的 apiPath 默认 `/v1/chat/completions`,
所以 apiHost 必须填到 `https://api.a7w.cn/api`。
填成 `https://api.a7w.cn/api/v1` 会双拼成 /api/v1/v1/chat/completions → 404。

只读调用 /v1/models 拉真实模型清单,不产生对话费用。"""

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
https://docs.chatboxai.app/en/guides/providers/import-config

关键点(已实测):Chatbox 的 apiPath 默认 `/v1/chat/completions`,
所以 apiHost 必须填到 `https://api.a7w.cn/api`。
填成 `https://api.a7w.cn/api/v1` 会双拼成 /api/v1/v1/chat/completions → 404。

只读调用 /v1/models 拉真实模型清单,不产生对话费用。"""

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

md
https://docs.chatboxai.app/en/guides/providers/import-config

关键点(已实测):Chatbox 的 apiPath 默认 `/v1/chat/completions`,
所以 apiHost 必须填到 `https://api.a7w.cn/api`。
填成 `https://api.a7w.cn/api/v1` 会双拼成 /api/v1/v1/chat/completions → 404。

只读调用 /v1/models 拉真实模型清单,不产生对话费用。"""

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 111)May include surrounding context.

md
https://docs.chatboxai.app/en/guides/providers/import-config

关键点(已实测):Chatbox 的 apiPath 默认 `/v1/chat/completions`,
所以 apiHost 必须填到 `https://api.a7w.cn/api`。
填成 `https://api.a7w.cn/api/v1` 会双拼成 /api/v1/v1/chat/completions → 404。

只读调用 /v1/models 拉真实模型清单,不产生对话费用。"""

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 199)May include surrounding context.

md
https://docs.chatboxai.app/en/guides/providers/import-config

关键点(已实测):Chatbox 的 apiPath 默认 `/v1/chat/completions`,
所以 apiHost 必须填到 `https://api.a7w.cn/api`。
填成 `https://api.a7w.cn/api/v1` 会双拼成 /api/v1/v1/chat/completions → 404。

只读调用 /v1/models 拉真实模型清单,不产生对话费用。"""

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 209)May include surrounding context.

md
https://docs.chatboxai.app/en/guides/providers/import-config

关键点(已实测):Chatbox 的 apiPath 默认 `/v1/chat/completions`,
所以 apiHost 必须填到 `https://api.a7w.cn/api`。
填成 `https://api.a7w.cn/api/v1` 会双拼成 /api/v1/v1/chat/completions → 404。

只读调用 /v1/models 拉真实模型清单,不产生对话费用。"""

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 242)May include surrounding context.

md
https://docs.chatboxai.app/en/guides/providers/import-config

关键点(已实测):Chatbox 的 apiPath 默认 `/v1/chat/completions`,
所以 apiHost 必须填到 `https://api.a7w.cn/api`。
填成 `https://api.a7w.cn/api/v1` 会双拼成 /api/v1/v1/chat/completions → 404。

只读调用 /v1/models 拉真实模型清单,不产生对话费用。"""

Static analysis

No suspicious patterns detected.