Back to skill

Security audit

api-test

Security checks for vulnerabilities and agentic risk

Overview

This package presents itself as an API documentation helper but includes executable code that makes arbitrary GET/POST requests to user-supplied URLs.

Review before installing. This should not be treated as a simple documentation-writing skill: it can send GET or POST requests, custom headers, query parameters, and JSON bodies to arbitrary URLs from the agent environment and return response data. Only install if you intentionally want a generic HTTP request tool and can constrain network access externally.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
Skill.py:17
Finding

Server-Side Request Forgery Through Unrestricted Caller-Controlled URLs

Content
View full analysis

Vulnerability Details

File Location: Skill.py:17-35
Vulnerability Type: Server-Side Request Forgery (SSRF)
Risk Level: High

Vulnerable Code

python
url = params.get("url")
if not url:
    return self.fail("缺少 url 参数")

method = params.get("method", "GET").upper()
headers = params.get("headers", {})
url_params = params.get("params", {})
data = params.get("data", {})
timeout = params.get("timeout", 10)

default_headers = {
    "User-Agent": "ClawHub-Skill/1.0",
    "Content-Type": "application/json"
}
headers = {**default_headers, **headers}

if method == "GET":
    resp = requests.get(url, headers=headers, params=url_params, timeout=timeout)
elif method == "POST":
    resp = requests.post(url, headers=headers, params=url_params, json=data, timeout=timeout)
else:
    return self.fail(f"不支持的请求方法:{method}")

Technical Analysis

The run() method passes a caller-controlled URL directly to requests.get() or requests.post() without validating the URL scheme, hostname, port, resolved IP address, or redirect destinations. Consequently, an untrusted caller can direct the host running this skill to connect to loopback interfaces, private networks, link-local services, cloud metadata endpoints, or arbitrary Internet hosts.

The caller can also control request headers, query parameters, and POST data, making the skill a flexible HTTP relay rather than a narrowly scoped API documentation assistant. The implementation does not disable redirects, so a public URL may redirect the request to a prohibited internal destination unless every redirect hop is separately validated.

After the request completes, JSON responses are returned without an explicit size limit. Non-JSON response bodies are returned up to 1,000 characters. This response disclosure allows an attacker to retrieve information from reachable internal services rather than merely performing blind network probes.

This beh ...[truncated 1828 chars]

Remediation
View remediation

Remediation Suggestions

  • If outbound HTTP access is unnecessary for the documented API-writing purpose, remove this functionality entirely.
  • Otherwise, permit only explicitly approved HTTPS hostnames and ports through a strict allowlist.
  • Parse URLs with a standards-compliant URL parser and reject unsupported schemes, embedded credentials, malformed hosts, unexpected ports, and ambiguous address representations.
  • Resolve destination hostnames before connecting and reject loopback, private, link-local, reserved, multicast, unspecified, and other non-public IP ranges for both IPv4 and IPv6.
  • Protect against DNS rebinding by ensuring the validated address is the address actually used for the connection.
  • Disable redirects by default. If redirects are required, repeat complete scheme, hostname, port, and resolved-address validation for every redirect hop.
  • Restrict caller-controlled headers to a minimal allowlist. Explicitly block sensitive or routing-relevant headers where they are not required.
  • Apply request and response size limits, including limits before JSON parsing, to reduce data exposure and resource exhaustion risks.
  • Use fixed, bounded timeout values rather than accepting arbitrary caller-supplied timeout settings.
  • Enforce network-level egress controls that prevent the process from accessing metadata services and internal administrative networks.
  • Log rejected destinations and anomalous request attempts without recording credentials or other sensitive header values.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose is generating API documentation, but the detected behavior includes making arbitrary external GET/POST requests to user-provided URLs. This mismatch is dangerous because it can turn a seemingly harmless writing assistant into a network-capable proxy, enabling SSRF-like behavior, data exfiltration, or interaction with untrusted remote systems without clear user awareness.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill’s implemented behavior is materially different from its declared purpose: instead of writing API documentation, it performs arbitrary outbound HTTP requests based on user-controlled inputs. In an agent environment, this mismatch is dangerous because it can covertly exfiltrate prompts, tokens, or other sensitive data to attacker-controlled endpoints under the guise of a harmless documentation helper.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
81% confidence
Finding

The skill metadata declares no tool restrictions, yet the detected behavior indicates network capability. For a documentation-writing skill, undeclared outbound request capability increases the risk of unauthorized data exfiltration, unreviewed remote interaction, or scope creep beyond the user’s expectations.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The comments and metadata identify this as an API data-fetching tool, directly contradicting the manifest that presents it as an API documentation assistant. This discrepancy increases supply-chain and user-trust risk because reviewers or orchestrators may grant permissions and invoke the skill under false assumptions about its capabilities.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill sends user-supplied URL parameters, headers, and POST body content to arbitrary external endpoints without any warning, confirmation, or data-classification checks. In an agent context, this can leak sensitive user data, internal prompts, credentials placed in headers, or derived context to third parties.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The POST request transmits attacker- or user-controlled data and headers to an arbitrary URL, creating a direct external data transmission path. Because the endpoint is unrestricted, this can be used for exfiltration, interaction with untrusted services, or abuse of the agent’s network position.

Content

Scanner excerpt · Skill.py (reported line 37)May include surrounding context.

python
if method == "GET":
                resp = requests.get(url, headers=headers, params=url_params, timeout=timeout)
            elif method == "POST":
                resp = requests.post(url, headers=headers, params=url_params, json=data, timeout=timeout)
            else:
                return self.fail(f"不支持的请求方法:{method}")

Vague Triggers

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The description says the skill triggers 'when needing to write API docs or interface specifications,' which is a broad natural-language condition without explicit limits or negative examples. This could overlap with many general documentation requests and does not clearly distinguish when the skill should or should not activate.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Natural-language comments, metadata, and runtime messages are presented only in Chinese, including the skill name, description, and error/output text. This imposes a specific language on users without any opt-in, language selection, or documented locale-specific scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.