Back to skill

Security audit

IP归属查询

Security checks for vulnerabilities and agentic risk

Overview

This IP lookup skill does what it says, but it sends the API key and queried IP address over plaintext HTTP, which could expose the credential and lookup data.

Review before installing. Use this only for IPs you are allowed to send to Juhe, avoid internal/customer-sensitive IP lookups unless approved, protect and rotate the Juhe API key, and prefer a version that uses a verified HTTPS endpoint with pinned dependencies.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
ip.py:8
Finding

API Credential and Query Data Transmitted over Plaintext HTTP

Content
View full analysis

Vulnerability Details

File Location: ip.py, lines 8–26
Vulnerability Type: Plaintext transmission of sensitive information
Risk Level: High

Vulnerable Code

python
API_URL = "http://apis.juhe.cn/ip/ipNewV3"

API_KEY = os.getenv("JUHE_API_KEY", "").strip()

def query_ip(ip):
    params = {
        "ip": ip,
        "key": API_KEY
    }
    headers = {
        "Content-Type": "application/x-www-form-urlencoded"
    }
    try:
        resp = requests.get(API_URL, params=params, headers=headers, timeout=10)

Technical Analysis

The application sends the Juhe API credential and the queried IP address to a plaintext HTTP endpoint. Because requests.get() encodes params into the URL query string, the resulting request includes both sensitive values in a URL similar to:

text
http://apis.juhe.cn/ip/ipNewV3?ip=114.114.114.114&key=API_KEY

Plaintext HTTP provides neither transport confidentiality nor server authentication. An attacker with visibility or control over the network path can read the credential, inspect queried IP addresses, modify requests, or forge API responses. A server-side redirect to HTTPS would not resolve the issue because the initial HTTP request already discloses the query string.

Query-string credentials may also be retained by HTTP proxies, gateways, monitoring systems, and access logs.

Attack Path

  1. A user configures a valid JUHE_API_KEY and invokes the Skill.
  2. The Skill constructs a plaintext HTTP request whose query string contains the API key and target IP address.
  3. An attacker positioned on the local network, an untrusted wireless network, a compromised proxy, or another network transit point observes or intercepts the request.
  4. The attacker extracts and reuses the API credential, or modifies the request or response in transit.
  5. Reused credentials can consume the victim's API quota, while a modified response can cause ...[truncated 607 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the endpoint with the API provider's verified HTTPS endpoint:
    python
    API_URL = "https://apis.juhe.cn/ip/ipNewV3"
    
  2. Confirm from the provider's official documentation that this endpoint supports TLS and validate its certificate normally.
  3. Disable or explicitly reject redirects from HTTPS to HTTP.
  4. Where supported by the provider, transmit the credential through an authorization header rather than a URL query parameter.
  5. If query-string authentication is mandatory, ensure all requests use HTTPS and configure application, proxy, and gateway logging to redact the key parameter.
  6. Rotate the current API key if this code has been used over an untrusted network.
  7. Add an automated test that rejects any API endpoint whose URL scheme is not https.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:25
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 25
Vulnerability Type: Unconstrained third-party dependency
Risk Level: Medium

Vulnerable Code

text
pip install requests

Technical Analysis

The installation instruction retrieves the latest version of requests available from the user's configured Python package index. It does not pin a reviewed version, use a lock file, or verify package hashes.

Consequently, installations are not reproducible and may receive an incompatible or compromised future release. The effective source also depends on local pip configuration, so an untrusted or compromised package index can affect which artifact is installed.

This finding does not establish that the legitimate requests package is malicious. The risk arises from unconstrained dependency resolution and the absence of artifact-integrity verification.

Attack Path

  1. A user follows the documented command to install the dependency.
  2. pip resolves requests and its transitive dependencies from the configured package index without a project-defined version or hash constraint.
  3. If the selected index, package release, maintainer account, or dependency artifact has been compromised, pip downloads the affected artifact.
  4. Package installation or subsequent import can execute attacker-controlled code.
  5. That code runs with the permissions of the account or environment used to install or execute the Skill.

Impact Assessment

Successful exploitation of the dependency supply chain could execute arbitrary Python code with the privileges of the installing or runtime user. Depending on those privileges, an attacker could access environment variables such as JUHE_API_KEY, modify files available to the user, tamper with Skill output, or make unauthorized network requests.

The scope is limited by the permissions of the Python environment and operating-system account. The project itself ...[truncated 37 chars]

Remediation
View remediation

Remediation Suggestions

  1. Add a dependency manifest or lock file containing a reviewed, exact version of requests and its transitive dependencies.
  2. Generate and verify cryptographic hashes for all distributable artifacts, for example by installing from a hash-locked requirements file with:
    text
    python3 -m pip install --require-hashes -r requirements.txt
    
  3. Configure installation to use a trusted HTTPS package index and avoid untrusted extra indexes.
  4. Use an isolated virtual environment rather than installing packages globally or with administrative privileges.
  5. Establish a dependency-update process that reviews security advisories and regenerates lock files and hashes after validation.
  6. Update SKILL.md to reference the locked dependency file instead of instructing users to install an unconstrained package.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill requires environment access and outbound network access, but the manifest does not explicitly declare tool scope such as permissions or allowed-tools. This weakens sandboxing and reviewability because operators and automated systems cannot clearly see or restrict the capability to read credentials and send data externally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation tells users to query IP addresses but does not clearly disclose that the queried IP will be transmitted to a third-party service. IP addresses can be sensitive personal or organizational data, so silent transmission creates privacy, compliance, and data-handling risk, especially for internal or customer-associated IPs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill sends the queried IP address and the JUHE API key to a third-party service over the network without any disclosure to the user. In this specific code, the risk is amplified because the endpoint uses plain HTTP rather than HTTPS, so the API key and queried IP can be intercepted or modified in transit by an on-path attacker.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The skill instructs users to set an API key in an environment variable but does not include guidance on protecting that credential from logs, screenshots, shell history, or accidental commits. While environment variables are common, omitting basic secret-handling guidance increases the chance of credential exposure and downstream abuse of the third-party account.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The script accesses the JUHE_API_KEY environment variable, which is a credential, but the file does not include any comment or user-facing notice explaining that sensitive environment data is consumed. Under the code-file criteria, sensitive environment variable access should have some disclosure unless already documented elsewhere, which is not evident here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.