Back to skill

Security audit

Terabox Link Extractor

Security checks for vulnerabilities and agentic risk

Overview

This TeraBox skill is mostly purpose-aligned, but its download mode can write untrusted remote files outside the intended folder and its third-party data sharing is inconsistently disclosed.

Review before installing. Use this only with non-sensitive TeraBox links unless you are comfortable sending the full URL and your XAPIverse API key to xapiverse.com. Avoid CLI --download mode until filenames, output-path containment, allowed download hosts, redirect limits, and size/time limits are fixed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/extract.js:104
Finding

Arbitrary File Write Through Untrusted Download Filenames and Weak Path Containment

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/extract.js:40
Finding

Unrestricted API-Provided Download URLs and Redirects Enable SSRF and Resource Exhaustion

Content
View full analysis
{ const req = https.get(fileUrl, (res) => { if (res.statusCode === 301 || res.statusCode === 302) { downloadFile(res.headers.location, destPath).then(resolve).catch(reject); return; } if (res.statusCode !== 200) { reject(new Error(`HTTP Status: ${res.statusCode}`)); return; } const file = fs.createWriteStream(destPath); res.pipe(file); file.on('finish', () => { file.close(resolve); }); }).on('error', (err) => { fs.unlink(destPath, () => { }); reject(err); }); }); } ``` The initial URL is selected directly from an external API response: ```js let dlUrl = file.fast_download_link || file.download_link; ``` ### Technical Analysis The Skill treats download URLs returned by XAPIverse as trusted and supplies them directly to `https.get()`. It does not validate: - The destination hostname. - The resolved IP address. - Whether the address is loopback, private, link-local, or otherwise internal. - Whether the URL belongs to an expected TeraBox or approved CDN domain. - The number of redirects. - Redirect destinations. - Response size. - Download duration or inactivity. - Available disk capacity. Redirect handling recursively invokes `downloadFile()` for every HTTP 301 or 302 response without a redirect counter. A redirect loop can consequently cause repeated requests and eventually exhaust resources or fail through excessive recursion and asynchronous activity. A malicious or compromised upstream API can ...[truncated 2305 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (10)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README promotes browser-less direct extraction and streaming through the XAPIverse API but does not disclose that user-provided TeraBox URLs will be sent to a third-party service. This omission is dangerous because such URLs may contain sensitive file references, access tokens, or private content identifiers, and users or operators are not warned about the privacy and data-sharing implications.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README says the skill is 'automatically triggered by the agent' for 'any valid TeraBox URL' without defining narrow invocation conditions, confirmation requirements, or trust boundaries. In an agent environment, this broad trigger can cause unintended transmission of user-supplied links to an external service, increasing the chance of accidental data disclosure or misuse.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares access to sensitive environment data (TERABOX_API_KEY) but does not define an explicit tool scope such as permissions or allowed-tools. This weakens least-privilege controls and makes it easier for the skill to access or expose secrets through code paths that are not clearly constrained or reviewable.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill states that the full target URL and the API key are transmitted to xapiverse.com, but only promises to disclose this 'if asked'. Because URLs may contain private file identifiers, tokens, or personal data, failing to proactively warn users undermines informed consent and can lead to unintended third-party disclosure of both user data and a sensitive credential.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The changelog explicitly records a version that optimized the skill to make the LLM trigger extraction automatically, which conflicts with informed-consent expectations for sending user-provided URLs to a third-party API. In this skill's context, automatic transmission is more dangerous because the skill handles external links and may disclose user-shared content to an external service without a clear permission step.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script sends the user-supplied TeraBox URL to xapiverse.com, a third-party service, without any in-script disclosure, consent prompt, or data-minimization checks. If the URL contains sensitive share tokens, identifiers, or private content references, users may unknowingly disclose that data to an external provider.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest description is narrowly framed around extracting high-speed download and stream links from TeraBox URLs. In addition to extraction, the implementation includes a full file-download path that fetches remote content and writes it to disk, which is a materially broader behavior than link extraction alone.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The handler reads ctx.env.TERABOX_API_KEY, which is access to a credential-like environment variable. In this code file there is no confirmation prompt, user-facing log, or explanatory comment/docstring disclosing that the skill uses an API key.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The manifest presents the skill as a direct-link extractor for user-supplied TeraBox URLs, but the implementation depends on a TERABOX_API_KEY secret loaded from the environment. Using service credentials may be a valid implementation detail, but it is still an additional capability not evident from the stated scope and could matter for deployment trust assumptions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

In download mode, the script writes files from externally supplied download URLs and uses file.name from remote API output directly in the destination path. Although the output directory is constrained under Downloads, an attacker-controlled filename containing path separators could traverse outside that directory, causing arbitrary file overwrite within the user's permissions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.