Back to skill

Security audit

热点聚合服务

Security checks for vulnerabilities and agentic risk

Overview

This hot-trend skill is not clearly malicious, but it handles API keys in a risky and under-scoped way.

Install only if you are comfortable giving this skill a XiaoBenYang API key and having it stored locally in plaintext. Use a low-privilege key, avoid committing .env, review or restrict XBY_GAOKAO_BASE_URL, and rotate the key if it may have been exposed. The package also appears broken because scripts/tools.py has invalid Python syntax, so it may not work until fixed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/config.py:42
Finding

API Key Stored Persistently in a Plaintext Environment File

Content
View full analysis
bool: """将API key保存到.env文件""" try: env_path = Path(".env") lines = [] if env_path.exists(): lines = env_path.read_text(encoding="utf-8").splitlines() found = False new_lines = [] for line in lines: if line.startswith("XBY_APIKEY="): new_lines.append(f"XBY_APIKEY={api_key}") found = True else: new_lines.append(line) if not found: new_lines.append(f"XBY_APIKEY={api_key}") env_path.write_text("\n".join(new_lines) + "\n", encoding="utf-8") os.environ["XBY_APIKEY"] = api_key return True except Exception as e: print(f"保存API key失败: {e}") return False ``` ### Technical Analysis The application persistently writes the user-supplied API key to a plaintext `.env` file. It does not explicitly apply restrictive file permissions, use an operating-system credential store, reject symbolic links, or create the file atomically. When the file already exists, its current permissions are retained. When it is created, its effective permissions depend on the process umask. Consequently, the credential may be readable by other local users or processes. Plaintext environment files are also commonly exposed through repository commits, backups, support archives, or broad project-directory access. The direct assignment to `os.environ` additionally makes the credential available to subsequently launched child processes. ### Attack Path 1. A user supplies an API key as instructed by the Skill. 2. `set_api_key()` calls `save_api_key_to_env()`. 3. The key is written as `XBY_APIKEY=` in the project’s `.env` file. 4. An attacker with access to t ...[truncated 759 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/call_api.py:51
Finding

Configurable API Endpoint Can Redirect Credentials to an Untrusted Server

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/tools.py:5
Finding

Malformed Tool Definitions Prevent the Skill Module from Loading

Content
View full analysis
Dict[str, Any]: """ 获取 36 氪热榜,提供创业、商业、科技领域的热门资讯,包含投融资动态、新兴产业分析和商业模式创新信息 Args: type: 分类 Returns: """ arguments = { "type": type } return call_api("1777316659328003", "get_36kr_trending", arguments) def get_9to5mac_news( ) -> Dict[str, Any]: """ 获取 9to5Mac 苹果相关新闻,包含苹果产品发布、iOS 更新、Mac 硬件、应用推荐及苹果公司动态的英文资讯 Args: Returns: """ arguments = { } return call_api("1777316659328003", "get_9to5mac_news", arguments) def get_bbc_news( category: Optional[null] = , edition: Optional[null] = ) -> Dict[str, Any]: ``` Additional malformed defaults occur elsewhere in the same module, including: ```python type: Optional[null] = subject region: Optional[null] = cn category: Optional[null] = rising ``` ### Technical Analysis The module contains syntactically invalid empty default expressions: ```python category: Optional[null] = , edition: Optional[null] = ``` Python cannot parse the module when these definitions are present. The file also refers to undefined identifiers such as `null`, `hot`, `subject`, `cn`, and `rising`. Furthermore, return annotations use `Dict` and `Any` without importing them. Although `from __future__ import annotations` defers evaluation of annotations, it does not make invalid function syntax valid and does not resolve undefined names used as default argument values. The first syntax error prevents the entire `scripts.tools` module from importing, so none of the documented tool wrappers are available. ### Attack Path 1. The Skill ru ...[truncated 888 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Unbounded Dependency Constraints Allow Unreviewed Future Releases

Content
View full analysis
=2.31.0 pydantic>=2.7.0 pydantic-settings>=2.2.0 python-dotenv>=1.0.1 ``` ### Technical Analysis Every dependency uses only a minimum-version constraint. The resolver may therefore install any later compatible release available at installation time, including versions that were never tested or reviewed with this Skill. This does not prove that any listed dependency is currently malicious or vulnerable. The risk is that deployments are not reproducible and can silently acquire future releases containing security regressions, compromised distribution artifacts, or breaking behavior. No lock file or package hash is present to ensure that reviewed artifacts are installed consistently. ### Attack Path 1. The project is installed or rebuilt at a later date. 2. The package resolver selects newer releases because all constraints allow any version at or above the stated minimum. 3. A selected release contains a security vulnerability, maliciously modified artifact, or incompatible behavior. 4. The release is imported and executed with the privileges of the Skill process. 5. The resulting impact depends on the behavior and privileges of the affected dependency. This is a supply-chain hardening weakness rather than evidence of a currently compromised package. ### Impact Assessment A compromised dependency would execute within the Skill process and could potentially access its environment, network permissions, local files available to that process, and the API key loaded by the application. An incompatible release could also cause availability failures. The actual impact is conditional on a future or otherwise affected dependency being resolved; no current malicious dependency was confirmed during this audit. ]]>
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (30)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose is hot-trend aggregation, but the documented behavior includes credential persistence and references to unrelated gaokao configuration and tooling. This mismatch is dangerous because users may consent to a news skill while the implementation accesses credentials and other functionality they would not reasonably expect, increasing the chance of deceptive data handling or misuse.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The configuration module is clearly mismatched with the declared hotspot aggregation service: comments and environment naming reference a different '高考/XBY_GAOKAO' skill and a different API key scheme. This kind of cross-skill reuse can cause credentials, endpoints, and runtime behavior to be pulled from the wrong deployment context, creating a realistic risk of data leakage, misrouting, or unintended access to another service.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/config.py (reported line 13)May include surrounding context.

python
model_config = SettingsConfigDict(
        env_prefix="XBY_GAOKAO_",
        env_file=".env",
        env_file_encoding="utf-8",
        extra="ignore",
    )

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/config.py (reported line 32)May include surrounding context.

python
model_config = SettingsConfigDict(
        env_prefix="XBY_GAOKAO_",
        env_file=".env",
        env_file_encoding="utf-8",
        extra="ignore",
    )

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The code manually opens and parses the local '.env' file to extract 'XBY_APIKEY', bypassing the safer, centralized settings loader already in use. Custom secret parsing increases the chance of mistakes, hidden precedence rules, and unintended secret access patterns that are harder to audit and control.

Content

Scanner excerpt · scripts/config.py (reported line 31)May include surrounding context.

python
default_year: int = 2025

    def model_post_init(self, __context):
        # 强制从 .env 文件读取 XBY_APIKEY
        env_path = Path(".env")
        if env_path.exists():
            content = env_path.read_text(encoding="utf-8")

Credential Access

High
Category
Privilege Escalation
Confidence
89% confidence
Finding

The explicit environment override using a second variable name ('XBY_APIKEY') creates another credential source outside the declared settings namespace. Multiple hidden secret sources complicate auditing and can allow unintended credentials to take effect, especially in shared or automated runtime environments.

Content

Scanner excerpt · scripts/config.py (reported line 39)May include surrounding context.

python
if line.startswith("XBY_APIKEY="):
                    self.api_key = line.split("=", 1)[1].strip()
                    break
        # 如果环境变量有值,覆盖 .env 的值
        env_val = os.getenv("XBY_APIKEY", "")
        if env_val:
            self.api_key = env_val

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

This function is dedicated to persisting an API key into a plaintext '.env' file, which materially increases the chance of secret exposure through source control mistakes, local compromise, logs, backups, or weak file permissions. In the context of a hotspot aggregation service, this credential handling is more dangerous because it is unrelated to core content functionality and therefore less likely to be expected or carefully governed by users.

Content

Scanner excerpt · scripts/config.py (reported line 48)May include surrounding context.

python
def save_api_key_to_env(api_key: str) -> bool:
    """将API key保存到.env文件"""
    try:
        env_path = Path(".env")
        lines = []
        if env_path.exists():
            lines = env_path.read_text(encoding="utf-8").splitlines()

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill declares no explicit tool scope or permissions despite requiring environment access, file read/write, and network operations. In an agent setting, missing scope declarations weakens least-privilege controls and makes it harder for users or platforms to understand and constrain what the skill can do.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill asks users for an API key and routes requests to an external service, but it does not clearly warn that the key will be stored in configuration and that data may be sent to third parties. This undermines informed consent and can expose users to credential retention and external data-sharing risks they did not knowingly accept.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly instructs the model to collect an API key through natural-language interaction and then persist it. This creates a sensitive-credential handling path in the conversation layer, where secrets may be exposed in chat logs, mishandled, or stored insecurely, especially if written to .env or other local files.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill claims the code only calls APIs for the current service, but the example directs the model to use an unrelated school-search tool. Contradictory instructions create ambiguity about actual execution paths and can cause the agent to invoke unintended tools or reveal behavior outside the advertised scope.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation and project structure mention unrelated gaokao/school-search functionality inside a supposedly hot-trends skill. Such inconsistency is a supply-chain integrity problem because it suggests copy-paste reuse, hidden functionality, or poor maintenance, any of which can mislead reviewers and users about what the skill actually does.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill directs the model to directly display raw upstream API data to the user. Unfiltered raw responses may contain sensitive fields, internal metadata, tokens, identifiers, or unexpected content, causing accidental disclosure that a safer presentation layer would suppress.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code accesses a sensitive credential via get_api_key() and includes it in the XBY-APIKEY header for an outbound network request. Although the file has internal logging for request success/failure, it does not provide any user-facing warning, confirmation, or explanatory comment/docstring that credentials and request data will be transmitted upstream.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The inline documentation says the code forcibly reads one scheme, but the implementation actually mixes multiple variable names and precedence rules: BaseSettings uses 'XBY_GAOKAO_' while manual parsing uses 'XBY_APIKEY'. This inconsistency can cause operators to set the wrong secret, unexpectedly override values, or load credentials from an unintended source, weakening configuration integrity.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The module persists API credentials to a local '.env' file and also exports them into the process environment. For a hotspot aggregation service, local secret persistence is not obviously required and increases exposure through accidental commit, permissive file access, backup leakage, or other local disclosure paths.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code silently writes sensitive API credentials into '.env' without any user-facing disclosure, warning, or consent flow. This can surprise users and administrators, leading to untracked secret persistence on disk and increasing the chance of inadvertent exposure or compliance violations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill documentation and operational instructions are entirely in Chinese and present mandatory behavior without indicating that users may interact in another language or that the locale is intentionally limited. Under the language/locale policy, forcing a specific language without opt-in can be a natural-language policy concern unless clearly justified.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency specification uses a lower-bound version only (requests>=2.31.0), which allows future installs to resolve to different releases over time. This weakens build reproducibility and can unintentionally introduce a vulnerable or incompatible version through dependency drift or supply-chain compromise.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests>=2.31.0
pydantic>=2.7.0
pydantic-settings>=2.2.0
python-dotenv>=1.0.1

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
88% confidence
Finding

requests has known advisories, and because the manifest does not pin a specific version, there is no reliable way to verify whether the installed release is affected. In a hotspot aggregation service that likely makes outbound HTTP requests, this uncertainty is more relevant because vulnerable client behavior could expose credentials, mishandle redirects, or weaken transport assumptions depending on the resolved version.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

pydantic>=2.7.0 is unpinned, so deployments may install different versions depending on when and where installation occurs. This creates supply-chain and reproducibility risk because a later vulnerable release could be pulled in without any code change in the project.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
requests>=2.31.0
pydantic>=2.7.0
pydantic-settings>=2.2.0
python-dotenv>=1.0.1

Unverifiable Dependency: pydantic has 4 known advisory(ies) (CVE-2021-29510 (Use of "infinity" as an input to datetime and date fields causes infinite loop i); CVE-2024-3772 (Pydantic regular expression denial of service); CVE-2021-29510 (Pydantic is a data validation and settings management using Python type hinting.) +1 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
86% confidence
Finding

pydantic has published advisories, but the unpinned requirement prevents determining whether deployments are using a safe release. Since this skill likely parses external data from multiple sources, a vulnerable validation library could increase exposure to denial-of-service or unsafe parsing conditions if an affected version is installed.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

Using pydantic-settings>=2.2.0 without an upper bound or exact pin permits uncontrolled version selection at install time. In a service-oriented skill, that increases the chance of pulling in a release with a known security issue or breaking behavior from the package ecosystem.

Content

Scanner excerpt · requirements.txt (reported line 3)May include surrounding context.

text
requests>=2.31.0
pydantic>=2.7.0
pydantic-settings>=2.2.0
python-dotenv>=1.0.1

Unverifiable Dependency: pydantic-settings has 1 known advisory(ies) (CVE-2026-58203 (pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
84% confidence
Finding

pydantic-settings has at least one advisory, and the manifest's broad version range means installations may resolve to an affected release without visibility. Because settings libraries often read local configuration and secrets, uncertainty around vulnerable versions carries meaningful configuration-handling risk even if exploitability depends on how the package is used elsewhere in the project.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

python-dotenv>=1.0.1 is not pinned, which means the installed version can vary and may unexpectedly include vulnerable or unsafe behavior. This is particularly relevant for configuration-loading packages because they often interact with local files and environment secrets.

Content

Scanner excerpt · requirements.txt (reported line 4)May include surrounding context.

text
requests>=2.31.0
pydantic>=2.7.0
pydantic-settings>=2.2.0
python-dotenv>=1.0.1

Static analysis

No suspicious patterns detected.