Back to skill

Security audit

快手评论分析

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its stated Kuaishou comment-analysis purpose, but it sends user content and API credentials to a configurable external endpoint with weak disclosure and broad auto-invocation settings.

Review before installing. Use this only when you intend to send Kuaishou links and related analysis data to the AI Skills API, keep AISKILLS_BASE_URL pinned to the trusted HTTPS service, use a narrowly scoped API key, and avoid implicit or automatic invocation for sensitive business content.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/run.py:24
Finding

Configurable API Endpoint Can Expose Credentials and Submitted Data

Content
View full analysis

Vulnerability Details

File Location: scripts/run.py:24-35, 65-75
Vulnerability Type: Unrestricted credential-bearing outbound requests
Risk Level: Medium

python
def build_base_url():
    return os.getenv("AISKILLS_BASE_URL", DEFAULT_BASE_URL).rstrip("/")

def build_headers():
    api_key = os.getenv("AISKILLS_API_KEY", "").strip()
    tenant_id = os.getenv("AISKILLS_TENANT_ID", "default").strip() or "default"
    if not api_key:
        fail("AISKILLS_API_KEY is required")
    return {
        "Content-Type": "application/json",
        # Cloudflare blocks urllib's default Python user agent for this endpoint.
        "User-Agent": "ai-skills-runner/1.0 (+https://ai-skills.ai)",
        "Accept": "application/json",
        "X-API-Key": api_key,
        "X-Tenant-Id": tenant_id,
    }

def request_json(method, path, payload):
    body = None if payload is None else json.dumps(payload).encode("utf-8")
    req = urllib.request.Request(
        f"{build_base_url()}{path}",
        data=body,
        method=method,
        headers=build_headers(),
    )
    try:
        with urllib.request.urlopen(req, context=SSL_CONTEXT) as response:
            return json.loads(response.read().decode("utf-8"))

Technical Analysis

AISKILLS_BASE_URL completely controls the destination receiving API requests, but the value is not restricted to HTTPS and its hostname is not validated against a trusted allowlist. Every request to this destination is automatically supplied with X-API-Key and X-Tenant-Id.

Consequently, a party that can influence the runner's environment can direct requests to an attacker-controlled server or to a plaintext HTTP endpoint. The request bodies can also contain the user-provided Kuaishou link, parsed content information, and task creation data. The use of an SSL context only protects HTTPS requests; it does not prevent an http:// base URL. Redirect beha ...[truncated 1933 chars]

Remediation
View remediation

Remediation Suggestions

  1. Parse the configured base URL with urllib.parse.urlsplit() and reject every scheme except https.
  2. Restrict the hostname to ai-skills.ai and explicitly approved subdomains, or require administrators to maintain a narrowly scoped trusted-host allowlist.
  3. Reject URLs containing user information, fragments, unexpected ports, or ambiguous hostname encodings.
  4. Disable automatic redirects for authenticated requests or implement a redirect handler that permits only HTTPS redirects to the same approved origin.
  5. Never forward X-API-Key or X-Tenant-Id across an origin change.
  6. Validate the base URL once during startup and fail closed before reading or using the API key.
  7. Protect environment and deployment configuration from untrusted modification and document that custom endpoints receive authentication credentials.
  8. Use narrowly scoped, revocable API keys and rotate any credential that may have been used with an untrusted endpoint.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill requires environment access for API credentials and performs network-backed analysis, but it does not declare any explicit tool scope such as permissions or allowed-tools. This weakens sandboxing and informed consent because a host may allow broader execution than users expect, especially when the skill transmits supplied content to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation says the script parses links, creates analysis tasks, and polls results against an external service, but it does not clearly warn users that provided Kuaishou links and related analysis data will be sent off-platform. This creates a privacy and data-handling risk because users may submit business-sensitive or personal-content URLs without informed consent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest enables implicit invocation while providing only a broad display name and generic default prompt, so the platform may auto-activate the skill in situations the user did not clearly intend. In a skill that analyzes user-provided Kuaishou content links and generates sentiment, profiling, and conversion insights, unintended activation can cause unnecessary processing of user content and potentially over-collect context for analytics-style outputs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This manifest presents the skill name, prompt question, and form labels entirely in Chinese, indicating a fixed language/locale experience. Under the policy, forcing a specific language is a violation unless the skill offers user opt-in or clearly documents a justified region-specific constraint, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The natural-language description and usage guidance are written in Chinese throughout, which effectively imposes a language constraint on users without documenting it as an explicit choice or justified locale limitation. The policy requires flagging language or locale constraints when the skill forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The parameter table states the required input is videoUrl, but the documented command examples and JSON payload consistently pass link instead. This is an active documentation contradiction about how the skill is meant to be called, which can mislead users and integrators about the actual interface.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest-facing display name, description, and prompt are entirely in Chinese, which may impose a language preference without any indication of user opt-in or a documented locale-specific constraint. Under the policy rule, language constraints should either offer choice or be clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This JSON schema contains user-facing strings only in Chinese, including the field title, description, and placeholder. Because the file does not indicate that the skill is region-specific or provide any user opt-in for language selection, it presents a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.