Back to skill

Security audit

Fofa Search v1.0

Security checks for vulnerabilities and agentic risk

Overview

This FOFA search skill largely does what it says, but it needs review because it can send your FOFA API key and queries to any user-supplied API URL.

Before installing, understand that this skill performs FOFA reconnaissance queries using your API key and writes result exports locally. Use the default FOFA endpoint only, avoid any untrusted --base-url, keep the key in an environment variable or secure store, and consider pinning dependencies before operational use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/fofa_search_cli.py:68
Finding

Arbitrary API Base URL Can Expose FOFA Credentials and Search Queries

Content
View full analysis

Vulnerability Details

File Location: scripts/fofa_search_cli.py, lines 68–79; related argument flow at lines 218 and 259
Vulnerability Type: Unrestricted credential-bearing network destination
Risk Level: High

Vulnerable Code

python
self.base_url = base_url.rstrip("/")
self.timeout = timeout
self.session = requests.Session()
self.lang = "zh-CN" if get_shell_language().startswith("zh") else "en"

if not self.key:
    raise FofaError("FOFA key is empty")

def _request(self, path: str, params: Optional[Dict] = None, retries: int = 3) -> Dict:
    url = f"{self.base_url}{path}"
    request_params = dict(params or {})
    request_params["key"] = self.key
    request_params["lang"] = self.lang

The unrestricted destination is exposed through the command-line interface and passed directly to the client:

python
parser.add_argument("--base-url", default=DEFAULT_BASE_URL, help=f"fofa base url, default: {DEFAULT_BASE_URL}")
python
client = FofaClient(key=args.key, base_url=args.base_url)

The resulting request transmits the sensitive parameters to the selected destination:

python
resp = self.session.get(url, params=request_params, timeout=self.timeout)

Technical Analysis

The user-controlled --base-url value is accepted without validating its scheme or hostname. The client appends FOFA API paths to this value and includes the FOFA API key in every request's query parameters. The search query is also transmitted as the qbase64 parameter by search() and search_next().

Base64 encoding of the search query is expected by the FOFA API and is not encryption or, by itself, evidence of a covert channel. Nevertheless, an arbitrary server receiving qbase64 can trivially decode it. The sensitive-data transmission alert is therefore materially relevant because both the key and encoded query can be sent to any destination selected through --base-url.

...[truncated 1866 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove --base-url if custom endpoints are not essential to the Skill's declared functionality.
  2. If custom endpoints are required, parse the URL with urllib.parse.urlparse and enforce:
    • The https scheme.
    • An explicit allowlist of trusted FOFA hostnames.
    • No embedded username or password.
    • No unexpected port unless explicitly approved.
  3. Reject loopback, link-local, private, and metadata-service addresses unless a documented deployment requirement specifically permits them.
  4. Disable automatic redirects or validate every redirect target before forwarding credentials:
    python
    resp = self.session.get(
        url,
        params=request_params,
        timeout=self.timeout,
        allow_redirects=False,
    )
    
  5. Where supported by the FOFA API, transmit credentials in an authorization header rather than in URL query parameters. Ensure exception messages and logs do not contain authorization values.
  6. If compatibility requires several FOFA domains, expose a fixed environment or configuration allowlist rather than accepting arbitrary destinations at each invocation.
  7. Add tests confirming that HTTP URLs, unapproved domains, embedded credentials, and redirects to untrusted hosts are rejected before any key-bearing request is sent.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill clearly directs use of network access to the FOFA API and file-writing to CSV/JSON exports, but it does not declare any explicit tool scope or permission boundaries in the skill metadata. In an agent environment, missing scope declarations can allow the skill to be loaded or executed without clear least-privilege constraints, increasing the chance of unintended network access, data export, or misuse of supplied API credentials.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The activation text is broad enough to trigger on generic requests about FOFA, asset mapping, batch queries, export, or even simply mentioning a key and query, which can cause the skill to activate in more situations than necessary. Overbroad activation increases the risk that an agent invokes networked reconnaissance and data-export functionality in contexts where the user did not explicitly intend to run this capability, especially given the skill handles API keys and bulk data retrieval.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The dependency is specified with a lower bound only (requests>=2.31.0), which makes builds non-reproducible and allows installation of different versions over time. In a security-sensitive skill that performs external API calls, this increases supply-chain risk and can unintentionally pull in a vulnerable or behavior-changing release.

Content

Scanner excerpt · scripts/requirements.txt (reported line 1)May include surrounding context.

text
requests>=2.31.0

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
88% confidence
Finding

Because requests is not pinned, it is impossible to verify from this manifest whether deployment will use a version affected by one of the known advisories. For a skill that likely makes authenticated outbound HTTP requests to the FOFA API, uncertainty around the exact requests version can matter because some historical issues in requests relate to credential handling and request verification behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.