Back to skill

Security audit

Api Security Scanner

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only API security checklist skill that asks the agent to review user-provided API details and produce a report, with no hidden execution or persistence behavior found.

Install only if you are comfortable using a Chinese-oriented API security review checklist. Provide only API documentation, configurations, or sanitized examples you intend the agent to inspect; avoid pasting real production bearer tokens, passwords, or customer data unless your environment permits that handling.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

md
POST /api/v1/users/register
GET /api/v1/users/{id}
PUT /api/v1/users/{id}
DELETE /api/v1/users/{id}
POST /api/v1/auth/login
GET /api/v1/admin/users

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scan-rules.md (reported line 23)May include surrounding context.

md
| # | 检查项 | 风险 | 规则描述 |
|---|--------|------|---------|
| A007 | JWT 签名算法 | 🔴 Critical | 禁止 "alg": "none",使用 RS256/ES256 |
| A008 | JWT 过期时间 | 🟠 High | Access Token ≤ 15min,Refresh Token ≤ 7天 |
| A009 | Token 传输方式 | 🟡 Medium | 优先使用 HttpOnly Cookie,避免 localStorage |
| A010 | Refresh Token 轮换 | 🟠 High | Refresh Token 应该一次性使用,使用后立即轮换 |
| A011 | Token 黑名单 | 🟡 Medium | 支持 Token 撤销/黑名单机制 |

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description and all example invocations are written in Chinese, including imperative usage prompts such as '请扫描以下 API 端点的安全问题' and '快速检查'. This indicates a language-specific usage expectation without documenting user choice or an explicit locale constraint, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file is almost entirely written in Chinese, starting with a headline that frames the scan rules in Chinese, and it does not indicate that other languages are supported. Under the policy for natural-language violations, forcing a specific language without user opt-in is reportable unless the locale restriction is clearly justified, which is not stated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file presents core descriptive and usage content in both Chinese and English, but does not state whether the skill responds in a user-selected language or whether a specific locale is required. Under the language/locale policy, forcing or assuming a language without opt-in can be a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.