Back to skill

Security audit

AnnData数据检索工具

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be an AnnData API wrapper, but it stores API keys in plaintext and has mismatched gaokao/Xiaobenyang configuration details that users should review before installing.

Review this skill before installing. It may be usable if you trust the Xiaobenyang service and are comfortable sending AnnData file paths or URLs plus query parameters to that service, but do not provide a sensitive API key unless you accept that the skill stores it in a plaintext .env file. Prefer running it in a dedicated workspace with non-production credentials, and rotate the key if the workspace is shared or archived.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/config.py:41
Finding

API Key Persisted in a Plaintext Environment File

Content
View full analysis
bool: """将API key保存到.env文件""" try: env_path = Path(".env") lines = [] if env_path.exists(): lines = env_path.read_text(encoding="utf-8").splitlines() found = False new_lines = [] for line in lines: if line.startswith("XBY_APIKEY="): new_lines.append(f"XBY_APIKEY={api_key}") found = True else: new_lines.append(line) if not found: new_lines.append(f"XBY_APIKEY={api_key}") env_path.write_text("\n".join(new_lines) + "\n", encoding="utf-8") os.environ["XBY_APIKEY"] = api_key return True except Exception as e: print(f"保存API key失败: {e}") return False ``` ### Technical Analysis The function stores the user-supplied API key directly in a plaintext `.env` file in the process's current working directory. It does not explicitly establish restrictive file permissions, use an operating-system credential manager, or verify that the file is excluded from source control and artifact collection. The resulting permissions depend on the current process umask and the permissions of any existing `.env` file. If these controls are permissive, another local account or process may be able to read the credential. Plaintext persistence also makes the key vulnerable to accidental source-control commits, workspace archives, backups, and diagnostic artifact collection. ### Attack Path 1. A user supplies an API key as required by the Skill workflow. 2. `set_api_key()` invokes `save_api_key_to_env()`. 3. The function writes `XBY_APIKEY=` to the current working directory's `.env` file. 4. An actor with access to the workspace, backup, repositor ...[truncated 652 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/call_api.py:49
Finding

Configurable API Destination Can Receive the User's API Key

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (31)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented purpose says the skill retrieves AnnData biomedical data, but the behavior and project references include API-key persistence and configuration for an unrelated gaokao/XBY service. This mismatch is dangerous because users and hosting platforms may grant trust and permissions based on the declared purpose while the actual behavior targets a different external service and local secret handling.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/config.py (reported line 13)May include surrounding context.

python
model_config = SettingsConfigDict(
        env_prefix="XBY_GAOKAO_",
        env_file=".env",
        env_file_encoding="utf-8",
        extra="ignore",
    )

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The custom post-init logic explicitly reads the .env file and extracts XBY_APIKEY, creating bespoke credential-handling code outside normal configuration patterns. This increases the chance of mishandling secrets, bypassing expected controls, and normalizing local credential harvesting behavior within a tool whose stated purpose does not justify it.

Content

Scanner excerpt · scripts/config.py (reported line 31)May include surrounding context.

python
default_year: int = 2025

    def model_post_init(self, __context):
        # 强制从 .env 文件读取 XBY_APIKEY
        env_path = Path(".env")
        if env_path.exists():
            content = env_path.read_text(encoding="utf-8")

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The code checks for the existence of .env and reads its full contents to locate a specific API key, which is a form of direct credential access. In the context of an AnnData retrieval skill, this is more suspicious because it introduces unnecessary secret collection behavior beyond simple data access.

Content

Scanner excerpt · scripts/config.py (reported line 32)May include surrounding context.

python
def model_post_init(self, __context):
        # 强制从 .env 文件读取 XBY_APIKEY
        env_path = Path(".env")
        if env_path.exists():
            content = env_path.read_text(encoding="utf-8")
            for line in content.splitlines():

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/config.py (reported line 39)May include surrounding context.

python
if line.startswith("XBY_APIKEY="):
                    self.api_key = line.split("=", 1)[1].strip()
                    break
        # 如果环境变量有值,覆盖 .env 的值
        env_val = os.getenv("XBY_APIKEY", "")
        if env_val:
            self.api_key = env_val

Credential Access

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

This function explicitly persists an API key into a plaintext .env file, which materially increases the risk of credential disclosure through source-control commits, local compromise, backups, logs, or permissive filesystem access. Because the skill is described as a biomedical data retrieval tool, secret persistence is less expected and therefore more dangerous from a user-trust and least-privilege standpoint.

Content

Scanner excerpt · scripts/config.py (reported line 48)May include surrounding context.

python
def save_api_key_to_env(api_key: str) -> bool:
    """将API key保存到.env文件"""
    try:
        env_path = Path(".env")
        lines = []
        if env_path.exists():
            lines = env_path.read_text(encoding="utf-8").splitlines()

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares no explicit tool scope or permission boundaries despite requiring environment access, file reads/writes, and network access. In an agent environment, missing scope declarations can allow broader-than-expected capability use, making it harder to enforce least privilege and easier for a misconfigured runtime to expose sensitive resources.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The workflow example instructs the model to call a gaokao school-search function in a skill presented as an AnnData retrieval tool. This inconsistency can misroute user requests to unintended tools or services, causing unauthorized data flow, incorrect execution, and increased risk of abusing available capabilities under false pretenses.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly instructs the agent to directly present raw API data to the user without any privacy, sensitivity, or minimization checks. In a biomedical data context, raw responses may contain sensitive metadata, identifiers, or proprietary dataset details, so unfiltered disclosure materially increases confidentiality risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code performs an HTTP POST to an external service and transmits both the provided params payload and an API key in headers. While there is internal logging for errors and success, there is no confirmation prompt, user-facing notice, or explanatory comment/docstring warning that data will be sent off-system.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
72% confidence
Finding

The visible natural-language identifier and comments present the skill as Chinese-specific, but the file does not indicate any user choice or opt-in for language/locale behavior. Under the policy, language constraints should either be optional for the user or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The module persists a supplied API key into a local .env file even though the declared skill purpose is only data retrieval. Writing secrets to disk increases exposure to accidental commits, local theft, insecure file permissions, and unintended reuse by other processes, especially because there is no consent or storage hardening.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The code adds credential storage and retrieval behavior that is broader than what is necessary for a simple AnnData retrieval tool. This expands the attack surface by creating a local secret-management mechanism without security controls, making credential compromise more likely in normal developer or analyst workflows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The function silently writes credentials to .env without any user-facing warning, disclosure, or confirmation. Users may reasonably assume a provided API key is used ephemerally, so undisclosed persistence can lead to unintentional long-term exposure through backups, source control, shared workspaces, or filesystem compromise.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The tool advertises AnnData retrieval but allows a user-supplied absolute path or URL to be forwarded to backend API operations. If the backend fetches remote URLs or opens arbitrary filesystem paths, this can enable SSRF, unintended access to internal resources, or retrieval of sensitive local data beyond the apparent scope of the skill. In a biomedical data context, this is more concerning because datasets may contain sensitive research or patient-adjacent information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The function transmits user-supplied file paths or URLs and potentially filter/query parameters to an external API via call_api with no visible disclosure, minimization, or validation in this code. This can expose sensitive local paths, internal URLs, dataset locations, or query details to another service, which is especially risky in biomedical workflows where data provenance and privacy matter.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Summary retrieval sends a user-provided dataset path or URL to an external API without any visible warning or limitation in this wrapper. Even if no raw data is returned here, the path itself may reveal sensitive infrastructure details or cause backend retrieval of internal or private resources if URL fetching is supported.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This function forwards user-provided dataset paths plus potentially sensitive filtering criteria to an external API, creating a privacy and data-handling risk. In a biomedical analysis setting, filters and selected attributes can themselves reveal study design, cohort characteristics, or sensitive metadata, increasing the severity compared with a generic non-sensitive domain.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The skill name, operational requirements, and user-interaction instructions are written in Chinese, while key tool descriptions are in English, with no statement that the user may choose their preferred language. This can create a locale/language policy issue because the skill appears to assume a default language rather than offering user choice.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

该段文档展示的项目根目录为 xiaobenyang_gaokao_skill/,与上文描述的 AnnData 数据检索工具明显不一致。虽然这不直接证明代码行为异常,但属于文档层面对技能意图的明确错配,会误导维护者和调用方理解该技能的真实用途。

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency is specified with a lower bound only, which allows future installs to resolve to different versions over time. This weakens build reproducibility and can unintentionally introduce vulnerable or breaking releases into the environment, especially for a data-retrieval tool that may run in varied deployments.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests>=2.31.0
pydantic>=2.7.0
pydantic-settings>=2.2.0
python-dotenv>=1.0.1

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
90% confidence
Finding

The manifest does not pin requests, and the package has multiple published advisories, so the actual installed version may be vulnerable without any visibility from this file alone. For a tool that retrieves data over network protocols, requests is security-relevant because issues may affect credential handling, TLS behavior, or request processing.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

Using an unpinned pydantic version means installations are not deterministic and may pull in newly released versions with security or compatibility regressions. In an MCP-integrated analysis tool, this increases supply-chain uncertainty rather than creating a direct code exploit by itself.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
requests>=2.31.0
pydantic>=2.7.0
pydantic-settings>=2.2.0
python-dotenv>=1.0.1

Unverifiable Dependency: pydantic has 4 known advisory(ies) (CVE-2021-29510 (Use of "infinity" as an input to datetime and date fields causes infinite loop i); CVE-2024-3772 (Pydantic regular expression denial of service); CVE-2021-29510 (Pydantic is a data validation and settings management using Python type hinting.) +1 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
87% confidence
Finding

Because pydantic is not pinned, it is impossible to determine from this manifest whether deployment will use a version affected by known advisories. While this is not proof of an exploitable state by itself, it is a real supply-chain risk that can impact input validation and parsing security in data-processing workflows.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.