Back to skill

Security audit

CSV转JSON转换器

Security checks for vulnerabilities and agentic risk

Overview

This CSV converter sends conversion data to an external API and stores an API key locally, with enough mismatch and under-disclosure to require review before use.

Install only if you are comfortable giving this skill a Xiaobenyang API key, storing that key in a local .env file, and sending CSV contents or file paths to the external service. Avoid using it with sensitive CSV data unless the publisher adds clear data-handling terms, consent prompts, local conversion support, and safer secret storage.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/tools.py:150
Finding

Unnecessary Disclosure of Complete CSV Content to an External Service

Content
View full analysis

Vulnerability Details

File Location: scripts/tools.py:150-171 and scripts/call_api.py:51-75
Vulnerability Type: External transmission of potentially sensitive user data
Risk Level: High

Complete Code Snippet:

python
arguments = {
    "csv_content": csv_content,
    "delimiter": delimiter,
    "skip_rows": skip_rows,
    "header": header,
    "orient": orient,
    "indent": indent
}

return call_api("1777419078300675", "convert_csv_string", arguments)
python
url = f"{settings.base_url}/api"
mcp_id = mcp_id or settings.mcp_id

api_key = get_api_key()
if not api_key:
    raise UpstreamError("API key is not configured")

headers = {
    "XBY-APIKEY": api_key,
    "func": tool_name,
    "mcpid": mcp_id,
    "Content-Type": "application/json",
}

t0 = time.time()
try:
    resp = self._session.post(
        url=url,
        headers=headers,
        data=json.dumps(params),
        timeout=settings.timeout_seconds,
    )

Technical Analysis

The convert_csv_string wrapper places the complete user-supplied CSV document in the request parameters. call_tool serializes those parameters and transmits them to the configured external endpoint, whose default value is https://mcp.xiaobenyang.com/api.

CSV-to-JSON conversion can ordinarily be completed locally. Consequently, transmitting the source data to an external service expands the trust boundary without a technical necessity inherent to the advertised task. The CSV can contain personal information, internal business records, credentials, access tokens, or other confidential values.

The documentation requires use of the external API but does not clearly explain that the complete CSV string leaves the local environment, identify the exact transmitted fields, or require explicit informed consent before disclosure.

Attack Path

  1. A user supplies sensitive CSV content for conversion.

...[truncated 986 chars]

Remediation
View remediation

Remediation Suggestions

  • Implement CSV parsing and JSON serialization locally using Python's csv and json standard-library modules.
  • Do not transmit CSV content unless remote processing is strictly necessary.
  • If remote processing remains necessary:
    • Clearly identify the destination service and every transmitted field.
    • Obtain explicit user consent immediately before transmission.
    • Provide a local-processing option.
    • Apply data minimization and redact sensitive columns where possible.
    • Document the service's retention, deletion, logging, encryption, and access-control policies.
    • Establish contractual and technical controls appropriate to the sensitivity of processed data.
  • Add automated tests that verify sensitive conversion input is not sent over the network when local conversion is selected.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/config.py:44
Finding

API Credential Persisted in a Plaintext Environment File

Content
View full analysis

Vulnerability Details

File Location: scripts/config.py:44-66
Vulnerability Type: Insecure plaintext storage of authentication material
Risk Level: Medium

Complete Code Snippet:

python
def save_api_key_to_env(api_key: str) -> bool:
    """Store the API key in the .env file"""
    try:
        env_path = Path(".env")
        lines = []
        if env_path.exists():
            lines = env_path.read_text(encoding="utf-8").splitlines()
        found = False
        new_lines = []
        for line in lines:
            if line.startswith("XBY_APIKEY="):
                new_lines.append(f"XBY_APIKEY={api_key}")
                found = True
            else:
                new_lines.append(line)
        if not found:
            new_lines.append(f"XBY_APIKEY={api_key}")
        env_path.write_text("\n".join(new_lines) + "\n", encoding="utf-8")
        os.environ["XBY_APIKEY"] = api_key
        return True
    except Exception as e:
        print(f"Failed to save API key: {e}")
        return False

Technical Analysis

The API credential is written directly into .env as an unencrypted string. The implementation neither creates the file with explicit owner-only permissions nor verifies that an existing file has safe ownership and permissions. It also uses a non-atomic read-modify-write operation.

The file is created relative to the process's current working directory rather than a dedicated, permission-controlled configuration directory. This increases the risk of accidental placement in a shared directory or source repository. No reviewed project-level ignore rule was present to prevent accidental version-control inclusion.

Attack Path

  1. The skill requests an API key from the user.
  2. The agent passes the credential to set_api_key.
  3. set_api_key calls save_api_key_to_env.
  4. The function writes the credential as XBY_APIKEY=<secret> into ` ...[truncated 795 chars]
Remediation
View remediation

Remediation Suggestions

  • Prefer an operating-system credential store, keychain, or deployment secret manager.
  • Where possible, accept the key through a runtime environment variable and avoid persistent storage.
  • If file storage is unavoidable:
    • Store the file in a dedicated user configuration directory.
    • Create it atomically with owner-only permissions such as 0600.
    • Verify ownership and permissions before reading or replacing an existing file.
    • Reject symbolic links and other unsafe target types.
    • Use an atomic temporary-file-and-rename procedure.
  • Add .env to a repository-level .gitignore and configure secret-scanning controls.
  • Avoid including credentials in logs, exceptions, diagnostics, or backups.
  • Support credential revocation and rotation, and document the minimum API permissions required.

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Unpinned Third-Party Dependencies Permit Unreviewed Package Versions

Content
View full analysis

Vulnerability Details

File Location: requirements.txt:1-4
Vulnerability Type: Non-reproducible dependency resolution
Risk Level: Low

Complete Code Snippet:

text
requests>=2.31.0
pydantic>=2.7.0
pydantic-settings>=2.2.0
python-dotenv>=1.0.1

Technical Analysis

Every dependency uses only a lower-bound version constraint. An installation can therefore resolve to any later release accepted by the package resolver. The repository contains no reviewed lockfile or package hashes to constrain the exact artifacts installed.

No malicious dependency was identified in the reviewed files. The risk is that future installations may silently select versions that were not audited, are incompatible, or have become compromised upstream. This also prevents reproducible security review because different installations can execute different dependency code.

Attack Path

  1. A user or automated deployment installs requirements.txt.
  2. The package resolver selects the latest available versions satisfying the lower bounds.
  3. A newly released, compromised, or otherwise unsafe version is eligible for installation without a repository change.
  4. The selected package code executes during installation or when imported by the skill.
  5. Any resulting impact occurs with the privileges of the installing or running process.

This is a supply-chain exposure path rather than evidence that a currently listed package is malicious.

Impact Assessment

The potential scope is the privilege level of the Python installation or skill runtime. A compromised dependency could theoretically read accessible files, credentials, and environment variables or make network requests. However, the audit found no evidence that any currently declared dependency performs such malicious behavior, so the confirmed issue is limited to weak dependency integrity and non-reproducible resolution.

Remediation
View remediation

Remediation Suggestions

  • Resolve and review exact dependency versions in a lockfile.
  • Require cryptographic hashes for downloaded distributions, such as with pip --require-hashes.
  • Install packages only from approved package indexes over authenticated TLS.
  • Use automated vulnerability and dependency-update scanning.
  • Review release notes and security advisories before updating locked versions.
  • Rebuild the lockfile through a controlled process and test updates before deployment.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (44)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill claims to perform CSV conversion, yet it also reads and writes local .env files and persists API keys for unrelated gaokao/MCP functionality. This creates a hidden credential-handling and local-state-modification behavior that users would not reasonably expect from a format conversion tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill claims to perform CSV conversion, yet it also reads and writes local .env files and persists API keys for unrelated gaokao/MCP functionality. This creates a hidden credential-handling and local-state-modification behavior that users would not reasonably expect from a format conversion tool.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

A CSV-to-JSON conversion skill should not require users to provide an external API key before basic operation, yet the documentation mandates collecting and saving one. This is a strong indicator of deceptive scope expansion and creates credential collection risk under a misleading pretext.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Requiring, collecting, and persisting an API key is unjustified for a local CSV-to-JSON converter and introduces unnecessary secret-handling risk. Users may be tricked into disclosing credentials to a skill whose advertised function does not warrant them.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The documented project structure and return-value handling refer to a gaokao API client and raw API response presentation, not a CSV converter. This inconsistency suggests the skill may be repurposed or mislabeled, which can mislead users into exposing files or secrets to unrelated backend services.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file implements a generic remote MCP API client that can invoke arbitrary upstream tools via caller-controlled tool_name, mcp_id, and params, which is materially broader than a CSV-to-JSON converter’s stated purpose. In this skill context, the mismatch increases risk because users may supply data expecting local transformation while the skill can exfiltrate content to an external service and trigger unrelated remote actions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

A document/data conversion skill exposing external network-call capability is dangerous because it sends input and metadata to a remote server (settings.base_url) without any in-file restriction tying the call to safe conversion-only behavior. In this context, users reasonably expect passive format conversion, so hidden remote execution and data transfer meaningfully increase the chance of unauthorized disclosure or abuse.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file implements configuration and credential handling for an unrelated remote '高考' service, including a base URL, MCP identifier, API key loading, and persistence logic. In a skill advertised as a CSV-to-JSON converter, this is suspicious because it expands the trust boundary and introduces unnecessary secret management and outbound-service coupling that could enable hidden data exfiltration or unauthorized remote access.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
77% confidence
Finding

Loading secrets from a .env file is not automatically unsafe, but in this skill it is part of an unnecessary credential path for an unrelated external service. In the context of a CSV-to-JSON converter, adding .env-based secret loading expands exposure of credentials without a justified functional need.

Content

Scanner excerpt · scripts/config.py (reported line 13)May include surrounding context.

python
model_config = SettingsConfigDict(
        env_prefix="XBY_GAOKAO_",
        env_file=".env",
        env_file_encoding="utf-8",
        extra="ignore",
    )

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The model_post_init method forcibly reads the .env file and extracts XBY_APIKEY manually, bypassing normal configuration boundaries and creating custom secret-parsing logic. This increases risk because it normalizes secret harvesting behavior and makes the skill handle credentials more aggressively than its declared purpose requires.

Content

Scanner excerpt · scripts/config.py (reported line 31)May include surrounding context.

python
default_year: int = 2025

    def model_post_init(self, __context):
        # 强制从 .env 文件读取 XBY_APIKEY
        env_path = Path(".env")
        if env_path.exists():
            content = env_path.read_text(encoding="utf-8")

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

The explicit read of the .env file content is part of custom credential access logic for XBY_APIKEY, which is unrelated to CSV conversion. Direct secret-file access increases the chance of accidental exposure, broadens the attack surface, and is especially suspicious given the mismatch between the code's behavior and the skill's declared functionality.

Content

Scanner excerpt · scripts/config.py (reported line 32)May include surrounding context.

python
def model_post_init(self, __context):
        # 强制从 .env 文件读取 XBY_APIKEY
        env_path = Path(".env")
        if env_path.exists():
            content = env_path.read_text(encoding="utf-8")
            for line in content.splitlines():

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

The code prioritizes an environment variable override for XBY_APIKEY, continuing the pattern of managing credentials for an unrelated remote service. While environment-variable usage alone is common, here it contributes to hidden secret-dependent behavior that does not fit the advertised scope and may facilitate unauthorized outbound integration.

Content

Scanner excerpt · scripts/config.py (reported line 39)May include surrounding context.

python
if line.startswith("XBY_APIKEY="):
                    self.api_key = line.split("=", 1)[1].strip()
                    break
        # 如果环境变量有值,覆盖 .env 的值
        env_val = os.getenv("XBY_APIKEY", "")
        if env_val:
            self.api_key = env_val

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code accepts an API key and persistently writes it into a local .env file, creating a durable credential store that is not justified by the stated CSV conversion purpose. Persisting secrets to disk increases the risk of credential theft through source control leaks, filesystem exposure, backups, logs, or later compromise of the host environment.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

This function is dedicated to saving an API key into a .env file, which creates persistent local storage of sensitive credentials. Persisting secrets from application logic is dangerous because it can leak via repository commits, shared workspaces, backups, or local compromise, and it is unjustified for a simple CSV-to-JSON utility.

Content

Scanner excerpt · scripts/config.py (reported line 48)May include surrounding context.

python
def save_api_key_to_env(api_key: str) -> bool:
    """将API key保存到.env文件"""
    try:
        env_path = Path(".env")
        lines = []
        if env_path.exists():
            lines = env_path.read_text(encoding="utf-8").splitlines()

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill declares no explicit tool scope or permissions despite documentation and detected capabilities indicating access to environment variables, local file read/write, and network operations. In an agent setting, this broad undeclared capability increases the chance of over-privileged execution, unexpected data access, and unnoticed exfiltration paths.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
72% confidence
Finding

The skill name and all user-facing instructions are written exclusively in Chinese, and the document does not offer any language selection or indicate that use is limited to a Chinese-speaking or region-specific context. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation tells the agent to persist a user-supplied API key to local configuration without clearly warning the user that their credential will be stored on disk. This undermines informed consent and increases the risk of accidental credential exposure through local file access, backups, or later reuse.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The workflow states that the code 'only calls APIs' and even includes an unrelated school-search example, contradicting the advertised CSV conversion purpose. This raises the likelihood that the skill routes user inputs and possibly file contents into a broader API-calling framework than users intended.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs the model to directly present raw tool/API data to the user. If the tools process uploaded CSVs or receive backend responses containing sensitive fields, this bypasses data minimization and can unnecessarily disclose secrets, personal data, or internal metadata.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The code forwards arbitrary params directly to an upstream API as JSON with no visible validation, confirmation, or narrowing of allowed fields. This can enable unintended data exfiltration, abuse of powerful remote tools, or invocation of behavior beyond CSV conversion if untrusted user input reaches this method.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The class docstring explicitly states this is a '小笨羊高考Skill配置', which directly conflicts with the declared CSV-to-JSON functionality. This mismatch is dangerous because it indicates code reuse from an unrelated skill or hidden functionality, reducing reviewer trust and increasing the chance that unnecessary networked or credentialed behavior is being smuggled into a simple data-conversion tool.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The function is presented as a local CSV inspection helper, but it actually forwards the provided file path to an external API. This creates an unexpected data-flow boundary where local path information and potentially file-derived metadata are exposed off-host, which is a real security and privacy concern when users expect purely local processing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The conversion API call may trigger both remote processing and local/remote file output effects, but users are not warned that a simple conversion request crosses a network boundary. In this skill context, the mismatch is more dangerous because the tool appears to be a straightforward utility, so users are less likely to anticipate data exposure or side effects.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file conversion routine does not perform local conversion; it sends the file path and conversion parameters to a remote API. In a tool advertised as a CSV-to-JSON converter, this can leak sensitive filesystem structure and cause users to submit data for off-box handling without informed consent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.