Back to skill

Security audit

NBA数据服务

Security checks for vulnerabilities and agentic risk

Overview

This NBA data skill should be reviewed before installation because it stores an API key locally and contains mismatched configuration plus an overridable credential-bearing API endpoint.

Install only if you are comfortable giving this skill a XiaoBenYang API key and having it saved in plaintext as .env in the working directory. Review or fix the gaokao/NBA inconsistencies, pin the API origin to the intended host, avoid persistent plaintext secrets where possible, and pin dependencies before using it in a shared or sensitive workspace.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/config.py:12
Finding

Configurable API Endpoint Can Expose the API Credential

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/config.py:47
Finding

API Key Is Persisted in a Predictable Plaintext File Without Enforced Permissions

Content
View full analysis
bool: """将API key保存到.env文件""" try: env_path = Path(".env") lines = [] if env_path.exists(): lines = env_path.read_text(encoding="utf-8").splitlines() found = False new_lines = [] for line in lines: if line.startswith("XBY_APIKEY="): new_lines.append(f"XBY_APIKEY={api_key}") found = True else: new_lines.append(line) if not found: new_lines.append(f"XBY_APIKEY={api_key}") env_path.write_text("\n".join(new_lines) + "\n", encoding="utf-8") os.environ["XBY_APIKEY"] = api_key ``` ### Technical Analysis The Skill persistently writes the API key to a file named `.env` in the current working directory. The credential is stored in plaintext, and the implementation does not explicitly create or verify the file with owner-only permissions. The effective permissions therefore depend on the existing file mode, process umask, directory configuration, and execution environment. If `.env` already exists with permissive permissions, rewriting it does not correct those permissions. The predictable location also increases exposure to accidental source-control commits, workspace sharing, backup collection, and unrelated processes with access to the directory. The file update is not atomic. An interruption during `write_text()` can also truncate or partially update the configuration file, although the primary security concern is credential disclosure. ### Attack Path 1. A user supplies an API key as directed by the Skill. 2. `set_api_key()` calls `save_api_key_to_env()`. 3. The key is written as plaintext to `./.env`. 4. The file has or inherits permissions that ...[truncated 793 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Open-Ended Dependency Versions Make Builds Non-Reproducible

Content
View full analysis
=2.31.0 pydantic>=2.7.0 pydantic-settings>=2.2.0 python-dotenv>=1.0.1 ``` ### Technical Analysis All dependencies use open-ended minimum-version constraints. A future installation can therefore resolve to releases that were not present during development or security review. The listed package names and package index are not themselves shown to be malicious. The risk arises because installations are not reproducible and no hashes are provided to verify downloaded artifacts. A compromised, vulnerable, or incompatible future release could be accepted automatically. Python dependencies can execute code during installation and are imported into the Skill at runtime. Supply-chain compromise of an accepted release could therefore affect both the installation environment and the Skill process. ### Attack Path 1. The project is installed at a later date without a reviewed lock file. 2. The package resolver selects newer versions satisfying the `>=` constraints. 3. A selected release contains a vulnerability or has been compromised in the package supply chain. 4. The affected package executes during installation or is imported by the Skill. 5. Malicious or vulnerable dependency behavior runs with the privileges of the installer or Skill process. This is a conditional supply-chain path; the reviewed source does not establish that any currently listed dependency release is malicious. ### Impact Assessment Potential impact depends on the compromised dependency and the privileges used to install or run the Skill. In a worst-case supply-chain compromise, code could execute with the Skill process's local permissions, access its API key, alter requests or responses, and read files available to that process. No direct privilege escalation beyond the inst ...[truncated 68 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (29)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The English description advertises an NBA data server, but the implementation behavior includes reading and persisting API keys, managing configuration for another service, and targeting a different external endpoint. This creates a trust-boundary violation: the skill is not just fetching basketball data, it is also handling credentials and interacting with a distinct service that users may not realize they are authorizing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The English description advertises an NBA data server, but the implementation behavior includes reading and persisting API keys, managing configuration for another service, and targeting a different external endpoint. This creates a trust-boundary violation: the skill is not just fetching basketball data, it is also handling credentials and interacting with a distinct service that users may not realize they are authorizing.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The configuration clearly targets a different service/domain ('高考' and XBY_* settings) than the declared NBA data skill. This kind of mismatched code strongly suggests code reuse or hidden functionality, increasing the risk that the skill routes data or credentials to an unrelated backend and violates user expectations about what the skill does.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/config.py (reported line 13)May include surrounding context.

python
model_config = SettingsConfigDict(
        env_prefix="XBY_GAOKAO_",
        env_file=".env",
        env_file_encoding="utf-8",
        extra="ignore",
    )

Credential Access

High
Category
Privilege Escalation
Confidence
82% confidence
Finding

The code manually opens and parses the .env file specifically to force-load XBY_APIKEY, bypassing the normal settings abstraction. Manual secret scraping increases the chance of mishandling credentials and is more dangerous here because it targets an unrelated key flow in an NBA skill context.

Content

Scanner excerpt · scripts/config.py (reported line 31)May include surrounding context.

python
default_year: int = 2025

    def model_post_init(self, __context):
        # 强制从 .env 文件读取 XBY_APIKEY
        env_path = Path(".env")
        if env_path.exists():
            content = env_path.read_text(encoding="utf-8")

Credential Access

High
Category
Privilege Escalation
Confidence
82% confidence
Finding

This line participates in direct filesystem access to a .env file for credential extraction. While not malicious on its own, it contributes to unnecessary credential handling outside the expected NBA data functionality and increases exposure of secrets to code paths that do not need them.

Content

Scanner excerpt · scripts/config.py (reported line 32)May include surrounding context.

python
def model_post_init(self, __context):
        # 强制从 .env 文件读取 XBY_APIKEY
        env_path = Path(".env")
        if env_path.exists():
            content = env_path.read_text(encoding="utf-8")
            for line in content.splitlines():

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/config.py (reported line 39)May include surrounding context.

python
if line.startswith("XBY_APIKEY="):
                    self.api_key = line.split("=", 1)[1].strip()
                    break
        # 如果环境变量有值,覆盖 .env 的值
        env_val = os.getenv("XBY_APIKEY", "")
        if env_val:
            self.api_key = env_val

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

A helper dedicated to saving API keys into .env indicates active credential collection and persistence behavior. In the context of an NBA data skill with unrelated XBY configuration, this is more suspicious and dangerous because it can retain sensitive keys locally without necessity or clear disclosure.

Content

Scanner excerpt · scripts/config.py (reported line 48)May include surrounding context.

python
def save_api_key_to_env(api_key: str) -> bool:
    """将API key保存到.env文件"""
    try:
        env_path = Path(".env")
        lines = []
        if env_path.exists():
            lines = env_path.read_text(encoding="utf-8").splitlines()

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares no explicit tool scope or permission boundaries even though it is documented and analyzed as having environment, file read/write, and network capabilities. In an agent setting, missing least-privilege declarations increases the chance that a seemingly simple NBA data skill can access secrets, persist data, or make unexpected outbound requests without clear user visibility.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs the agent to ask the user for an API key and save it, but provides no safeguards around secret minimization, consent, masking, storage location, retention, or access control. In agent environments this can lead to overcollection and unsafe persistence of credentials, especially when combined with file write and environment access.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The workflow examples and project structure reference gaokao/school-search functionality, which contradicts the claimed NBA domain and suggests copy-pasted or mislabeled routing logic. Such inconsistencies are a security concern because they undermine reviewer confidence, can hide actual behavior, and may cause the agent to invoke unintended tools or pass incorrect parameters to external services.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This file contains a Chinese-only class docstring and later returns Chinese-only user-facing error/success messages, indicating the skill is designed to communicate in a fixed language. Under the policy, forcing a specific language without user opt-in or documented regional justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code is a generic proxy to an external MCP API: it accepts arbitrary mcp_id, tool_name, and params, then forwards them directly to the upstream service with the stored API key. In a skill advertised as an NBA data service, this expands the accessible capability surface beyond the declared domain and can enable unintended tool invocation, data access, or abuse of the configured credentials if callers can influence these fields.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The raised error message is user-readable and written only in Chinese, with no indication that the user can choose another language. This violates the language/locale policy unless the skill is explicitly documented as region-specific or provides opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The function docstring and returned message strings are Chinese-only and appear to be surfaced to callers, which fixes the interaction language without a user choice. The policy requires either locale selection/opt-in or a clearly justified documented locale restriction.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The declared settings prefix is XBY_GAOKAO_, but the manual credential logic reads and writes XBY_APIKEY instead. This inconsistency can cause operators to misconfigure the service, accidentally load the wrong secret, or bypass intended configuration controls, which is especially risky in security-sensitive credential handling code.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This file includes credential persistence and management behavior that is not disclosed by the NBA data service description. Undocumented secret-handling capabilities are dangerous because they expand trust boundaries and can cause users or operators to supply sensitive keys to a skill that appears to only provide sports data.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code writes API keys directly into a local .env file, creating plaintext secret storage on disk. If the host is shared, backed up, logged, or the project directory is exposed, the credential can be recovered and reused by unauthorized parties.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The function silently persists a provided API key to disk without any user-facing warning or confirmation. That behavior is risky because users may assume the key is used only for the current session, while the code creates a durable secret artifact that may later be disclosed.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency is specified with only a minimum version (requests>=2.31.0), which allows future installs to resolve to different releases over time. This weakens build reproducibility and can unintentionally pull in vulnerable or breaking versions, especially significant for a network-facing data service that relies on HTTP requests.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests>=2.31.0
pydantic>=2.7.0
pydantic-settings>=2.2.0
python-dotenv>=1.0.1

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
88% confidence
Finding

The manifest does not pin requests, so it is impossible to verify whether deployed environments avoid known vulnerable releases. In a service that likely makes outbound HTTP calls for NBA data, an affected requests version could expose credentials or weaken transport security depending on usage.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

Using pydantic>=2.7.0 without an upper bound or exact pin permits uncontrolled dependency drift. That creates supply-chain and reliability risk because future releases may introduce security regressions or behavior changes that affect validation logic.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
requests>=2.31.0
pydantic>=2.7.0
pydantic-settings>=2.2.0
python-dotenv>=1.0.1

Unverifiable Dependency: pydantic has 4 known advisory(ies) (CVE-2021-29510 (Use of "infinity" as an input to datetime and date fields causes infinite loop i); CVE-2024-3772 (Pydantic regular expression denial of service); CVE-2021-29510 (Pydantic is a data validation and settings management using Python type hinting.) +1 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
85% confidence
Finding

Because pydantic is not pinned, the project may install a version impacted by known advisories, but that cannot be confirmed from this file alone. For a data service, flaws in validation libraries can enable denial of service or unsafe parsing if untrusted inputs are processed.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The unpinned pydantic-settings dependency allows installation of any newer version meeting the minimum constraint. Since settings libraries often process environment and secret-loading behavior, version drift can introduce security-sensitive changes unexpectedly.

Content

Scanner excerpt · requirements.txt (reported line 3)May include surrounding context.

text
requests>=2.31.0
pydantic>=2.7.0
pydantic-settings>=2.2.0
python-dotenv>=1.0.1

Static analysis

No suspicious patterns detected.