Back to skill

Security audit

网络研究助手

Security checks for vulnerabilities and agentic risk

Overview

This appears to be an API-backed web research skill, but it stores the user's API key in a plaintext .env file and forwards research inputs to an external service with limited disclosure and safeguards.

Install only if you are comfortable giving this publisher a XiaoBenYang API key and sending your research inputs to its remote API. Use a low-privilege or throwaway API key if possible, avoid submitting private URLs, proprietary code, secrets, or full stack traces, and remove or rotate the key if the workspace .env file may have been shared or committed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/config.py:46
Finding

API Key Persisted in a Plaintext Environment File

Content
View full analysis

Vulnerability Details

File Location: scripts/config.py:46-64
Vulnerability Type: Plaintext storage of sensitive credentials
Risk Level: Medium

Vulnerable Code

python
def save_api_key_to_env(api_key: str) -> bool:
    """将API key保存到.env文件"""
    try:
        env_path = Path(".env")
        lines = []
        if env_path.exists():
            lines = env_path.read_text(encoding="utf-8").splitlines()
        found = False
        new_lines = []
        for line in lines:
            if line.startswith("XBY_APIKEY="):
                new_lines.append(f"XBY_APIKEY={api_key}")
                found = True
            else:
                new_lines.append(line)
        if not found:
            new_lines.append(f"XBY_APIKEY={api_key}")
        env_path.write_text("\n".join(new_lines) + "\n", encoding="utf-8")
        os.environ["XBY_APIKEY"] = api_key
        return True

Technical Analysis

The function stores the user-provided API key directly in a plaintext .env file. It does not use an operating-system credential store, encrypt the credential, request explicit consent for persistent storage, enforce restrictive file permissions, or protect against writing through a symbolic link.

Path.write_text() creates or overwrites the file according to the process umask. On systems with an insufficiently restrictive umask, other local users or processes may be able to read the credential. The file may also be unintentionally included in source-control commits, workspace archives, support bundles, or backups.

The credential is legitimately required by the declared API-backed functionality and is sent over HTTPS in the XBY-APIKEY header. The vulnerability is therefore not the authenticated network request itself, but the unnecessary and insufficiently protected persistent plaintext copy.

Attack Path

  1. The Skill instructs the agent to ask the user for an API key whe ...[truncated 1534 chars]
Remediation
View remediation

Remediation Suggestions

  1. Prefer session-only credential handling through a process environment variable. Do not persist the key unless the user explicitly requests persistence.
  2. Store persistent credentials in an operating-system secret manager or platform-provided encrypted credential store.
  3. If .env storage must remain supported:
    • Obtain explicit user consent before writing the key.
    • Create the file atomically with owner-only permissions such as 0600.
    • Verify that the destination is a regular file and reject symbolic links.
    • Use an application-specific configuration directory rather than the current working directory.
    • Add .env to .gitignore and document that it must never be committed or shared.
  4. Avoid keeping duplicate persistent copies of the credential.
  5. Provide API-key rotation and revocation guidance in case the workspace or .env file is exposed.
  6. Redact credentials from exceptions, logs, diagnostics, backups, and support bundles.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (35)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose is generic web research, but the documented behavior includes credential collection/persistence and references to a different project/domain (xiaobenyang_gaokao_skill, search_schools). This mismatch undermines informed consent and trust, and can hide unexpected data handling or off-purpose behavior from users and reviewers.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The workflow and project naming reference a different domain (xiaobenyang_gaokao_skill and search_schools) than the advertised network-research assistant. Such cross-domain inconsistency is a strong signal of copied or repurposed instructions and can conceal unintended operations, integrations, or data flows from users and security reviewers.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/config.py (reported line 13)May include surrounding context.

python
model_config = SettingsConfigDict(
        env_prefix="XBY_GAOKAO_",
        env_file=".env",
        env_file_encoding="utf-8",
        extra="ignore",
    )

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

This code explicitly opens and parses .env to extract XBY_APIKEY, which is credential access behavior beyond ordinary web-research functionality. In the skill context, local credential harvesting/persistence is more suspicious because the declared capability does not require rummaging through local secret files; any compromise of this module or misuse of the key could enable unauthorized API use.

Content

Scanner excerpt · scripts/config.py (reported line 31)May include surrounding context.

python
default_year: int = 2025

    def model_post_init(self, __context):
        # 强制从 .env 文件读取 XBY_APIKEY
        env_path = Path(".env")
        if env_path.exists():
            content = env_path.read_text(encoding="utf-8")

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

The direct reference to .env and subsequent read_text call form part of a plaintext credential access path. Because the skill is presented as a network research assistant, local secret file inspection is outside the narrow expected scope and increases risk of unexpected credential exposure or collection.

Content

Scanner excerpt · scripts/config.py (reported line 32)May include surrounding context.

python
def model_post_init(self, __context):
        # 强制从 .env 文件读取 XBY_APIKEY
        env_path = Path(".env")
        if env_path.exists():
            content = env_path.read_text(encoding="utf-8")
            for line in content.splitlines():

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/config.py (reported line 39)May include surrounding context.

python
if line.startswith("XBY_APIKEY="):
                    self.api_key = line.split("=", 1)[1].strip()
                    break
        # 如果环境变量有值,覆盖 .env 的值
        env_val = os.getenv("XBY_APIKEY", "")
        if env_val:
            self.api_key = env_val

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

This function writes an API key into a plaintext .env file, creating a persistent local credential store and expanding the attack surface to filesystem readers, backups, and accidental commits. In this skill's context, secret storage/manipulation is not clearly necessary for the advertised web research role, making the behavior more dangerous and less expected.

Content

Scanner excerpt · scripts/config.py (reported line 48)May include surrounding context.

python
def save_api_key_to_env(api_key: str) -> bool:
    """将API key保存到.env文件"""
    try:
        env_path = Path(".env")
        lines = []
        if env_path.exists():
            lines = env_path.read_text(encoding="utf-8").splitlines()

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill declares broad capabilities such as environment access, file read/write, and network use but does not scope or constrain which tools are permitted. In an agent setting, missing explicit tool boundaries increases the chance of unintended credential access, filesystem modification, or arbitrary outbound requests beyond the stated user task.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Manifest 将该技能描述为用于搜索、爬取和分析网络内容的“网络研究助手”,但后续工具列表包含包注册表查询、GitHub 仓库健康评估、错误诊断、API 文档发现、技术选型对比等面向软件开发决策的专门能力。这些能力不只是一般性的网页研究实现细节,而是显著超出了“网络研究和发现”这一自然语言描述所传达的范围。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill advertises web search, crawling, and extraction functions but does not disclose that user queries and URLs may be transmitted to external services or third-party sites. This creates privacy and data-governance risk, especially if users submit proprietary queries, internal URLs, or sensitive research targets.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs the agent to solicit a user API key and persist it via configuration for future use. Credential persistence expands the blast radius of compromise, especially when storage format, access controls, masking, and retention policies are not disclosed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill directs the agent to collect and store a user-provided API key without any warning about storage, exposure, or handling risk. Users may disclose sensitive credentials without informed consent about persistence or downstream access, making accidental leakage more likely.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The combination of collecting a secret and instructing the model to continue operating around raw tool outputs creates a plausible path for secret disclosure through prompts, logs, status messages, or echoed API responses. In agent systems, natural-language handling of credentials is especially risky because models may inadvertently repeat or transform sensitive inputs.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly tells the agent to directly present result["raw"] to the user. Raw API responses frequently contain unnecessary metadata, internal identifiers, tokens, URLs, debug details, or other sensitive fields, so unfiltered rendering can leak information unintentionally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code sends request parameters to an external API and includes an API key in the headers, which is a network operation involving potentially sensitive user or system data. While the code has internal logging and docstrings, there is no user-facing warning, confirmation, or explicit disclosure here that data and credentials will be transmitted upstream.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code persists an API key to a local .env file and updates process environment state, creating a durable credential storage path in a skill whose stated purpose is web research/discovery rather than local secret management. If the working directory is shared, committed, backed up, or readable by other local users/processes, the credential can be exposed and reused.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The function silently writes a supplied API key into .env without any user-facing disclosure or confirmation. Secret persistence without clear notice increases the chance users provide credentials assuming transient use, after which the key may remain on disk and be exposed through local access, backups, or accidental repository inclusion.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file defines many helper functions that forward user-supplied inputs such as queries, URLs, package names, error messages, and free-form reasoning directly to an external/local API via call_api(). In a network-research skill, this creates a real data-exposure risk because sensitive prompts, internal URLs, stack traces, or proprietary context can be transmitted off-component without any consent gate, warning, redaction, or validation in this layer.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
71% confidence
Finding

The skill is primarily presented in Chinese, while substantial operational instructions and tool descriptions are in English, and no language-selection or opt-in behavior is documented. This can create a language/locale policy concern because the skill does not clearly let the user choose their preferred language for interaction or output.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
99% confidence
Finding

顶部 manifest 和标题说明都声称该 MCP 服务器“包含13种工具”,但从 scripts.tools.web_search 到 scripts.tools.check_service_status 实际只出现 12 个工具条目。这会造成能力范围和实际实现数量不一致,属于描述与文档化行为不匹配。

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency specification uses a lower-bound version only, which allows future installs to resolve to different releases over time. This weakens build reproducibility and can unintentionally introduce vulnerable or breaking versions of requests into a network-facing tool that fetches remote content.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests>=2.31.0
pydantic>=2.7.0
pydantic-settings>=2.2.0
python-dotenv>=1.0.1

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
91% confidence
Finding

The manifest does not pin requests, and that package has multiple known advisories across versions. Because this skill is a network research assistant that performs web requests against potentially malicious sites, running an affected requests release could increase the chance of credential leakage, TLS-related issues, or unsafe request handling.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

Using pydantic>=2.7.0 without an upper bound or exact pin means dependency resolution is non-deterministic across environments. This can expose deployments to newly introduced vulnerable releases or behavior changes without explicit review.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
requests>=2.31.0
pydantic>=2.7.0
pydantic-settings>=2.2.0
python-dotenv>=1.0.1

Unverifiable Dependency: pydantic has 4 known advisory(ies) (CVE-2021-29510 (Use of "infinity" as an input to datetime and date fields causes infinite loop i); CVE-2024-3772 (Pydantic regular expression denial of service); CVE-2021-29510 (Pydantic is a data validation and settings management using Python type hinting.) +1 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
87% confidence
Finding

The pydantic dependency is unpinned despite known advisories in some versions, so the actual installed version may be vulnerable and cannot be verified from this file alone. While this is less exposed than the HTTP client, unsafe parsing or validation behavior can still affect robustness and denial-of-service resistance.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The pydantic-settings package is unpinned, so installations may pull different versions over time. In configuration-handling libraries, this increases risk because security-relevant parsing or file-handling behavior can change unexpectedly.

Content

Scanner excerpt · requirements.txt (reported line 3)May include surrounding context.

text
requests>=2.31.0
pydantic>=2.7.0
pydantic-settings>=2.2.0
python-dotenv>=1.0.1

Static analysis

No suspicious patterns detected.