Back to skill

Security audit

qinglite

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it says, but it handles login codes, tokens, and publish content in ways that can expose the user's account credentials.

Review this skill before installing if you plan to use a real Qinglite account. Only use it in an environment where command output, command history, process arguments, and agent logs are protected or redacted, because leaked tokens may allow someone else to publish through your account.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Warning
Location
login.py:36
Finding

Sensitive login credentials exposed through command-line arguments

Content
View full analysis
") sys.exit(1) mobile = sys.argv[1] code = sys.argv[2] qinglite_login(mobile, code) ``` ### Technical Analysis The script requires the user's mobile number and one-time verification code to be supplied as command-line arguments. Command-line arguments may be exposed through process inspection facilities, shell history, terminal-session recording, CI logs, audit systems, and orchestration metadata. Although sending these values to the documented Qinglite login endpoint is necessary for the declared login operation, exposing them through the command line is not necessary and exceeds secure minimum handling requirements. A verification code should be treated as an authentication secret during its validity period. ### Attack Path 1. A victim invokes `login.py` with a mobile number and valid verification code. 2. The arguments are recorded in shell history, captured by execution logging, or observed through local process inspection while the command is running. 3. A local user, monitoring operator, or log reader obtains the mobile number and code. 4. If the code remains valid, the attacker submits it to the Qinglite login endpoint. 5. The attacker may obtain an authenticated token for the victim's account. ### Impact Assessment Successful exploitation may disclose personally identifiable information and a temporary authentication factor. If the verification code is still valid and accepted by the service, an attacker may authenticate as the victim and obtain the account token. The resulting access is limited by the permissions granted to that token, including the documented ability to publish Qinglite content. ]]>
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
qinglite_platform.py:70
Finding

Authentication token and private publication data exposed through command-line arguments

Content
View full analysis
") sys.exit(1) mobile = sys.argv[2] code = sys.argv[3] qinglite_login(mobile, code) elif action == "publish": if len(sys.argv) < 6 or len(sys.argv) > 7: print("Usage: python qinglite_platform.py publish <content> <type> [media]") sys.exit(1) token = sys.argv[2] title = sys.argv[3] content = sys.argv[4] post_type = int(sys.argv[5]) media = sys.argv[6] if len(sys.argv) == 7 else "" qinglite_publish(token, title, content, post_type, media) else: print("Invalid action. Use 'login' or 'publish'.") sys.exit(1) ``` ### Technical Analysis Both operational modes place sensitive values in command-line arguments. Login exposes the mobile number and verification code. Publishing exposes the authentication token and potentially private title, content, and media metadata. Process arguments may be accessible to local process-monitoring tools and may be retained in shell history, Agent execution records, CI output, telemetry, or audit logs. This creates an unnecessary secondary disclosure channel unrelated to the declared Qinglite network requests. ### Attack Path 1. A victim invokes the script to log in or publish content. 2. The command includes a valid verification code or authentication token as a visible argument. 3. An attacker with local process visibility or access to retained command logs captures the secret. 4. The attacker reuses the verification code to request a token, if it remains valid, or directly reuses th ...[truncated 542 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
login.py:23
Finding

Authentication token disclosed in plaintext program output

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
qinglite_platform.py:25
Finding

Authentication token disclosed in plaintext by the platform login workflow

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

代码行为与描述部分匹配:它确实调用轻识的登录接口并在成功时返回 token。但声明包含两个能力:1) 登录并获取 token;2) 使用 token 发布作品。当前提供的代码只实现了第一个能力,没有任何使用 token 进行内容发布、调用发布接口、上传作品或相关触发逻辑。因此描述相对代码存在能力范围上的不准确/夸大,应判定为不完全匹配。

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script prints the authentication token directly to stdout, which can expose it through terminal history, shell logs, CI/CD job logs, process supervisors, or shared console sessions. Anyone who obtains the token may be able to impersonate the user and perform authenticated actions against the qinglite platform until the token expires or is revoked.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This finding describes the same underlying issue as SDI-2: sensitive credentials are emitted to stdout immediately after login. In agent or automation contexts, stdout is commonly captured and persisted, so exposing the token materially increases the risk of credential theft and unauthorized content publication.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill describes outbound HTTP requests to qinglite.cn but does not declare any tool scope such as permissions or allowed-tools. Missing explicit network scoping weakens least-privilege controls and makes it harder for reviewers or runtime policy systems to constrain what the skill can access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs users to provide highly sensitive authentication material including phone numbers, one-time verification codes, and bearer tokens, but gives no warning about storage, redaction, logging, or reuse risks. In an agent environment, these secrets may be exposed in transcripts, tool logs, or downstream systems, enabling account takeover or unauthorized posting.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The login instructions hard-code the phone prefix to '+86', which forces a specific locale/country assumption in natural-language documentation. The file does not state that the skill is China-only or otherwise justify this regional restriction, nor does it offer user opt-in or alternatives.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · login.py (reported line 19)May include surrounding context.

python
}

    try:
        response = requests.post(url, json=payload, headers=headers)
        response.raise_for_status()  # Raise an exception for HTTP errors
        response_json = response.json()

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · qinglite_platform.py (reported line 21)May include surrounding context.

python
}

    try:
        response = requests.post(url, json=payload, headers=headers)
        response.raise_for_status()  # Raise an exception for HTTP errors
        response_json = response.json()

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · qinglite_platform.py (reported line 55)May include surrounding context.

python
}

    try:
        response = requests.post(url, json=payload, headers=headers)
        response.raise_for_status()  # Raise an exception for HTTP errors
        response_json = response.json()

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The code forces all logins to use the +86 country prefix, which imposes a specific locale assumption in the skill behavior. There is no user opt-in, alternative locale handling, or explanation that this skill is intentionally restricted to that region.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The login function prints the returned authentication token directly to stdout, which can expose it through terminal history, shell logging, process supervisors, CI logs, or any wrapper that captures command output. Because the token appears to be sufficient to perform authenticated publish actions, disclosure can enable account misuse until the token expires or is revoked.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest says the skill can either log into qinglite.cn to obtain a token or use a token to publish作品, but this file only defines and invokes a login flow against the mobile login endpoint. There is no code here for any publish operation using a token, so the implemented behavior is narrower than the stated description.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.