Back to skill

Security audit

中国裁判文书案例检索(得理科技)

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it says, but its case-search script disables TLS verification while sending API credentials and potentially sensitive legal case text to an external service.

Review this skill before installing or using it with real case materials. Treat all keywords and long-text inputs as sent to Deli Legal's external API, redact confidential or personal information first, and do not use a sensitive API key unless the TLS verification issue is fixed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/search_cases.py:115
Finding

TLS Certificate and Hostname Verification Disabled

Content
View full analysis

Vulnerability Details

File Location: scripts/search_cases.py, lines 115–120
Vulnerability Type: Improper TLS certificate validation
Risk Level: High

Vulnerable Code

python
ctx = ssl.create_default_context()
ctx.check_hostname = False
ctx.verify_mode = ssl.CERT_NONE

try:
    with urllib.request.urlopen(req, timeout=30, context=ctx) as resp:
        return json.loads(resp.read().decode("utf-8"))

Technical Analysis

The script creates a TLS context but explicitly disables both certificate-chain verification and hostname verification. Consequently, HTTPS encrypts the connection without authenticating that the remote endpoint is the legitimate Deli Legal API server.

An attacker capable of intercepting or redirecting network traffic can present an arbitrary certificate, which the client will accept. This enables a man-in-the-middle attack against requests sent to the configured API endpoint.

Each affected request contains the API key in the Authorization: Bearer header. Requests may also contain sensitive legal-search keywords or full case materials supplied through the --long-text option. The attacker can read these values and return manipulated API responses that the script will present as legitimate case-search results.

Attack Path

  1. A user invokes the script with a search query or sensitive case material.
  2. The script reads the API key from config.json and places it in the Bearer authorization header.
  3. An attacker with a network interception or traffic-redirection position redirects or intercepts the connection to the API.
  4. The attacker presents an untrusted certificate for an attacker-controlled endpoint.
  5. Because certificate and hostname verification are disabled, the script accepts the certificate.
  6. The attacker captures the API key and submitted legal material.
  7. The attacker may return forged JSON responses, causing fabricated or altered legal case information to be displayed as API output.

Im

...[truncated 597 chars]

Remediation
View remediation

Remediation Suggestions

Remove the statements that disable hostname and certificate verification. Use Python's default verified TLS behavior:

python
try:
    with urllib.request.urlopen(req, timeout=30) as resp:
        return json.loads(resp.read().decode("utf-8"))

Alternatively, retain an explicit default context without weakening its security settings:

python
ctx = ssl.create_default_context()

try:
    with urllib.request.urlopen(req, timeout=30, context=ctx) as resp:
        return json.loads(resp.read().decode("utf-8"))

Additional hardening measures:

  1. Allow certificate-validation failures to terminate the request rather than retrying insecurely.
  2. If a private certificate authority is required, configure its trusted CA bundle explicitly instead of using ssl.CERT_NONE.
  3. Store the API key in an environment variable or dedicated secret manager rather than a project file containing operational credentials.
  4. Rotate any API key that may have been used while verification was disabled.
  5. Add an automated test confirming that self-signed certificates and hostname mismatches are rejected.
  6. Avoid logging authorization headers or full legal-case materials in error and diagnostic output.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill invokes external network access and reads local configuration (config.json) but does not declare any explicit tool scope or allowed tools. That creates an authorization gap: an agent/runtime may grant broader capabilities than intended, making it harder to constrain or audit what the skill can access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest description is entirely written as a Chinese-only invocation and usage description for both legal professionals and general users, with no indication that other languages are supported or that language choice is optional. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill encourages users to upload full case materials for semantic matching and shows those materials being passed as long text to a search script, but it provides no warning about personal, confidential, or litigation-sensitive information. In a legal context, uploaded documents may contain names, ID numbers, addresses, account details, trade secrets, or sealed case facts, so sending them to downstream APIs or logs without minimization or consent creates a meaningful privacy and confidentiality risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill sends user-provided search keywords and especially long-form case text to an external third-party API, but the interface and output do not provide an explicit disclosure or consent step before transmission. In a legal workflow, those inputs may contain sensitive personal, contractual, or dispute details, so silent exfiltration to an external service creates a meaningful privacy and compliance risk even if the transmission channel were properly secured.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script explicitly disables both certificate validation and hostname verification before sending an authenticated HTTPS request. This allows a man-in-the-middle attacker to intercept or modify traffic, exposing the Bearer API key and potentially sensitive legal queries or returned case data. In the context of a legal case-retrieval skill, users may submit confidential fact patterns via --long-text, which makes transport security especially important.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file's natural-language instructions, examples, and outputs are entirely in Chinese, which can amount to forcing a specific language without user opt-in. The content does not indicate that the skill is intentionally region- or locale-specific, nor does it offer any language choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language strings in the module docstring, argument descriptions, errors, and output are exclusively in Chinese, with no option for users to select another language. This can violate language/locale policy when a skill mandates a specific language without documenting that constraint or offering opt-in.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.insecure_tls_verification

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
scripts/search_cases.py:113