Back to skill

Security audit

中国法律法规检索(得理科技)

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent legal-research helper, but its API script disables TLS verification while sending an API key and legal queries, so it needs review before installation.

Review or fix the TLS behavior before installing: remove the disabled certificate checks, rotate any key used with this version, and assume searches are sent to Delilegal with the configured API key. Treat outputs as retrieval aids only and verify important legal conclusions against official texts.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/search_laws.py:97
Finding

TLS Certificate and Hostname Verification Disabled for Authenticated API Requests

Content
View full analysis

Vulnerability Details

File Location: scripts/search_laws.py, lines 97–114
Vulnerability Type: Improper TLS certificate validation
Risk Level: High

python
req = urllib.request.Request(
    API_URL,
    data=payload,
    headers={
        "Content-Type": "application/json",
        "Authorization": "Bearer " + apikey
    },
    method="POST",
)

ctx = ssl.create_default_context()
ctx.check_hostname = False
ctx.verify_mode = ssl.CERT_NONE

try:
    with urllib.request.urlopen(req, timeout=30, context=ctx) as resp:
        return json.loads(resp.read().decode("utf-8"))

Technical Analysis

The code creates a default TLS context but then explicitly disables both server hostname validation and certificate-chain verification:

  • ctx.check_hostname = False permits a certificate issued for an unrelated hostname.
  • ctx.verify_mode = ssl.CERT_NONE accepts certificates that are self-signed, expired, untrusted, or otherwise invalid.

Consequently, HTTPS encrypts the connection without reliably authenticating the remote server. An attacker capable of intercepting or redirecting network traffic can impersonate platform.delilegal.com using an arbitrary certificate.

The affected request carries two sensitive or integrity-relevant values:

  1. The configured API key in the Authorization: Bearer header.
  2. The user's legal-search query in the JSON request body.

Because the response is also accepted over the unauthenticated connection and formatted as legal-retrieval output, an interceptor can return manipulated legal records that may be presented to the user as database results.

Attack Path

  1. A user places a valid API key in config.json and invokes the legal-search script.
  2. An attacker gains a position from which traffic can be intercepted or redirected, such as a compromised network gateway, malicious Wi-Fi access point, poisoned DNS resolver, or hostile proxy.
  3. T ...[truncated 1512 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the statements that disable TLS validation:

    • ctx.check_hostname = False
    • ctx.verify_mode = ssl.CERT_NONE
  2. Prefer the standard verified HTTPS behavior:

    python
    try:
        with urllib.request.urlopen(req, timeout=30) as resp:
            return json.loads(resp.read().decode("utf-8"))
    
  3. If an explicit SSL context is required, retain secure defaults without modifying verification settings:

    python
    ctx = ssl.create_default_context()
    
    try:
        with urllib.request.urlopen(req, timeout=30, context=ctx) as resp:
            return json.loads(resp.read().decode("utf-8"))
    
  4. Treat certificate or hostname validation failures as hard errors. Do not retry using an unverified context or offer an insecure fallback.

  5. Ensure the runtime environment has a current trusted CA bundle. If the service requires a private CA, load only that specific trusted CA using ssl.create_default_context(cafile=...) rather than disabling verification globally.

  6. Rotate any API key that has previously been transmitted using the vulnerable implementation, especially if the script was used on untrusted networks.

  7. Prefer loading the API key from an environment variable or managed secret store instead of a project file. If config.json remains supported, restrict its filesystem permissions and exclude it from version control.

  8. Add an automated test that connects to a server presenting an invalid or hostname-mismatched certificate and verifies that the request fails.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill invokes local file access and outbound network access but does not declare any explicit tool scope or permissions boundaries. This increases the chance of over-broad execution in hosts that rely on manifest-level restrictions, allowing the skill to read configuration files and call external services without transparent least-privilege controls.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest description is entirely framed in Chinese and presents the skill as operating through Chinese trigger phrases and outputs, but it does not state that the skill is China-only or otherwise justify a Chinese-only locale requirement. Under the policy, language constraints should either be optional for the user or clearly documented as justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file contains all headings, user inputs, workflow descriptions, and output examples exclusively in Chinese. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a locale-policy issue unless the restriction is explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Manifest将该技能描述为法规检索、条款查找、时效核实和法规对比工具,核心能力应是提供法规信息检索结果。L158-L168 的“维权路径建议”则从检索扩展到面向具体争议的行动建议与程序性指导,属于法律问题处置建议而非单纯法规检索输出。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script documentation states that basic keyword searches '默认只返回有效法规', but the request payload contains no timeliness or validity filter. In a legal-retrieval context, this can mislead users into relying on repealed or invalid laws, creating integrity and compliance risk because the tool appears to guarantee a safety property it does not enforce.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script automatically loads an API key from config.json and sends user queries to a third-party legal API without any runtime disclosure or consent step. In this skill context, user-entered queries may contain sensitive legal matters, so silent outbound transmission with credentials creates privacy, policy, and data-handling risk even though it is expected functionality rather than overtly malicious behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This markdown file presents all content exclusively in Chinese and does not indicate that users can choose another language or locale. Under the policy rule for natural-language constraints, forcing a specific language without user opt-in can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

All user-facing natural-language instructions, help text, and output are written only in Chinese, with no indication that another language can be selected. Under the policy for natural-language violations, forcing a specific language without user opt-in can be a locale-policy issue unless the regional constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.insecure_tls_verification

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
scripts/search_laws.py:109