Back to skill

Security audit

IP Lookup Tool

Security checks for vulnerabilities and agentic risk

Overview

This skill performs a narrow public IP and approximate location lookup using disclosed third-party web services, with privacy considerations but no evidence of hidden persistence, credential access, or malicious behavior.

Install this only if you are comfortable with a public IP lookup tool contacting third-party services such as ipinfo.io, ifconfig.co, ip.sb, and OpenStreetMap. Those services may receive your public IP, request timing, and approximate location lookup data. The skill appears narrow and non-persistent, but a clearer privacy notice would be preferable.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs the agent to send a request to third-party IP geolocation services to determine the user's public IP and approximate location, but it does not explicitly require informing the user that their network metadata will be disclosed to an external provider. This creates a real privacy issue because the request itself reveals the user's public IP and can associate the query with timing and user activity at those external services.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

Referencing and using an external endpoint such as api.ip.sb/geoip causes transmission of the user's public IP and request metadata to a third party. In this skill's context, that transmission is functionally necessary for the feature, but it is still a genuine data-exposure risk if done without transparency, consent, or vetting of the external provider.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

md
- 只做一次 HTTP 请求,优先顺序:
  1. `https://ipinfo.io/json`
  2. `https://ifconfig.co/json`
  3. `https://api.ip.sb/geoip`
- 若主源失败,自动降级到下一源
- 不要对精确位置做过度解读,只提供大致城市/国家信息
- 明确说明“这是公网出口 IP,不一定等于本机局域网 IP”

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code hard-codes an Accept-Language preference for zh-CN and returns human-readable messages entirely in Chinese, which imposes a specific language/locale by default. The policy allows locale constraints only when users are given a choice or the restriction is clearly justified, neither of which is evident in this file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill sends the user's public IP lookup requests to multiple third-party services and may also send derived location coordinates to OpenStreetMap for reverse geocoding. Even though this is the feature's purpose, it transmits network-identifying and geolocation-related data off-device without any visible consent, warning, or privacy notice in the code path, which creates a real privacy/security concern.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This finding identifies a concrete external transmission endpoint used to send requests containing the caller's apparent public network identity to a third party. In this skill's context, the transmission is intentional to implement IP lookup, but it is still a real privacy-relevant data flow that could expose user IP, timing, and usage metadata to external services.

Content

Scanner excerpt · scripts/ip_lookup.js (reported line 51)May include surrounding context.

js
const sources = [
    { url: 'https://ipinfo.io/json', source: 'ipinfo.io' },
    { url: 'https://ifconfig.co/json', source: 'ifconfig.co' },
    { url: 'https://api.ip.sb/geoip', source: 'ip.sb' }
  ];

  const errors = [];

Static analysis

No suspicious patterns detected.