T09 · Insecure Skill Coding Practices
- Location
scripts/catalog_builder.py:88- Finding
Shell Command Injection in Generated curl Command
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is not clearly malicious, but it needs Review because an Airbnb-specific description is paired with broader scraping/workflow code and unsafe command and credential handling.
Install only after review or remediation. Use a limited Dataify token, avoid storing it permanently in shell profile files, do not execute generated curl commands for untrusted or edited URLs, and remove or isolate the unrelated business workflow scripts if you only need Airbnb search-result collection.
scripts/catalog_builder.py:88Shell Command Injection in Generated curl Command
scripts/wait_for_task.py:33Dataify API Token Exposed in HTTP URL Query Strings
scripts/build-dataify-request.py:5Import-Path Hijacking Can Replace the Bundled Catalog Builder
scripts/catalog_builder.py:18Airbnb-Only Target Restriction Is Not Enforced
scripts/business_workflow.py:143Bundled Generic Business Workflows Exceed the Skill's Declared Scope
SKILL.md:43Documentation Encourages Persistent Plaintext API Token Storage
The skill describes a simple Airbnb URL collector but also handles generic Dataify task submission, monitoring, result download, and account-token workflow. That broader remote-task management capability is not transparently disclosed and can mislead users about the true trust boundary and data flow.
The skill describes a simple Airbnb URL collector but also handles generic Dataify task submission, monitoring, result download, and account-token workflow. That broader remote-task management capability is not transparently disclosed and can mislead users about the true trust boundary and data flow.
The skill describes a simple Airbnb URL collector but also handles generic Dataify task submission, monitoring, result download, and account-token workflow. That broader remote-task management capability is not transparently disclosed and can mislead users about the true trust boundary and data flow.
The skill describes a simple Airbnb URL collector but also handles generic Dataify task submission, monitoring, result download, and account-token workflow. That broader remote-task management capability is not transparently disclosed and can mislead users about the true trust boundary and data flow.
The skill describes a simple Airbnb URL collector but also handles generic Dataify task submission, monitoring, result download, and account-token workflow. That broader remote-task management capability is not transparently disclosed and can mislead users about the true trust boundary and data flow.
The skill describes a simple Airbnb URL collector but also handles generic Dataify task submission, monitoring, result download, and account-token workflow. That broader remote-task management capability is not transparently disclosed and can mislead users about the true trust boundary and data flow.
The skill describes a simple Airbnb URL collector but also handles generic Dataify task submission, monitoring, result download, and account-token workflow. That broader remote-task management capability is not transparently disclosed and can mislead users about the true trust boundary and data flow.
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
量,而不是只在当前终端临时设置。
Windows PowerShell,当前用户永久设置:
[Environment]::SetEnvironmentVariable("DATAIFY_API_TOKEN", "your_token_here", "User")
然后重新打开 PowerShell。如果当前会话也要立即生效,再执行:
$env:DATAIFY_API_TOKEN = "your_token_here"
macOS 或 Linux,bash 永久设置:
echo 'export DATAIFY_API_TOKEN="your_token_here"' >> ~/.bashrc
source ~/.bashrc
macOS 或 Linux,zsh 永久设置:
echo 'export DATAIFY_API_TOKEN="your_token_here"' >> ~/.zshrc
source ~/.zshrc
Python:
python scripts/build-dataify-request.py --tool-sign <selected_tool_sign> --values-file values.json
PowerShell:
& ".\scripts\build-dataify-request.ps1" -ToolSign "<selected_tool_sign>" -ValuesFile ".\values.json"
values.json 可以是单个对象,也可以是对象数组。例如:
[{"searchurl":"https://www
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
量,而不是只在当前终端临时设置。
Windows PowerShell,当前用户永久设置:
[Environment]::SetEnvironmentVariable("DATAIFY_API_TOKEN", "your_token_here", "User")
然后重新打开 PowerShell。如果当前会话也要立即生效,再执行:
$env:DATAIFY_API_TOKEN = "your_token_here"
macOS 或 Linux,bash 永久设置:
echo 'export DATAIFY_API_TOKEN="your_token_here"' >> ~/.bashrc
source ~/.bashrc
macOS 或 Linux,zsh 永久设置:
echo 'export DATAIFY_API_TOKEN="your_token_here"' >> ~/.zshrc
source ~/.zshrc
Python:
python scripts/build-dataify-request.py --tool-sign <selected_tool_sign> --values-file values.json
PowerShell:
& ".\scripts\build-dataify-request.ps1" -ToolSign "<selected_tool_sign>" -ValuesFile ".\values.json"
values.json 可以是单个对象,也可以是对象数组。例如:
[{"searchurl":"https://www
The file is a shared business-intelligence orchestrator supporting price, review, lead, and brand-monitoring workflows, which is materially broader than the declared skill purpose of scraping a known Airbnb search-results URL. In this skill context, that scope mismatch is dangerous because it enables repurposing the skill for unrelated collection and surveillance tasks, violating least privilege and expanding the reachable attack surface.
This code dynamically creates actions for broad Google search, Google News, Google Shopping, generic web unlocking, and source-URL crawling across arbitrary domains rather than only processing an Airbnb search URL. In an Airbnb scraper skill, that is dangerous because a user or upstream agent can drive collection against many external sites and queries, turning a narrow scraper into a general web reconnaissance and scraping tool.
The lead-generation workflow explicitly targets LinkedIn and Crunchbase company pages, which has no legitimate connection to extracting Airbnb listing results from a provided search URL. In this context, that functionality is dangerous because it enables unrelated profiling and prospecting behavior under the cover of an Airbnb scraper, increasing privacy, compliance, and misuse risk.
The skill declares no explicit tool/permission scope while instructing use of environment access, file reads, shell commands, and outbound network requests. In an agent environment, this broad undeclared capability increases the chance of overreach, misuse, or accidental execution beyond the advertised purpose.
The workflow tells the agent to let the user choose between a search-URL tool and a separate location-based tool, expanding the skill beyond its declared single-purpose manifest. This increases the chance of unintended data collection paths and undermines policy controls based on the advertised scope.
Inline instructions contradict the manifest by documenting use of a non-search-URL tool. Contradictory guidance is dangerous in agent settings because it weakens enforcement of intended scope and can lead to execution of capabilities the user did not authorize.
The workflow explicitly says to ask the user to choose exactly one tool from a Chinese list, and the listed options are only in Chinese. This imposes a specific language on the interaction without user opt-in, which matches the locale/language policy violation criteria.
The skill sends user-supplied scraping parameters and authentication to an external third-party endpoint. External transmission is risky here because the skill does not visibly constrain inputs to Airbnb search URLs, so arbitrary or sensitive URLs/data could be sent off-platform under a misleadingly narrow skill description.
13. Set `spider_name` to `airbnb.com`.
14. Set `spider_id` to the selected tool's `tool_sign`.
15. Always include `spider_errors=true` and `file_name={{TasksID}}`.
16. Return a curl command for `https://scraperapi.dataify.com/builder`.
## Set DATAIFY_API_TOKEN
The skill instructs the agent to construct and submit a curl request to an external third-party endpoint using user-supplied scraping parameters and an API token. This creates a real external data transmission path: user-provided Airbnb search URLs and related parameters are sent off-platform, and the skill encourages operational use of a credentialed external service.
---
name: "dataify-airbnb-product-by-searchurl"
description: "为 airbnb.com 上以 airbnb_product_by-searchurl 为根的 scraper 系列准备 Dataify builder 请求。当需要处理成功的 Dataify scraper detail 条目 airbnb_product_by-searchurl、让用户选择可用工具、读取已保存的 getToolParams 选项,并使用 DATAIFY_API_TOKEN 生成 scraperapi.dataify.com/builder curl 请求时,使用此 skill。"
---
# Dataify Builder Skill 中文版
The manifest context presents the skill as one that collects structured Airbnb listing results from a provided search URL. In contrast, this file describes the skill's primary function as preparing and outputting a Dataify builder curl request, which is a request-construction/integration task rather than direct result collection.
The manifest context says this skill is for collecting Airbnb listing results from a known Airbnb search-results URL and explicitly says not to use it for general discovery. However, the file instructs the agent to offer both a search-URL tool and a location-based tool, which expands behavior beyond the stated search-URL-only scope.
The instructions require the agent to have the user choose from a Chinese tool list, which imposes a specific language on the interaction. The file does not state that Chinese is optional or that the user can choose another language, so this conflicts with the language/locale choice policy.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
## Account CTA policy
- Show a prominent Dataify account CTA only when the API token is missing, rejected/invalid, or the account has insufficient credits.
- For a missing token, offer https://dashboard.dataify.com/login?utm_source=skill and state: New accounts get 50 free credits, enough for about 6,000 trial results, valid for 7 days, and only successful requests are billed. Never ask the user to paste the token into chat.
- Detect the current operating system and shell. Show only the matching session-scoped setup command first (`export` for macOS/Linux shells, `$env:` for Windows PowerShell, or `set` for Windows Command Prompt). Show other platforms or persistent setup only when detection is ambiguous or the user asks.
- After the user says the token is configured, verify only whether `DATAIFY_API_TOKEN` is present; never print its value. If verification succeeds, continue the original task without asking the user to repeat it.
- Explain that persistent shell changes may require a new terminal or restarting the agent application. Do not recommend a project `.env` unless the execution path explicitly loads it, and ensure `.env` is ignored by version control.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
## Account CTA policy
- Show a prominent Dataify account CTA only when the API token is missing, rejected/invalid, or the account has insufficient credits.
- For a missing token, offer https://dashboard.dataify.com/login?utm_source=skill and state: New accounts get 50 free credits, enough for about 6,000 trial results, valid for 7 days, and only successful requests are billed. Never ask the user to paste the token into chat.
- Detect the current operating system and shell. Show only the matching session-scoped setup command first (`export` for macOS/Linux shells, `$env:` for Windows PowerShell, or `set` for Windows Command Prompt). Show other platforms or persistent setup only when detection is ambiguous or the user asks.
- After the user says the token is configured, verify only whether `DATAIFY_API_TOKEN` is present; never print its value. If verification succeeds, continue the original task without asking the user to repeat it.
- Explain that persistent shell changes may require a new terminal or restarting the agent application. Do not recommend a project `.env` unless the execution path explicitly loads it, and ensure `.env` is ignored by version control.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
- Show a prominent Dataify account CTA only when the API token is missing, rejected/invalid, or the account has insufficient credits.
- For a missing token, offer https://dashboard.dataify.com/login?utm_source=skill and state: New accounts get 50 free credits, enough for about 6,000 trial results, valid for 7 days, and only successful requests are billed. Never ask the user to paste the token into chat.
- Detect the current operating system and shell. Show only the matching session-scoped setup command first (`export` for macOS/Linux shells, `$env:` for Windows PowerShell, or `set` for Windows Command Prompt). Show other platforms or persistent setup only when detection is ambiguous or the user asks.
- After the user says the token is configured, verify only whether `DATAIFY_API_TOKEN` is present; never print its value. If verification succeeds, continue the original task without asking the user to repeat it.
- Explain that persistent shell changes may require a new terminal or restarting the agent application. Do not recommend a project `.env` unless the execution path explicitly loads it, and ensure `.env` is ignored by version control.
- For an invalid token, direct the user to API-key management without implying that a new registration is required. For insufficient credits, direct the user to balance or recharge management.
- During normal submission, processing, and successful completion, do not promote registration or the Dashboard. Never expose the token or include it in CTA attribution parameters.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
- Show a prominent Dataify account CTA only when the API token is missing, rejected/invalid, or the account has insufficient credits.
- For a missing token, offer https://dashboard.dataify.com/login?utm_source=skill and state: New accounts get 50 free credits, enough for about 6,000 trial results, valid for 7 days, and only successful requests are billed. Never ask the user to paste the token into chat.
- Detect the current operating system and shell. Show only the matching session-scoped setup command first (`export` for macOS/Linux shells, `$env:` for Windows PowerShell, or `set` for Windows Command Prompt). Show other platforms or persistent setup only when detection is ambiguous or the user asks.
- After the user says the token is configured, verify only whether `DATAIFY_API_TOKEN` is present; never print its value. If verification succeeds, continue the original task without asking the user to repeat it.
- Explain that persistent shell changes may require a new terminal or restarting the agent application. Do not recommend a project `.env` unless the execution path explicitly loads it, and ensure `.env` is ignored by version control.
- For an invalid token, direct the user to API-key management without implying that a new registration is required. For insufficient credits, direct the user to balance or recharge management.
- During normal submission, processing, and successful completion, do not promote registration or the Dashboard. Never expose the token or include it in CTA attribution parameters.
Detected: suspicious.exposed_secret_literal