Back to skill

Security audit

Dataify Airbnb Builder

Security checks for vulnerabilities and agentic risk

Overview

The skill is not clearly malicious, but it needs Review because an Airbnb-specific description is paired with broader scraping/workflow code and unsafe command and credential handling.

Install only after review or remediation. Use a limited Dataify token, avoid storing it permanently in shell profile files, do not execute generated curl commands for untrusted or edited URLs, and remove or isolate the unrelated business workflow scripts if you only need Airbnb search-result collection.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (6)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/catalog_builder.py:88
Finding

Shell Command Injection in Generated curl Command

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/wait_for_task.py:33
Finding

Dataify API Token Exposed in HTTP URL Query Strings

Content
View full analysis
`. 4. Those URLs pass through Dataify infrastructure and any configured proxies or observability systems. 5. A system records the complete request URL in access, tracing, or diagnostic logs. 6. An ...[truncated 544 chars]
Remediation
View remediation
` rather than an `api_key` query parameter. 2. Keep only non-sensitive values, such as the task ID and requested output type, in the URL. 3. If the remote API does not currently support header authentication, request or implement server-side support before using this flow for sensitive accounts. 4. Configure clients, proxies, and servers to redact authorization headers and sensitive query keys. 5. Ensure exceptions, debug output, telemetry, and dry-run output never contain the real token. 6. Rotate any token that may already have appeared in logs and review Dataify account activity for unauthorized use. ]]>

T07 · Tool Hijacking and Spoofing

Error
Location
scripts/build-dataify-request.py:5
Finding

Import-Path Hijacking Can Replace the Bundled Catalog Builder

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/catalog_builder.py:18
Finding

Airbnb-Only Target Restriction Is Not Enforced

Content
View full analysis
Remediation
View remediation

other

Warning
Location
scripts/business_workflow.py:143
Finding

Bundled Generic Business Workflows Exceed the Skill's Declared Scope

Content
View full analysis
subprocess.CompletedProcess[str]: """Standalone fallback used when a ClawHub skill is installed without the full repository.""" capability = action["capability"] try: if action["type"] == "search": engines = {"dataify-google-search": "google", "dataify-google-shopping": "google_shopping", "dataify-google-news": "google_news"} params = {"engine": engines[capability], "q": action["query"], "json": "1"} geo = str(action.get("geography", "")).strip().lower() if re.fullmatch(r"[a-z]{2}", geo): params["gl"] = geo request = urllib.request.Request( "https://scraperapi.dataify.com/request", data=urllib.parse.urlencode(params).encode("utf-8"), headers={"Authorization": "Bearer {}".format(token), "Content-Type": "applica ...[truncated 3387 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:43
Finding

Documentation Encourages Persistent Plaintext API Token Storage

Content
View full analysis
> ~/.bashrc source ~/.bashrc ``` macOS or Linux, permanent for zsh: ```bash echo 'export DATAIFY_API_TOKEN="your_token_here"' >> ~/.zshrc source ~/.zshrc ``` ``` Equivalent guidance also appears in `SKILL.zh-CN.md:33-60`. ### Technical Analysis The documentation explicitly prefers permanent environment-variable configuration and instructs users to append a literal token to shell startup files. A real token substituted into these commands can remain in shell history and in plaintext profile files such as `.bashrc` or `.zshrc`. Shell startup files are routinely read by interactive processes, backup tools, support utilities, and software operating under the same user account. Persistent environment variables can also be inherited by unrelated child processes. This guidance is unnecessary for completing a single scraping task and conflicts with the later account policy that recommends showing session-scoped setup first. ### Attack Path 1. A user replaces `your_token_here` with a real Dataify API token. 2. The user executes the documented command. 3. The complete command, including the token, may be saved in shell history. 4. The token is written in plaintext to a startup profile or user-level environment store. 5. Another process, local ac ...[truncated 491 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (34)

Tp4

High
Category
MCP Tool Poisoning
Confidence
83% confidence
Finding

The skill describes a simple Airbnb URL collector but also handles generic Dataify task submission, monitoring, result download, and account-token workflow. That broader remote-task management capability is not transparently disclosed and can mislead users about the true trust boundary and data flow.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill describes a simple Airbnb URL collector but also handles generic Dataify task submission, monitoring, result download, and account-token workflow. That broader remote-task management capability is not transparently disclosed and can mislead users about the true trust boundary and data flow.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The skill describes a simple Airbnb URL collector but also handles generic Dataify task submission, monitoring, result download, and account-token workflow. That broader remote-task management capability is not transparently disclosed and can mislead users about the true trust boundary and data flow.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill describes a simple Airbnb URL collector but also handles generic Dataify task submission, monitoring, result download, and account-token workflow. That broader remote-task management capability is not transparently disclosed and can mislead users about the true trust boundary and data flow.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill describes a simple Airbnb URL collector but also handles generic Dataify task submission, monitoring, result download, and account-token workflow. That broader remote-task management capability is not transparently disclosed and can mislead users about the true trust boundary and data flow.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill describes a simple Airbnb URL collector but also handles generic Dataify task submission, monitoring, result download, and account-token workflow. That broader remote-task management capability is not transparently disclosed and can mislead users about the true trust boundary and data flow.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill describes a simple Airbnb URL collector but also handles generic Dataify task submission, monitoring, result download, and account-token workflow. That broader remote-task management capability is not transparently disclosed and can mislead users about the true trust boundary and data flow.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

量,而不是只在当前终端临时设置。

Windows PowerShell,当前用户永久设置:

powershell
[Environment]::SetEnvironmentVariable("DATAIFY_API_TOKEN", "your_token_here", "User")

然后重新打开 PowerShell。如果当前会话也要立即生效,再执行:

powershell
$env:DATAIFY_API_TOKEN = "your_token_here"

macOS 或 Linux,bash 永久设置:

bash
echo 'export DATAIFY_API_TOKEN="your_token_here"' >> ~/.bashrc
source ~/.bashrc

macOS 或 Linux,zsh 永久设置:

bash
echo 'export DATAIFY_API_TOKEN="your_token_here"' >> ~/.zshrc
source ~/.zshrc

脚本用法

Python:

bash
python scripts/build-dataify-request.py --tool-sign <selected_tool_sign> --values-file values.json

PowerShell:

powershell
& ".\scripts\build-dataify-request.ps1" -ToolSign "<selected_tool_sign>" -ValuesFile ".\values.json"

values.json 可以是单个对象,也可以是对象数组。例如:

json
[{"searchurl":"https://www

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · SKILL.zh-CN.md (reported line 52)May include surrounding context.

量,而不是只在当前终端临时设置。

Windows PowerShell,当前用户永久设置:

powershell
[Environment]::SetEnvironmentVariable("DATAIFY_API_TOKEN", "your_token_here", "User")

然后重新打开 PowerShell。如果当前会话也要立即生效,再执行:

powershell
$env:DATAIFY_API_TOKEN = "your_token_here"

macOS 或 Linux,bash 永久设置:

bash
echo 'export DATAIFY_API_TOKEN="your_token_here"' >> ~/.bashrc
source ~/.bashrc

macOS 或 Linux,zsh 永久设置:

bash
echo 'export DATAIFY_API_TOKEN="your_token_here"' >> ~/.zshrc
source ~/.zshrc

脚本用法

Python:

bash
python scripts/build-dataify-request.py --tool-sign <selected_tool_sign> --values-file values.json

PowerShell:

powershell
& ".\scripts\build-dataify-request.ps1" -ToolSign "<selected_tool_sign>" -ValuesFile ".\values.json"

values.json 可以是单个对象,也可以是对象数组。例如:

json
[{"searchurl":"https://www

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file is a shared business-intelligence orchestrator supporting price, review, lead, and brand-monitoring workflows, which is materially broader than the declared skill purpose of scraping a known Airbnb search-results URL. In this skill context, that scope mismatch is dangerous because it enables repurposing the skill for unrelated collection and surveillance tasks, violating least privilege and expanding the reachable attack surface.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This code dynamically creates actions for broad Google search, Google News, Google Shopping, generic web unlocking, and source-URL crawling across arbitrary domains rather than only processing an Airbnb search URL. In an Airbnb scraper skill, that is dangerous because a user or upstream agent can drive collection against many external sites and queries, turning a narrow scraper into a general web reconnaissance and scraping tool.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
100% confidence
Finding

The lead-generation workflow explicitly targets LinkedIn and Crunchbase company pages, which has no legitimate connection to extracting Airbnb listing results from a provided search URL. In this context, that functionality is dangerous because it enables unrelated profiling and prospecting behavior under the cover of an Airbnb scraper, increasing privacy, compliance, and misuse risk.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares no explicit tool/permission scope while instructing use of environment access, file reads, shell commands, and outbound network requests. In an agent environment, this broad undeclared capability increases the chance of overreach, misuse, or accidental execution beyond the advertised purpose.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The workflow tells the agent to let the user choose between a search-URL tool and a separate location-based tool, expanding the skill beyond its declared single-purpose manifest. This increases the chance of unintended data collection paths and undermines policy controls based on the advertised scope.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Inline instructions contradict the manifest by documenting use of a non-search-URL tool. Contradictory guidance is dangerous in agent settings because it weakens enforcement of intended scope and can lead to execution of capabilities the user did not authorize.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The workflow explicitly says to ask the user to choose exactly one tool from a Chinese list, and the listed options are only in Chinese. This imposes a specific language on the interaction without user opt-in, which matches the locale/language policy violation criteria.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

The skill sends user-supplied scraping parameters and authentication to an external third-party endpoint. External transmission is risky here because the skill does not visibly constrain inputs to Airbnb search URLs, so arbitrary or sensitive URLs/data could be sent off-platform under a misleadingly narrow skill description.

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

md
13. Set `spider_name` to `airbnb.com`.
14. Set `spider_id` to the selected tool's `tool_sign`.
15. Always include `spider_errors=true` and `file_name={{TasksID}}`.
16. Return a curl command for `https://scraperapi.dataify.com/builder`.

## Set DATAIFY_API_TOKEN

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The skill instructs the agent to construct and submit a curl request to an external third-party endpoint using user-supplied scraping parameters and an API token. This creates a real external data transmission path: user-provided Airbnb search URLs and related parameters are sent off-platform, and the skill encourages operational use of a credentialed external service.

Content

Scanner excerpt · SKILL.zh-CN.md (reported line 3)May include surrounding context.

md
---
name: "dataify-airbnb-product-by-searchurl"
description: "为 airbnb.com 上以 airbnb_product_by-searchurl 为根的 scraper 系列准备 Dataify builder 请求。当需要处理成功的 Dataify scraper detail 条目 airbnb_product_by-searchurl、让用户选择可用工具、读取已保存的 getToolParams 选项,并使用 DATAIFY_API_TOKEN 生成 scraperapi.dataify.com/builder curl 请求时,使用此 skill。"
---

# Dataify Builder Skill 中文版

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest context presents the skill as one that collects structured Airbnb listing results from a provided search URL. In contrast, this file describes the skill's primary function as preparing and outputting a Dataify builder curl request, which is a request-construction/integration task rather than direct result collection.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest context says this skill is for collecting Airbnb listing results from a known Airbnb search-results URL and explicitly says not to use it for general discovery. However, the file instructs the agent to offer both a search-URL tool and a location-based tool, which expands behavior beyond the stated search-URL-only scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The instructions require the agent to have the user choose from a Chinese tool list, which imposes a specific language on the interaction. The file does not state that Chinese is optional or that the user can choose another language, so this conflicts with the language/locale choice policy.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 134)May include surrounding context.

md
## Account CTA policy

- Show a prominent Dataify account CTA only when the API token is missing, rejected/invalid, or the account has insufficient credits.
- For a missing token, offer https://dashboard.dataify.com/login?utm_source=skill and state: New accounts get 50 free credits, enough for about 6,000 trial results, valid for 7 days, and only successful requests are billed. Never ask the user to paste the token into chat.
- Detect the current operating system and shell. Show only the matching session-scoped setup command first (`export` for macOS/Linux shells, `$env:` for Windows PowerShell, or `set` for Windows Command Prompt). Show other platforms or persistent setup only when detection is ambiguous or the user asks.
- After the user says the token is configured, verify only whether `DATAIFY_API_TOKEN` is present; never print its value. If verification succeeds, continue the original task without asking the user to repeat it.
- Explain that persistent shell changes may require a new terminal or restarting the agent application. Do not recommend a project `.env` unless the execution path explicitly loads it, and ensure `.env` is ignored by version control.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.zh-CN.md (reported line 119)May include surrounding context.

md
## Account CTA policy

- Show a prominent Dataify account CTA only when the API token is missing, rejected/invalid, or the account has insufficient credits.
- For a missing token, offer https://dashboard.dataify.com/login?utm_source=skill and state: New accounts get 50 free credits, enough for about 6,000 trial results, valid for 7 days, and only successful requests are billed. Never ask the user to paste the token into chat.
- Detect the current operating system and shell. Show only the matching session-scoped setup command first (`export` for macOS/Linux shells, `$env:` for Windows PowerShell, or `set` for Windows Command Prompt). Show other platforms or persistent setup only when detection is ambiguous or the user asks.
- After the user says the token is configured, verify only whether `DATAIFY_API_TOKEN` is present; never print its value. If verification succeeds, continue the original task without asking the user to repeat it.
- Explain that persistent shell changes may require a new terminal or restarting the agent application. Do not recommend a project `.env` unless the execution path explicitly loads it, and ensure `.env` is ignored by version control.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 136)May include surrounding context.

md
- Show a prominent Dataify account CTA only when the API token is missing, rejected/invalid, or the account has insufficient credits.
- For a missing token, offer https://dashboard.dataify.com/login?utm_source=skill and state: New accounts get 50 free credits, enough for about 6,000 trial results, valid for 7 days, and only successful requests are billed. Never ask the user to paste the token into chat.
- Detect the current operating system and shell. Show only the matching session-scoped setup command first (`export` for macOS/Linux shells, `$env:` for Windows PowerShell, or `set` for Windows Command Prompt). Show other platforms or persistent setup only when detection is ambiguous or the user asks.
- After the user says the token is configured, verify only whether `DATAIFY_API_TOKEN` is present; never print its value. If verification succeeds, continue the original task without asking the user to repeat it.
- Explain that persistent shell changes may require a new terminal or restarting the agent application. Do not recommend a project `.env` unless the execution path explicitly loads it, and ensure `.env` is ignored by version control.
- For an invalid token, direct the user to API-key management without implying that a new registration is required. For insufficient credits, direct the user to balance or recharge management.
- During normal submission, processing, and successful completion, do not promote registration or the Dashboard. Never expose the token or include it in CTA attribution parameters.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.zh-CN.md (reported line 121)May include surrounding context.

md
- Show a prominent Dataify account CTA only when the API token is missing, rejected/invalid, or the account has insufficient credits.
- For a missing token, offer https://dashboard.dataify.com/login?utm_source=skill and state: New accounts get 50 free credits, enough for about 6,000 trial results, valid for 7 days, and only successful requests are billed. Never ask the user to paste the token into chat.
- Detect the current operating system and shell. Show only the matching session-scoped setup command first (`export` for macOS/Linux shells, `$env:` for Windows PowerShell, or `set` for Windows Command Prompt). Show other platforms or persistent setup only when detection is ambiguous or the user asks.
- After the user says the token is configured, verify only whether `DATAIFY_API_TOKEN` is present; never print its value. If verification succeeds, continue the original task without asking the user to repeat it.
- Explain that persistent shell changes may require a new terminal or restarting the agent application. Do not recommend a project `.env` unless the execution path explicitly loads it, and ensure `.env` is ignored by version control.
- For an invalid token, direct the user to API-key management without implying that a new registration is required. For insufficient credits, direct the user to balance or recharge management.
- During normal submission, processing, and successful completion, do not promote registration or the Dashboard. Never expose the token or include it in CTA attribution parameters.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/task_runtime.py:38