Back to skill

Security audit

Dataify Airbnb Builder

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent Dataify request-building purpose, but its helper can expose API tokens and generate unsafe shell commands from user-supplied values.

Review before installing or using. Only use trusted input files, avoid running generated curl commands that contain untrusted parameter values, do not share generated output because it may include the live API token, prefer session-scoped or managed secret storage over shell-profile persistence, and rotate any token that has already appeared in logs or transcripts.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/build-dataify-request.py:66
Finding

Shell Command Injection Through Unescaped Scraper Parameters

Content
View full analysis
List[Dict[str, Any]]: param_defs = {item["param"]: item for item in tool.get("params", [])} mapped_rows: List[Dict[str, Any]] = [] for row in rows: mapped: Dict[str, Any] = {} for key, value in row.items(): param_def = param_defs.get(key) final_value = value if param_def and param_def.get("input_mode") == "select": for option in param_def.get("options", []): if value in { option.get("label"), option.get("submitted_value"), option.get("raw_value"), option.get("raw_type_value"), }: final_value = option.get("submitted_value") break mapped[key] = final_value mapped_rows.append(mapped) return mapped_rows ``` ```python def build_curl(tool: Dict[str, Any], spider_parameters_json: str) -> str: token = os.environ.get("DATAIFY_API_TOKEN", "").strip() if not token: raise SystemExit( "DATAIFY_API_TOKEN is not set. Sign in at https://dashboard.dataify.com?utm_source=skill to obtain it, then export it as an environment variable." ) parts = [ "curl -X POST 'https://scraperapi.dataify.com/builder'", f" -H 'Authorization: Bearer {token}'", " -H 'Content-Type: application/x-www-form-urlencoded'", f" -d 'spider_name={tool['spider_name']}'", f" -d 'spider_id={tool['tool_sign']}'", f" -d 'spider_parameters={spider_parameters_json}'", " -d 'spider_errors=true'", " -d ...[truncated 3058 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/build-dataify-request.py:53
Finding

Bearer Token Exposed in Generated Command Output

Content
View full analysis
str: token = os.environ.get("DATAIFY_API_TOKEN", "").strip() if not token: raise SystemExit( "DATAIFY_API_TOKEN is not set. Sign in at https://dashboard.dataify.com?utm_source=skill to obtain it, then export it as an environment variable." ) parts = [ "curl -X POST 'https://scraperapi.dataify.com/builder'", f" -H 'Authorization: Bearer {token}'", " -H 'Content-Type: application/x-www-form-urlencoded'", f" -d 'spider_name={tool['spider_name']}'", f" -d 'spider_id={tool['tool_sign']}'", f" -d 'spider_parameters={spider_parameters_json}'", " -d 'spider_errors=true'", " -d 'file_name={{TasksID}}'", ] return " \\\n".join(parts) ``` ```python print(build_curl(tool, spider_parameters_json)) ``` ### Technical Analysis The helper reads `DATAIFY_API_TOKEN` from the process environment and interpolates its actual value into the generated command: ```python f" -H 'Authorization: Bearer {token}'" ``` The complete command is then written to standard output. As a result, the bearer credential can be captured in: - Agent conversation transcripts. - Terminal scrollback and session recordings. - CI/CD logs. - Redirected output files. - Debugging or monitoring systems that capture standard output. - Clipboard contents or messages when generated commands are shared. This behavior is unnecessary. The documented command shape in `SKILL.md` uses `Bearer $DATAIFY_API_TOKEN`, which allows the shell to resolve the token only when the command runs rather than embedding it in the generated text. ### Attack Path 1. A user sets a valid `DATAIFY_API_TOKEN` in the environ ...[truncated 1193 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 1)May include surrounding context.

md
---
name: "dataify-airbnb-product-by-searchurl"
description: "Prepare Dataify builder requests for the airbnb.com scraper family rooted at airbnb_product_by-searchurl. Use  when needs to work with the successful Dataify scraper detail entry for airbnb_product_by-searchurl, let the user choose one of its available tools, read saved getToolParams options, and generate a scraperapi.dataify.com/builder curl request with DATAIFY_API_TOKEN."
---

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

the token only for the current terminal session.

Windows PowerShell, permanent for the current user:

powershell
[Environment]::SetEnvironmentVariable("DATAIFY_API_TOKEN", "your_token_here", "User")

Then reopen PowerShell. If the current session also needs the token immediately, run:

powershell
$env:DATAIFY_API_TOKEN = "your_token_here"

macOS or Linux, permanent for bash:

bash
echo 'export DATAIFY_API_TOKEN="your_token_here"' >> ~/.bashrc
source ~/.bashrc

macOS or Linux, permanent for zsh:

bash
echo 'export DATAIFY_API_TOKEN="your_token_here"' >> ~/.zshrc
source ~/.zshrc

Script usage

Python:

bash
python scripts/build-dataify-request.py --tool-sign <selected_tool_sign> --values-file values.json

PowerShell:

powershell
& ".\scripts\build-dataify-request.ps1" -ToolSign "<selected_tool_sign>" -ValuesFile ".\values.json"

The values.json file should contain either one object or an array of objects. Example:

json
[{"searchurl":"https://

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · SKILL.zh-CN.md (reported line 52)May include surrounding context.

the token only for the current terminal session.

Windows PowerShell, permanent for the current user:

powershell
[Environment]::SetEnvironmentVariable("DATAIFY_API_TOKEN", "your_token_here", "User")

Then reopen PowerShell. If the current session also needs the token immediately, run:

powershell
$env:DATAIFY_API_TOKEN = "your_token_here"

macOS or Linux, permanent for bash:

bash
echo 'export DATAIFY_API_TOKEN="your_token_here"' >> ~/.bashrc
source ~/.bashrc

macOS or Linux, permanent for zsh:

bash
echo 'export DATAIFY_API_TOKEN="your_token_here"' >> ~/.zshrc
source ~/.zshrc

Script usage

Python:

bash
python scripts/build-dataify-request.py --tool-sign <selected_tool_sign> --values-file values.json

PowerShell:

powershell
& ".\scripts\build-dataify-request.ps1" -ToolSign "<selected_tool_sign>" -ValuesFile ".\values.json"

The values.json file should contain either one object or an array of objects. Example:

json
[{"searchurl":"https://

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The skill is explicitly designed to send requests containing a bearer token to an external service, which is an external transmission of sensitive credentials and user-supplied scraping parameters. In context this appears expected business logic, but it still creates security risk if users are not clearly informed of the destination, trust boundary, and data being transmitted.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "dataify-airbnb-product-by-searchurl"
description: "Prepare Dataify builder requests for the airbnb.com scraper family rooted at airbnb_product_by-searchurl. Use  when needs to work with the successful Dataify scraper detail entry for airbnb_product_by-searchurl, let the user choose one of its available tools, read saved getToolParams options, and generate a scraperapi.dataify.com/builder curl request with DATAIFY_API_TOKEN."
---

# Dataify Builder Skill

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instructions explicitly require the user to choose from a Chinese list, which imposes a language constraint in the skill's workflow. There is no opt-in, alternative language presentation, or justification that this skill must operate only in Chinese.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill directs users to persistently store a sensitive API token in shell profile files and user environment settings, but provides no warning about local credential exposure, shell history leakage, profile sync/backup risks, or safer secret-management alternatives. This is not malware, but it is an insecure credential-handling practice that can increase the chance of token theft on shared or compromised systems.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
83% confidence
Finding

The skill instructs the agent/user to construct a curl request that sends user-supplied scraping parameters and an authorization bearer token to an external service (scraperapi.dataify.com). External transmission is expected for this skill's purpose, but it still creates a real data-exfiltration boundary: sensitive URLs, query parameters, and API credentials may be disclosed to a third party if used without validation or user awareness.

Content

Scanner excerpt · SKILL.zh-CN.md (reported line 3)May include surrounding context.

md
---
name: "dataify-airbnb-product-by-searchurl"
description: "为 airbnb.com 上以 airbnb_product_by-searchurl 为根的 scraper 系列准备 Dataify builder 请求。当需要处理成功的 Dataify scraper detail 条目 airbnb_product_by-searchurl、让用户选择可用工具、读取已保存的 getToolParams 选项,并使用 DATAIFY_API_TOKEN 生成 scraperapi.dataify.com/builder curl 请求时,使用此 skill。"
---

# Dataify Builder Skill 中文版

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

该文件标题直接声明为“中文版”,且全文均以中文规定交互与输出方式,没有看到允许用户选择其他语言或说明为何必须使用中文的自然语言说明。根据规则,若技能强制特定语言而无用户选择或明确、合理的区域性约束,可视为语言/locale 策略违规。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script reads a bearer token from the environment and injects it directly into a generated curl command that is printed to stdout. This can expose the credential through terminal history, logs, CI output, screenshots, or copy/paste into shared channels, allowing reuse of the API token by anyone who sees the command.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
83% confidence
Finding

The external transmission finding is valid in context because the script constructs a request intended for a third-party endpoint and includes both a bearer token and user-supplied spider parameters. While sending data to the vendor API is the apparent purpose of the tool, this still creates a real security risk if sensitive input values or the token are exposed or transmitted without adequate user awareness and handling controls.

Content

Scanner excerpt · scripts/build-dataify-request.py (reported line 63)May include surrounding context.

python
)

    parts = [
        "curl -X POST 'https://scraperapi.dataify.com/builder'",
        f"  -H 'Authorization: Bearer {token}'",
        "  -H 'Content-Type: application/x-www-form-urlencoded'",
        f"  -d 'spider_name={tool['spider_name']}'",

Static analysis

No suspicious patterns detected.