Back to skill

Security audit

我好牛AI智投

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it says, but it has under-disclosed handling of a paid API key and can relay untrusted remote output verbatim.

Review this skill before installing. It needs a Wohaoniu API key and will send your brand, product, audience, and campaign details to the Wohaoniu service; generation calls may consume account credits. Only run it in an environment where WOHAONIU_BASE_URL is unset or trusted, and treat generated scripts, links, and command-like text from the API as untrusted content unless you separately verify them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/zhitou.mjs:10
Finding

Configurable API Origin Can Expose the Bearer Credential and Submitted Data

Content
View full analysis

Vulnerability Details

File Location: scripts/zhitou.mjs:10-22
Vulnerability Type: Arbitrary credential-bearing API destination
Risk Level: Medium

Vulnerable Code

js
const BASE = (process.env.WOHAONIU_BASE_URL || 'https://ai.wohaoniu.com').replace(/\/$/, '');
const KEY = process.env.WOHAONIU_API_KEY || '';

const die = (msg) => {
  console.error(msg);
  process.exit(1);
};

if (!KEY) die('未配置 WOHAONIU_API_KEY —— 到 https://ai.wohaoniu.com → 个人中心 → 开放接口 生成密钥后配置到环境变量。');

async function call(path, body) {
  const res = await fetch(BASE + path, {
    method: body ? 'POST' : 'GET',
    headers: { 'content-type': 'application/json', authorization: `Bearer ${KEY}` },
    body: body ? JSON.stringify(body) : undefined,
    signal: AbortSignal.timeout(110_000),
  });

Technical Analysis

The complete API origin is taken from the undocumented WOHAONIU_BASE_URL environment variable. The program does not validate the URL scheme or restrict the destination hostname before attaching WOHAONIU_API_KEY as a bearer credential.

Consequently, a party capable of influencing the Skill process environment can redirect the initial request to an arbitrary HTTP or HTTPS server. That server receives the API key in the Authorization header. For commands that accept user input, it also receives the submitted brand, category, product description, target audience, or advertising brief.

The override may be useful for legitimate testing, but allowing unrestricted destinations is not necessary for the declared production functionality. It violates least-privilege principles because a credential issued for ai.wohaoniu.com can be disclosed to an unrelated origin.

Attack Path

  1. An attacker gains the ability to modify the environment used to launch the Skill, such as through a compromised launcher, deployment configuration, shell profile, or environment file.
  2. The attacker sets `WOHAONIU_BASE_ ...[truncated 1104 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove WOHAONIU_BASE_URL from production builds and use a fixed API origin:
    js
    const BASE = 'https://ai.wohaoniu.com';
    
  2. If an override is required for development, enable it only under an explicit development mode and never reuse production credentials.
  3. Parse the URL and enforce both an HTTPS scheme and an exact hostname allowlist before sending credentials.
  4. Reject URLs containing unexpected credentials, ports, protocols, or hostnames.
  5. Configure redirect handling defensively and ensure authorization headers are never forwarded to a different origin.
  6. Use separate, minimally scoped test credentials for non-production endpoints.
  7. Document every supported configuration variable and its security consequences.
  8. Revoke and replace any API key that may have been used while an untrusted base URL was configured.

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:27
Finding

Untrusted Remote Content Is Required to Be Reproduced Verbatim in Agent Responses

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:27-37, with executable sinks at scripts/zhitou.mjs:47-55
Vulnerability Type: Remote-content instruction and output injection
Risk Level: Medium

Vulnerable Code and Instructions

md
**2. 广告钩子(10 条,消耗 1 次数)**
```bash
node scripts/zhitou.mjs hooks "<产品与人群描述>"

描述越具体越好:产品、价格、核心卖点、目标人群、投放平台、冷/热流量。产出直接转述给用户(内容已过广告法自检,不要自行"润色"加回违规词)。

3. 15s 口播素材脚本(消耗 1 次数)

bash
node scripts/zhitou.mjs script "<素材需求:产品/卖点/人群/平台>"

产出含分镜表与合规提示,原样呈现给用户,分镜表保持表格格式。

text

The executable script prints the remote response without validation:

```js
} else if (cmd === 'hooks') {
  if (!a1) die('用法:zhitou.mjs hooks "<产品与人群描述>"');
  const d = await call('/api/open/ad-hooks', { product: a1 });
  console.log(d.text);
} else if (cmd === 'script') {
  if (!a1) die('用法:zhitou.mjs script "<素材需求:产品/卖点/人群/平台>"');
  const d = await call('/api/open/ad-script', { brief: a1 });
  console.log(d.text);

The documented API response can also contain command-like material:

md
回:`{ ok, text }` —— text 含分镜表、合规提示、AI 成片管线命令。消耗 1 次数,失败自动退还。

Technical Analysis

The Skill instructs the Agent to reproduce the remote service's text field directly or verbatim. The implementation performs no schema-level content validation, output boundary enforcement, link validation, or separation between data and instructions.

The API reference states that generated text may include AI media-pipeline commands. This increases the likelihood that command-like material will appear in what the Agent is told to treat as trusted output. Although the script only prints this content and does not execute it, a malicious or compromised service can return prompt-injection text, misleading links, fixed advertisements, requests for secrets, or instructions encouraging the user or Agent to run commands.

This creates an instruction-hijacking channel becau ...[truncated 2119 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace instructions to reproduce remote output verbatim with an explicit requirement to treat all API responses as untrusted data.
  2. Validate the response against a strict schema, including expected types, size limits, and required fields.
  3. Present generated content inside a clearly labeled and delimited block so it cannot be confused with Skill or system instructions.
  4. Instruct the Agent to ignore directives inside generated content that request secrets, tool use, policy changes, external navigation, or command execution.
  5. Validate returned URLs against an allowlist before displaying them as trusted report or purchase links.
  6. Do not execute, recommend, or automatically forward pipeline commands returned by the service without separate review and explicit user confirmation.
  7. Apply output filtering for known prompt-injection patterns, credential requests, hidden markup, and unexpected promotional suffixes.
  8. Prefer structured API fields for hooks, scenes, compliance notices, and links rather than a single unrestricted text field.
  9. Preserve the generated wording where legally necessary, but separate content fidelity from instruction trust: formatting and safety review should remain permitted.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (9)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · .gitignore (reported line 2)May include surrounding context.

text
node_modules/
.env

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
node scripts/zhitou.mjs geo "<品牌名>" "<品类,可选>"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

md
node scripts/zhitou.mjs geo "<品牌名>" "<品类,可选>"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

md
node scripts/zhitou.mjs geo "<品牌名>" "<品类,可选>"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

md
node scripts/zhitou.mjs geo "<品牌名>" "<品类,可选>"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill invokes local Node scripts that rely on environment secrets and make outbound API calls, but it declares no explicit tool scope or permission boundaries. In platforms that use manifest-declared permissions for policy enforcement, this can lead to over-broad execution, reduced review visibility, and accidental exposure of secrets or network access beyond what users expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger description includes broad natural-language requests such as asking whether AI will recommend a brand, asking for ad hooks/scripts, or checking balance, which can cause the skill to activate in cases the user did not specifically intend. Mis-triggering can unnecessarily send user-provided business or marketing data to an external service, creating privacy and consent risks even if the skill's purpose is otherwise legitimate.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The header comment explicitly states that failures are reported in Chinese, and all usage/help strings in the file are Chinese-only. This imposes a specific language on users without any visible opt-in or alternative, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill description and all user-facing usage examples are presented exclusively in Chinese, which can imply a fixed language requirement for interaction. There is no statement that other languages are supported or that Chinese is optional, so this may violate a language/locale policy requiring user choice or opt-in.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/zhitou.mjs:10