Back to skill

Security audit

Joke Api

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward JokeAPI helper that makes user-initiated requests to an external joke service and does not show hidden persistence, credential access, or remote code execution.

Install only if you are comfortable with user-invoked requests being sent to JokeAPI, including any text passed with --contains. Use --safe-mode or blacklist flags when jokes may be shown in work or public contexts.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (9)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/joke.sh (reported line 77)May include surrounding context.

sh
# 获取笑话
    local response
    response=$(curl -s "$url")
    
    # 根据格式输出
    if [[ "$FORMAT" == "txt" ]]; then

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/joke.sh (reported line 141)May include surrounding context.

sh
# 列出分类
list_categories() {
    curl -s "${BASE_URL}/categories" | python3 -c "
import sys, json
data = json.load(sys.stdin)
print('可用分类:')

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/joke.sh (reported line 152)May include surrounding context.

sh
# 列出语言
list_languages() {
    curl -s "${BASE_URL}/languages" | python3 -c "
import sys, json
data = json.load(sys.stdin)
print('支持的编程语言:')

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/joke.sh (reported line 163)May include surrounding context.

sh
# 获取 API 信息
get_info() {
    curl -s "${BASE_URL}/info" | python3 -m json.tool
}

# 解析命令行参数

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file's user-facing instructions and descriptions are presented only in Chinese, which effectively forces a specific language for use of the skill. The policy allows language constraints only when users are offered a choice or when the locale restriction is clearly documented and justified, neither of which appears here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code file contains natural-language strings that present usage, help text, and runtime messages in Chinese only. Under the policy, a skill should not force a specific language or locale unless it offers user opt-in or clearly documents a justified regional constraint, which is not present here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script sends user-provided search text from --contains to a third-party API over the network without any explicit notice, consent prompt, or local-only alternative. While this is expected for an API client, it still creates a real privacy risk because arbitrary user text may contain sensitive data and is transmitted off-host to an external service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documentation is written entirely in Chinese, including usage instructions and warnings, with no indication that the skill is intended only for a Chinese-speaking audience or that other language options are available. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language configuration sets LANG="en" as the default, which forces a specific language unless the user discovers and overrides --lang. Under the policy, locale or language constraints should be optional, user-selected, or clearly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.