Back to skill

Security audit

Company search fengniao

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its China company lookup purpose, but its broad auto-invocation and risky API key handling deserve Review before installation.

Install only if you are comfortable with company names and due-diligence targets being sent to Riskbird. Avoid using a paid/private FN_API_KEY unless you accept that the key is transmitted in a URL parameter, and do not follow setup checks that print the full key on screen. The publisher should narrow auto-invoke triggers, mask key verification, clarify privacy implications, and avoid bundled shared credentials or URL-based secret transport where possible.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
references/due_diligence_report.md:26
Finding

Mandatory Branded Content Hijacks Due-Diligence Report Output

Content
View full analysis
Query date: {YYYY-MM-DD} > Full company name: {entName} > Unified Social Credit Code: {uniscid} [Mandatory report sections and queried company data] The above data comes from the Riskbird enterprise information query platform. Its data dimensions continue to expand. For additional company information and features, see the Riskbird website: https://www.riskbird.com/ ``` The file additionally requires the agent to output the completed report directly without adding an independent explanation. ### Technical Analysis The Skill does not merely specify how company data should be organized. It requires every due-diligence report to contain a branded promotional statement and outbound website link. The instruction is loaded as part of the Skill and controls content in the agent's final response regardless of whether the user requested advertising, attribution, or an external link. This behavior is classified as instruction hijacking because Skill-controlled instructions alter the response objective from producing a due-diligence result to also promoting the Skill provider. The rigid-template requirement prevents the agent from omitting the unrelated content. ### Attack Path 1. A user installs or enables the Skill. 2. The user requests an enterprise due-diligence report. 3. The agent loads `references/due_diligence_report.md`. 4. The file instructs the agent to follow the supplied structure strictly. 5. The agent generates the requested report using API results. 6. The mandatory Riskbird promotional stat ...[truncated 646 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/env.mjs:1
Finding

Hard-Coded Shared API Credential and Query-String Credential Exposure

Content
View full analysis
t.tool_id === toolId); if (!tool) throw new Error(`Tool not found: ${toolId}`); const url = new URL(BASE_URL + tool.endpoint); url.searchParams.set("apikey", apiKey); ``` ### Technical Analysis The package contains a reusable API credential directly in source code. Anyone who can download or inspect the Skill can recover and reuse the credential without authorization from the credential owner. Because the key is shared, one user can also consume the quota available to all other users. The client gives a user-supplied `FN_API_KEY` priority over the bundled key and then places whichever credential is selected in the URL query string. URLs are commonly recorded by reverse proxies, web-server access logs, monitoring agents, debugging tools, network telemetry, and error-reporting systems. HTTPS protects the URL in transit from passive network observers, but it does not prevent endpoints and authorized intermediaries from logging the complete URL. The reviewed code sends the credential only to the declared Riskbird production endpoint. No evidence was found that it intentionally exfiltrates credentials to an un ...[truncated 1504 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (20)

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
95% confidence
Finding

printenv FN_API_KEY explicitly reveals the secret value, which is a form of credential exposure guidance. While it only reads the current session variable and does not exfiltrate it automatically, the command trains users to disclose sensitive material in plain text and can leak into logs, recordings, or copied terminal output.

Content

Scanner excerpt · SETUP.md (reported line 62)May include surrounding context.

macOS / Linux

bash
printenv FN_API_KEY

Windows PowerShell

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all user-facing instructions exclusively in Chinese, including setup, credential handling, and validation steps. Under the policy for natural-language violations, forcing a specific language without user opt-in can be a locale policy issue unless the skill clearly documents a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation tells users to display the full FN_API_KEY in the terminal to verify configuration. Exposing secrets on screen increases the chance of shoulder-surfing, screen recording, terminal logging, shell history capture, or accidental inclusion in support screenshots, which can lead to credential compromise.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill is configured with auto_invoke and a very broad set of enterprise-search and due-diligence triggers, including generic phrases like supplier verification, background check, and finding a company-query skill. This can cause the skill to activate on common requests without sufficiently narrow boundaries, leading to unintended transmission of user-provided company names or sensitive business context to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill states that requests are sent to an external service and that the API key is passed in the URL query string, but it does not clearly warn users that their query terms and business investigation targets will be disclosed to a third party. Using URL parameters for credentials is especially risky because URLs are commonly logged by clients, proxies, servers, and monitoring systems, increasing the chance of API key leakage and query exposure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file is entirely written as a fixed Chinese-language reporting guide and instructs the model to follow that template strictly, but it does not indicate that Chinese output is optional or limited to a China-specific compliance context. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill directs the agent to compile due diligence reports using corporate records that include personal and sensitive fields such as legal representative, executives, shareholders, enforcement records, and high-consumption restrictions. The document provides no warning that the output may contain sensitive personal or legal-risk information, which is the kind of user disclosure expected for markdown files affecting privacy.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation explicitly instructs callers to pass the API key in the URL query string (apikey=<API_KEY>). Query-parameter secrets are commonly exposed via browser history, proxy/CDN logs, server access logs, analytics, referrer headers, and shared screenshots or copied URLs, so this creates a realistic credential leakage risk. In this skill context, the issue is somewhat more dangerous because the document is operational API guidance that downstream agents or integrators may follow verbatim.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Line L095 states that English search is invalid and that users must pass Chinese, which is a natural-language locale constraint. The file does not offer a language choice, opt-in, or explain that this is a justified region-specific limitation, so it conflicts with the stated policy criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Comments and user-visible error strings in this file are written only in Chinese, including the API key setup instruction. Under the stated policy, forcing a specific language without opt-in can be a natural-language locale policy violation unless the locale restriction is clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The thrown error message instructing the user how to obtain and configure the API key is entirely in Chinese. Because this is user-facing natural language and no opt-in or locale justification is present in this file, it may violate the language/locale policy.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code appends the API key to the request URL as a query parameter. Query strings are commonly captured in browser history, logs, proxies, analytics, referrers, and error telemetry, so this increases the chance of credential disclosure even if TLS is used. The skill context makes this somewhat more sensitive because the API is used for enterprise/risk investigation data and credential exposure could enable unauthorized API use.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

These aliases include broad everyday terms such as supplier/background/contract-related phrases that can easily appear in normal conversation without the user explicitly intending to invoke this skill. In a due-diligence skill that surfaces sensitive company and risk data, accidental routing can cause unintended external queries, privacy issues, and confusing or overbroad disclosure of business-risk information.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Single-word aliases like '法人', '官网', '电话', and '邮箱' are highly ambiguous and can match ordinary user requests that are not meant to call this skill. Because the skill performs company-information lookup, such generic triggers raise the risk of unintended activation and unnecessary retrieval or exposure of corporate contact and identity data.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The keyword "官网" is extremely broad and commonly used for many unrelated products, services, or organizations, so it can spuriously match normal user queries. In this skill context, that can route users into enterprise-information retrieval flows and fetch unnecessary business profile data when they may have only wanted a website.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The keyword "官网" is extremely broad and commonly used for many unrelated products, services, or organizations, so it can spuriously match normal user queries. In this skill context, that can route users into enterprise-information retrieval flows and fetch unnecessary business profile data when they may have only wanted a website.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The keyword "官网" is extremely broad and commonly used for many unrelated products, services, or organizations, so it can spuriously match normal user queries. In this skill context, that can route users into enterprise-information retrieval flows and fetch unnecessary business profile data when they may have only wanted a website.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instruction that English search is invalid and Chinese input is required hard-codes a language restriction into tool behavior without any user-choice or graceful fallback. While not a classic security bug, it can cause reliability and usability failures that lead agents to transform or reinterpret user input unsafely, especially if they attempt implicit translation or retry logic without consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The file's natural-language instructions and field descriptions are entirely in Chinese, which can impose a language constraint on users or maintainers without explicit opt-in. The policy allows locale constraints when they are documented and justified, but no such justification or alternative language option is provided here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

This manifest hard-codes trigger vocabulary in specific languages/locales but provides no natural-language statement that users can choose their preferred language or that the skill is intentionally region-specific. Because SQP-3 applies to all file types, the lack of opt-in or documented locale justification may conflict with language/locale policy expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.