Back to skill

Security audit

Umeng Stats

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but it ships plaintext Umeng API credentials and allows broader app-key access than its configured-app framing suggests.

Do not install this package with the included credentials. Rotate the exposed Umeng apiSecurity/apiKey if they are real, replace config.json with a credential-free template or secret-store based setup, and restrict queries to explicitly configured apps before use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
config.json:2
Finding

Plaintext Umeng API Credentials Embedded in Configuration

Content
View full analysis

Vulnerability Details

File Location: config.json:2-4
Vulnerability Type: Hardcoded API credentials and plaintext sensitive data
Risk Level: High

Vulnerable Code

json
{
  "apiKey": "4676865",
  "apiSecurity": "JCVOyuLUcr",
  "apps": {

The credential is consumed by the request-signing implementation in scripts/query_crash.py:21-29:

python
def sign(api_key, api_security, service, method_name, params):
    url_path = f"param2/1/{service}/{method_name}/{api_key}"
    sorted_keys = sorted(params.keys())
    param_str = ""
    for k in sorted_keys:
        param_str += f"{k}{params[k]}"
    s = url_path + param_str
    signature = hmac.new(
        api_security.encode("utf-8"),
        s.encode("utf-8"),
        hashlib.sha1
    ).hexdigest().upper()
    return url_path, signature

Technical Analysis

The project distributes an Umeng API key and its HMAC signing secret in plaintext. These values are authentication credentials rather than non-sensitive configuration. Any party able to download, inspect, copy, or otherwise access the Skill package can recover both values without needing runtime access to the legitimate operator's system.

The script contains the complete signing algorithm required to use the credential. It constructs the canonical request from the API path and sorted parameters, then calculates an HMAC-SHA1 signature using apiSecurity. Consequently, possession of the repository is sufficient to reproduce authenticated Umeng requests outside the Skill.

The configuration also associates the credential with 20 application identifiers. This gives an attacker the information required to target the configured applications' U-APM crash information and U-App analytics. Actual accessible operations remain subject to the permissions assigned to the exposed Umeng credential.

Attack Path

  1. An attacker obtains a copy of the Skill package, repository, ...[truncated 1211 chars]
Remediation
View remediation

Remediation Suggestions

  1. Revoke and rotate the exposed apiKey and apiSecurity immediately. Treat the current values as compromised because they have been distributed in plaintext.
  2. Remove credentials from config.json, repository history, release archives, build artifacts, logs, backups, and deployed Skill packages where feasible.
  3. Load credentials at runtime from environment variables, an operating-system credential store, or a managed secret service.
  4. Commit only a credential-free template such as config.example.json, using placeholders for sensitive values.
  5. Separate application metadata from secrets so that application identifiers can be configured without distributing the signing secret.
  6. Apply least privilege to the replacement credential. Restrict it to only the applications and API methods required by the Skill.
  7. Restrict access to any local secret file with appropriate filesystem permissions and ensure it is excluded through repository ignore rules and packaging configuration.
  8. Add automated secret scanning to source-control and release pipelines to prevent credentials from being committed or packaged again.
  9. Review Umeng access and usage records for requests made with the exposed credential, including unusual applications, source addresses, methods, or quota consumption.
  10. Avoid placing authentication secrets in command-line arguments or diagnostic output when implementing the replacement secret-loading mechanism.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (10)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

When an app name is not found in the configured allowlist, resolve_app falls back to treating the user input as a raw appKey. That defeats the stated boundary of supporting only configured apps and can let a caller query arbitrary Umeng app data with the locally stored credentials, creating an authorization bypass relative to the skill's declared scope.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill documents network-capable behavior against Umeng APIs but does not declare any explicit tool scope or allowed tools. This weakens least-privilege controls and can allow the runtime to grant broader capabilities than users or platform policy expect, especially for a skill that accesses external services using stored credentials.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The invocation text is broad enough to trigger on generic analytics or stability questions, increasing the chance the skill runs outside its narrowly intended Umeng-specific context. Misrouting can cause unnecessary use of stored credentials, unintended external queries, or disclosure of app analytics when the user only asked a general question.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill explicitly points to a local config file containing app credentials but provides no warning or handling guidance for sensitive secrets. In a skill that performs signed API calls, this increases the risk of accidental credential exposure through logs, debugging, repo inclusion, or operator misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The configuration loader reads a local JSON file that is later used for apiKey and apiSecurity, which are credentials for authenticating to the Umeng API. There is no user-facing warning, comment, or docstring indicating that sensitive credentials are accessed from disk and used by the script.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code performs an outbound HTTPS request to Umeng using app identifiers and query parameters derived from local configuration and user input, but there is no confirmation prompt, visible disclosure message, or explanatory comment/docstring near the network operation. For a code file, network transmission of user or system data should have some form of user disclosure unless clearly documented as expected behavior in accompanying markdown, which is not available in this file.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The --list-apps option prints every configured app name together with its raw appKey, disclosing identifiers for all tenant applications to any caller of the skill. In this skill context, those keys are used to query Umeng analytics across about 20 apps, so exposing them broadens the set of accessible targets and aids unauthorized enumeration or later abuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The config contains multiple natural-language identifiers in Chinese for application names, with no indication that users can opt into another language or that the skill is region-specific. Under the language/locale policy rule, hard-coded locale-specific language can be a policy concern when no choice or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

Multiple user-visible status and report strings are emitted only in Chinese, and the CLI provides no language or locale selection. This creates a language policy concern because the skill imposes a specific locale on all users rather than offering a choice or documenting a justified regional restriction.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The help string says '--type' selects among 'crash/today/yesterday/allapps', implying a query-category parameter, but the default chosen is one specific data mode ('yesterday'). This is documentation-to-code divergence because the inline user-facing documentation suggests a neutral type selector while the implementation silently biases behavior to yesterday stats.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.