Back to skill

Security audit

小艺联网搜索

Security checks for vulnerabilities and agentic risk

Overview

This web-search skill does what it says, but it ships a live-looking cloud API bearer token in source code and uses risky dependency packaging practices.

Review this before installing. It appears to be a simple Huawei Cloud search wrapper, but the embedded bearer token should be treated as exposed and the dependency lockfile should be regenerated with HTTPS sources and patched versions. Users should also avoid sending confidential search terms unless they accept that queries go to Huawei Cloud.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
search.js:17
Finding

Hard-Coded Huawei Cloud Bearer Token in Distributed Source Code

Content
View full analysis

Vulnerability Details

File Location: search.js:17-18
Vulnerability Type: Hard-coded cloud API credential
Risk Level: High

javascript
// Huawei Cloud API Token (obtained from SKILL.md)
const TOKEN = 'eyJhbGciOiJQUzI1NiIsImtpZCI6IjNjMWZhNWQwNjIxNzRkYTA4MWNlY2E4NTY3NDViYTQxIiwidHlwIjoiSldUIn0.[REDACTED EXPOSED JWT]';

The original file contains the complete bearer token. Its payload and signature are redacted in this report to avoid further disclosure.

The credential is subsequently attached to every API request at search.js:39-42:

javascript
headers: {
  'Content-Type': 'application/json',
  'Authorization': `Bearer ${TOKEN}`
},

Technical Analysis

The project embeds an authentication bearer token directly in distributable source code. Bearer tokens authorize their holder without requiring additional proof of identity, so anyone who can download the package, access its source, inspect an installed copy, or read a repository containing it can extract and reuse the credential.

This is an intentional implementation choice rather than an accidental debug artifact: SKILL.md states that the token is built into the code, while _meta.json declares no environment-based secret configuration. Source-level embedding prevents effective per-installation access control and makes credential rotation require a code or package update.

The token appears structurally consistent with a signed JWT and therefore must be treated as compromised regardless of whether it is currently active. No attempt to use the exposed credential was made during this static audit.

Attack Path

  1. An attacker downloads the Skill package or reads an installed copy of search.js.
  2. The attacker copies the JWT assigned to TOKEN.
  3. The attacker sends requests to the declared Huawei Cloud endpoint: https://connect-api.cloud.huawei.com/api/aiNetworking/v1/webSearch.
  4. The attacker supplies the copied ...[truncated 1007 chars]
Remediation
View remediation

Remediation Suggestions

  1. Revoke the exposed token immediately and issue a replacement; assume the committed value has already been compromised.

  2. Remove the token from source code, documentation, package artifacts, repository history, release archives, logs, and examples.

  3. Read the credential from an environment variable or secret manager, for example:

    javascript
    const TOKEN = process.env.HUAWEI_WEB_SEARCH_TOKEN;
    
    if (!TOKEN) {
      throw new Error('HUAWEI_WEB_SEARCH_TOKEN is required');
    }
    
  4. Declare only the required environment variable in the Skill metadata rather than supplying a default credential.

  5. Provision a separate credential per deployment and grant only the minimum API scope needed for web search.

  6. Prefer short-lived credentials and automated rotation over long-lived static bearer tokens.

  7. Add secret scanning to development and release pipelines, including JWT and cloud-token detection.

  8. Review Huawei Cloud access logs for unauthorized use of the exposed token and investigate unexpected requests, quota use, or source addresses.

  9. Ensure errors and diagnostic output never print authorization headers or token values.

T08 · Insecure Dependencies

Warning
Location
package-lock.json:18
Finding

Dependency Archives Locked to a Plaintext HTTP Package Mirror

Content
View full analysis

Vulnerability Details

File Location: package-lock.json:18 and additional resolved fields throughout the lockfile
Vulnerability Type: Insecure dependency transport and supply-chain configuration
Risk Level: Medium

Representative affected entries include:

json
"node_modules/asynckit": {
  "version": "0.4.0",
  "resolved": "http://mirrors.tencentyun.com/npm/asynckit/-/asynckit-0.4.0.tgz",
  "integrity": "sha512-Oei9OH4tRh0YqU3GxhX79dM/mwVgvbZJaSNaRk+bshkj0S5cfHcgYakreBjrHwatXKbz+IoIdYLxrKim2MjW0Q==",
  "license": "MIT"
},
"node_modules/axios": {
  "version": "1.13.5",
  "resolved": "http://mirrors.tencentyun.com/npm/axios/-/axios-1.13.5.tgz",
  "integrity": "sha512-cz4ur7Vb0xS4/KUN0tPWe44eqxrIu31me+fbang3ijiNscE129POzipJJA6zniq2C/Z6sJCjMimjS8Lc/GAs8Q==",
  "license": "MIT"
}

Technical Analysis

The lockfile directs npm to retrieve dependency archives from http://mirrors.tencentyun.com, which does not provide transport encryption or server authentication. A network-positioned attacker can observe, redirect, block, replay, or modify plaintext HTTP responses.

The recorded SHA-512 integrity values materially mitigate arbitrary package replacement: a modified archive that does not match the lockfile hash should be rejected by a correctly functioning npm client. Consequently, this finding is not evidence that the named packages are malicious, and straightforward tampering is more likely to cause installation failure than code execution.

Nevertheless, HTTP remains an unsafe source for software dependencies. It exposes package-fetch metadata, permits denial of service and redirection attempts, and relies entirely on lockfile integrity enforcement rather than combining integrity validation with authenticated transport. Numerous transitive package entries use the same plaintext mirror, so the condition affects the dependency installation chain rather than only one package.

Attack Path

...[truncated 1464 chars]

Remediation
View remediation

Remediation Suggestions

  1. Configure npm to use the official HTTPS registry or an authenticated internal HTTPS mirror:

    bash
    npm config set registry https://registry.npmjs.org/
    
  2. Regenerate package-lock.json so every resolved archive URL uses HTTPS:

    bash
    rm -rf node_modules package-lock.json
    npm install
    
  3. Review the regenerated lockfile before committing it and retain all integrity fields.

  4. In CI, use npm ci to enforce the reviewed lockfile without silently rewriting dependency resolution.

  5. Add an automated policy check that rejects http:// dependency sources and unapproved registries in lockfiles.

  6. If a mirror is operationally required, use one controlled by the organization with valid TLS, access controls, upstream synchronization validation, and audit logging.

  7. Restrict network egress from build workers to approved HTTPS package registries.

  8. Continue using cryptographic lockfile integrity verification as defense in depth rather than treating HTTPS as a replacement for package hashes.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill documentation explicitly states that a Bearer token is hardcoded in code and used to access a third-party cloud service. Embedding credentials inside a distributable skill is a real security issue because anyone with access to the skill files may recover and abuse the token, causing unauthorized API usage, billing exposure, and possible access to associated account resources.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: axios==1.13.5 — 16 advisory(ies): CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more

High
Category
Supply Chain
Confidence
92% confidence
Finding

The lockfile pins axios to 1.13.5, and the finding lists multiple advisories including SSRF/proxy-bypass and prototype-pollution-related MITM/credential-theft issues. For a web-search skill that makes outbound HTTP requests to retrieve real-time network content, flaws in the HTTP client are directly relevant and could let an attacker influence request routing, proxy handling, or response trust boundaries.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: form-data==4.0.5 — 1 advisory(ies): CVE-2026-12143 (form-data: CRLF injection in form-data via unescaped multipart field names and f)

High
Category
Supply Chain
Confidence
80% confidence
Finding

form-data 4.0.5 is reported vulnerable to CRLF injection via unescaped multipart field names and filenames. This skill appears focused on web/API search rather than arbitrary multipart uploads, so exploitability may be lower in current usage, but the dependency remains risky if any user-controlled multipart construction is introduced now or later through axios features or future code changes.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: axios==1.13.5 — 16 advisory(ies): CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill depends on axios through a version range that can resolve to axios 1.13.5, which is flagged with multiple advisories including SSRF-related and request-handling issues. Because this skill performs live web searches and outbound HTTP requests, a vulnerable HTTP client is especially risky: it can undermine network boundary assumptions, expose credentials, or allow manipulated responses depending on how requests are made and proxied.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation normalizes the presence of a hardcoded Bearer token ('开箱即用' / '已固化在代码中') without warning that it is sensitive credential material. This increases the likelihood that users will distribute, reuse, or trust the skill without understanding the risk of credential leakage and unauthorized third-party service access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language interface, usage text, and output strings are written exclusively in Chinese, which effectively forces a specific language/locale. There is no indication that this is optional, configurable, or justified as a region-specific tool.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script sends the user's search query to Huawei Cloud over the network, but it does not provide any user-facing notice, consent prompt, or privacy warning before transmitting potentially sensitive input. In a search skill, users may enter confidential terms, so silent third-party transmission creates a real privacy and data-handling risk even if HTTPS is used.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: follow-redirects==1.15.11 — 1 advisory(ies): CVE-2026-40895 (follow-redirects leaks Custom Authentication Headers to Cross-Domain Redirect Ta)

Low
Category
Supply Chain
Confidence
84% confidence
Finding

follow-redirects 1.15.11 is flagged for leaking custom authentication headers across cross-domain redirects. In a search integration that likely calls authenticated cloud APIs, this matters because a malicious or compromised endpoint could trigger a redirect and cause sensitive headers or tokens to be forwarded to an attacker-controlled domain.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency is specified with a caret range (^1.6.0), which allows npm to install newer 1.x releases automatically rather than a single reviewed version. In a network-search skill that depends on HTTP client behavior, this increases supply-chain and change-management risk because vulnerable or behavior-changing releases can be pulled in without explicit review.

Content

Scanner excerpt · package.json (reported line 13)May include surrounding context.

json
"search": "node search.js"
  },
  "dependencies": {
    "axios": "^1.6.0"
  }
}

Static analysis

No suspicious patterns detected.