T09 · Insecure Skill Coding Practices
- Location
scripts/ari.py:53- Finding
API Credential Disclosure Through an Unrestricted Base URL Override
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill largely matches its Amazon review-analysis purpose, but it can send the saved ARI API key to an environment-selected API server, which needs review before installation.
Install only if you trust ARI and your execution environment. Before using it, ensure ARI_BASE_URL is unset or points only to the legitimate ARI service, protect/revoke the ari_live_ key if it may have run with an untrusted environment, and review paid --confirm actions, exports, and workbench status updates before approving them.
scripts/ari.py:53API Credential Disclosure Through an Unrestricted Base URL Override
The request destination is derived from base_url(), which accepts ARI_BASE_URL from the environment, and authenticated requests attach the Bearer API key. If an attacker can influence the environment or wrapper configuration, they can redirect requests to an attacker-controlled host and exfiltrate the API key and request data.
headers["Content-Type"] = "application/json"
try:
req = urllib.request.Request(url, data=data, headers=headers, method=method)
with urllib.request.urlopen(req, timeout=TIMEOUT_SEC) as resp:
note_release(resp.headers)
raw = resp.read().decode("utf-8")
out = json.loads(raw) if raw else {"success": True, "data": None}
This SSE request also uses base_url() from ARI_BASE_URL while sending the Authorization bearer token and analysis payload to the selected host. Because SSE sessions can be long-lived and include sensitive report content, redirecting them to an attacker-controlled endpoint can expose both credentials and business data.
try:
req = urllib.request.Request(
url, data=json.dumps(payload).encode("utf-8"), headers=headers, method="POST")
with urllib.request.urlopen(req, timeout=SSE_TIMEOUT_SEC) as resp:
note_release(resp.headers)
content_type = resp.headers.get("Content-Type", "")
if "text/event-stream" not in content_type:
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
base_url() + "/api/v1/public/config",
headers={"Accept": "application/json",
"User-Agent": user_agent()})
with urllib.request.urlopen(req, timeout=15) as resp:
note_release(resp.headers)
body = json.loads(resp.read().decode("utf-8"))
except Exception:
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
headers["Content-Type"] = "application/json"
try:
req = urllib.request.Request(base_url() + path, data=data, headers=headers, method=method)
with urllib.request.urlopen(req, timeout=timeout) as resp:
note_release(resp.headers)
out = json.loads(resp.read().decode("utf-8"))
if isinstance(out, dict):
The download/export path sends the Bearer API key to the host derived from ARI_BASE_URL and may also write attacker-controlled response bodies to local files. If the environment is maliciously set, this enables credential exfiltration and delivery of untrusted file contents under a trusted-looking workflow.
headers = {"Authorization": "Bearer " + require_key(), "User-Agent": user_agent()}
try:
req = urllib.request.Request(url, headers=headers, method="GET")
with urllib.request.urlopen(req, timeout=TIMEOUT_SEC) as resp:
note_release(resp.headers)
ctype = resp.headers.get("Content-Type", "")
body = resp.read()
Referenced artifact was not completely inspected
- CLI:本 Skill 目录下的 `scripts/ari.py`。在 Skill 根目录执行,例如
Referenced artifact was not completely inspected
- CLI:本 Skill 目录下的 `scripts/ari.py`。在 Skill 根目录执行,例如
Referenced artifact was not completely inspected
- CLI:本 Skill 目录下的 `scripts/ari.py`。在 Skill 根目录执行,例如
Referenced artifact was not completely inspected
- CLI:本 Skill 目录下的 `scripts/ari.py`。在 Skill 根目录执行,例如
The README states '安装后直接用中文描述需求即可', which directs users to interact in Chinese and does not indicate that other languages are supported or that language choice is optional. This is a natural-language locale/policy concern because it forces a specific language without explicit user opt-in or justification.
The skill instructs the agent to use shell commands, access environment-based credentials, perform network calls, and potentially write local configuration, but it does not declare any explicit tool scope or permission boundaries. This creates an over-privileged integration where an agent may invoke powerful capabilities without transparent restriction, increasing the blast radius if the skill is misused, misrouted, or modified.
The trigger phrases are broad enough to match generic requests about complaints, quality issues, or rating drops, which can cause the skill to activate in situations the user did not specifically intend. In this skill, unintended activation is more concerning because it can lead the agent toward networked data collection, local credential setup, or quoted/paid workflows tied to an external service.
The display name, short description, and default prompt all require Chinese, but the file does not state that the skill is intended only for Chinese-speaking users or provide any language opt-in. This can violate language/locale policy by implicitly forcing a specific language without user choice or documented justification.
The document title and all operational instructions are written in Chinese, and there is no indication that users may choose another language or that the skill is intentionally restricted to a Chinese-speaking audience. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation.
The manifest describes a skill focused on collecting reviews for a specified ASIN and analyzing 1–3 star negative feedback, root causes, rankings, and trend charts. This CLI also exposes alerts management, category benchmarking, paid category leaderboards, a workbench for review status tracking, single-review AI advice generation, and local export capabilities, which materially extend beyond the stated bad-review analysis scope.
A skill advertised as review analysis and reporting is expected to read data and generate insights, but these commands perform state-changing operations on remote resources: POST /api/v1/alerts/read and PUT /api/v1/workbench/reviews//status. Those workflow-management mutations are not justified by the manifest's stated purpose of analyzing negative reviews and producing recommendations/charts.
The analysis argument helper sets --language default to zh, causing analysis commands to produce Chinese output unless the user explicitly overrides it. This is a natural-language policy issue because it forces a specific language by default rather than offering a neutral default or explicit opt-in.
The voc subcommand hard-codes --language to zh by default, so generated VOC reports are produced in Chinese unless changed by the caller. This enforces a specific language choice without explicit user consent.
The deepdive subcommand sets --language default to zh, which means its analysis portion will be generated in Chinese by default. This is a locale/language policy violation because a specific language is imposed absent explicit opt-in.
The usage guide materially expands the skill from narrow bad-review analysis into a broad review-intelligence suite, including competitor comparison, purchase-motivation analysis, exports, alerts, benchmarking, and full VOC reporting. This scope mismatch is dangerous because users and host platforms may grant trust, permissions, or purchase consent based on the manifest’s narrower description, while the documentation steers them toward higher-risk or higher-cost actions outside the declared intent.
Dynamic getattr() with a non-literal attribute name can access arbitrary object attributes, potentially bypassing access controls.
所以校验不能写死 B 前缀。顺手把值归一成大写,后续命令不必再 upper()。
"""
for attr in ("asin", "competitor"):
value = getattr(args, attr, None)
if value in (None, ""):
continue
normalized = str(value).strip().upper()
The statement says the CLI will not itself download or run remote files for updates, which is narrowly true, but the surrounding update flow describes remote version checks and server-enforced execution gating. This creates an intent-level documentation tension: the text emphasizes safety from remote update execution while the tool still depends on server-side control over what operations may run.
No suspicious patterns detected.