Back to skill

Security audit

Official Baidu Search

Security checks for vulnerabilities and agentic risk

Overview

This Baidu search skill is mostly coherent, but a direct-run mode can expose an unauthenticated API-key-backed search proxy on the network and the code logs user queries verbatim.

Review this before installing if you plan to run the service outside a tightly controlled local environment. Bind only to 127.0.0.1, do not expose the port publicly without authentication and rate limits, avoid sensitive searches, and consider removing raw query/body logging and locking dependency versions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
src/baidu_search/main.py:42
Finding

Unauthenticated Search Endpoint Exposes the Operator's Baidu API Quota

Content
View full analysis
SearchResponse: """ 搜索网页 - **query**: 搜索关键词 - **top_k**: 返回结果数量 (1-20, 默认 10) - **recency_filter**: 时间过滤 (day, week, month, year) - **site_filter**: 限定搜索的网站列表 """ return search(request) if __name__ == "__main__": import uvicorn uvicorn.run("baidu_search.main:app", host="0.0.0.0", port=8001) ``` ### Technical Analysis When this module is executed directly, Uvicorn binds the application to `0.0.0.0`, making it reachable through every available network interface. The `/search` endpoint has no authentication, authorization, request throttling, or usage quota. Every accepted request is forwarded to Baidu using the server operator's `BAIDU_API_KEY`. Consequently, any client that can reach TCP port 8001 can consume the operator's upstream API quota without possessing that credential. This runtime behavior is also less restrictive than the setup command in `SKILL.md`, which binds the documented service to `127.0.0.1`. ### Attack Path 1. The operator starts the application by running `src/baidu_search/main.py` directly. 2. The service listens on `0.0.0.0:8001`. 3. An attacker discovers or otherwise reaches port 8001. 4. The attacker repeatedly sends valid JSON requests to `POST /search`. 5. The application authenticates each upstream request with the operator's Baidu API key. 6. The attacker consumes the operator's API quota, potentially generating charges or exhausting service capacity. ### Impact Assessment An unauthenticated remote user can invoke the upstream search service under the operator's identity. The attacker does not obtain the literal API key or local operating-system privileges, but can abuse the author ...[truncated 184 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/baidu_search/main.py:24
Finding

Sensitive Search Queries and Invalid Request Bodies Are Logged Verbatim

Content
View full analysis
JSONResponse: logger.error( "Validation error on %s %s. body=%s errors=%s", request.method, request.url.path, exc.body, exc.errors(), ) return JSONResponse( status_code=422, content=jsonable_encoder({"detail": exc.errors()}), ) ``` A related disclosure occurs in `src/baidu_search/baidu_api.py:101-105`: ```python def search(request: SearchRequest) -> SearchResponse: """执行百度搜索""" api_key = _get_api_key() body = _build_request_body(request) logger.info("Searching Baidu: %s", request.query) ``` ### Technical Analysis The validation exception handler records the complete rejected request body. Valid search requests are also logged with the complete query. Search terms and submitted bodies may contain names, internal identifiers, confidential business topics, personal information, access tokens accidentally pasted by users, or other sensitive material. Logs commonly have different retention periods and access controls from the application data they describe. Recording complete user content therefore creates a secondary repository of sensitive information. Attacker-controlled line breaks or control characters may also interfere with log integrity when the logging backend does not normalize them. ### Attack Path 1. A user submits a confidential search query, which is logged at the information level; or submits a malformed request containing sensitive content, which is logged at the error level. 2. The log record is retained by the local system, a container platform, or a centralized logging service. 3. A user or com ...[truncated 585 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/baidu_search/baidu_api.py:126
Finding

Unsanitized Upstream Error Bodies Are Logged and Returned to Clients

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
pyproject.toml:5
Finding

Unbounded Dependency Specifications Permit Unreviewed Future Versions

Content
View full analysis
=3.11" dependencies = [ "fastapi>=0.110.0", "httpx>=0.27.0", "uvicorn[standard]>=0.29.0", ] [project.optional-dependencies] dev = [ "pytest>=8.0.0", ] ``` The documented setup in `SKILL.md:39-40` resolves these dependencies without a repository lock file: ```bash echo "BAIDU_API_KEY=your-api-key" > .env uv venv && uv pip install -e ".[dev]" ``` ### Technical Analysis Every dependency uses an open-ended lower-bound constraint. The repository contains no reviewed lock file in the supplied directory structure. As a result, two installations performed at different times can resolve materially different package versions and transitive dependency graphs. The listed package names are common packages from the normal Python ecosystem; the audit found no evidence of typosquatting, dependency confusion, or a currently malicious package. The security weakness is that future releases are accepted automatically without review, reducing build reproducibility and increasing exposure to compromised, incompatible, or newly vulnerable releases. Installing the development extra during normal setup also unnecessarily expands the dependency graph. ### Attack Path 1. A new direct or transitive dependency version is published after this project was reviewed. 2. A user follows the documented setup command. 3. The package resolver selects the new version because it satisfies the unbounded `>=` constraint. 4. Installation or runtime loads that unreviewed package code. 5. If that release is compromised or vulnerable, it can execute with the privileges of the user running the service. ### Impact Assessment The exact impact depends on a future compromised or vulnerable dependency. Python package installation and imported runtime code execute with the service user's p ...[truncated 227 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (16)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

bash
cd {baseDir}
echo "BAIDU_API_KEY=your-api-key" > .env
uv venv && uv pip install -e ".[dev]"
uv run --env-file .env uvicorn baidu_search.main:app --host 127.0.0.1 --port 8001

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

bash
cd {baseDir}
echo "BAIDU_API_KEY=your-api-key" > .env
uv venv && uv pip install -e ".[dev]"
uv run --env-file .env uvicorn baidu_search.main:app --host 127.0.0.1 --port 8001

Possible Typosquatting: 'uvicorn' resembles popular package 'gunicorn'

High
Category
Supply Chain
Confidence
70% confidence
Finding

Package name closely resembles a popular package, suggesting possible typosquatting. Attackers publish malicious packages with similar names to trick developers into installing them.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description states the skill is used to obtain real-time information from the Chinese internet, and the document consistently presents the skill as Chinese-only without any opt-in or alternative language behavior. Under the policy rule, forcing a specific language or locale without user choice is a natural-language policy violation unless clearly justified as region-specific compliance tooling.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

Quick Start

  1. 检查服务: curl http://127.0.0.1:8001/ping

  2. 搜索网页:

bash

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The function logs the raw search query and sends it to Baidu’s external API, which creates a privacy and data-handling risk if users enter secrets, personal data, or sensitive enterprise information. In a search skill, transmitting the query externally is expected behavior, but logging it server-side without minimization or redaction increases exposure through log retention, monitoring systems, and incident response tooling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The package description is written only in Chinese ("百度 AI 搜索 API 代理服务"), which can be interpreted as imposing a language choice without indicating any user-selectable locale or multilingual support. This is a natural-language policy concern because the manifest provides no opt-in or documented justification for the language restriction.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: fastapi has 3 known advisory(ies) (CVE-2021-32677 (Cross-Site Request Forgery (CSRF) in FastAPI); CVE-2021-32677 (FastAPI is a web framework for building APIs with Python 3.6+ based on standard ); CVE-2024-24762 (FastAPI is a web framework for building APIs with Python 3.8+ based on standard )), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: httpx has 2 known advisory(ies) (CVE-2021-41945 (Improper Input Validation in httpx); CVE-2021-41945 (Encode OSS httpx <=1.0.0.beta0 is affected by improper input validation in `http)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: uvicorn has 4 known advisory(ies) (CVE-2020-7694 (Log injection in uvicorn); CVE-2020-7695 (HTTP response splitting in uvicorn); CVE-2020-7694 (This affects all versions of package uvicorn. The request logger provided by the) +1 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: pytest has 2 known advisory(ies) (CVE-2025-71176 (pytest has vulnerable tmpdir handling); CVE-2025-71176 (pytest has vulnerable tmpdir handling)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The only natural-language description is the Chinese docstring "百度搜索 API 代理服务", which presents the skill in a single language with no indication that users can choose another language or that the skill is intentionally region-specific. Under the policy, forcing a specific language without user opt-in can be a locale/language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The file's natural-language docstrings and comments are written exclusively in Chinese, including user-relevant descriptions such as the function docstrings. Under the stated policy, forcing a specific language without opt-in can be a locale/language policy issue when no user choice or justification is documented.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The FastAPI title and description are presented only in Chinese, which can impose a specific language on users without opt-in. The policy allows locale constraints when explicitly documented and justified, but this file provides no such justification or alternative.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.