Back to skill

Security audit

Zhipu Search

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Zhipu web-search skill that sends search queries to Zhipu using the user's API key, with no hidden persistence or destructive behavior found.

Install only if you intend to use Zhipu for web search. Do not submit secrets, private internal data, or sensitive personal information as search queries, and use a scoped or revocable Zhipu API key on a trusted single-user machine because the key may be visible to local process inspection while curl runs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
skill/scripts/search.sh:43
Finding

Zhipu API Key Exposed in Process Command-Line Arguments

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'shell' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description is broad enough to match many ordinary information-seeking requests, which can cause the agent to invoke this skill more often than necessary. That increases unnecessary external data transmission to a third-party service and may send user queries off-platform without sufficiently explicit user intent or exclusion rules.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This skill sends user-supplied search content and an API credential to an external third-party endpoint via curl. While external search is the skill's purpose, the transmission is still security-relevant because user queries may contain sensitive data, and the documented use of an Authorization header with a shell command can expose operational risk in logs, shell history, or surrounding tooling.

Content

Scanner excerpt · SKILL.md (reported line 40)May include surrounding context.

bash
export ZHIPU_API_KEY="your_key"

curl -s -X POST "https://open.bigmodel.cn/api/paas/v4/chat/completions" \
  -H "Authorization: Bearer $ZHIPU_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The 'When to Use' section uses ambiguous trigger phrases like 'find information about' and 'look up' without guardrails, so the skill may activate for general questions that do not require web access. In context, this is risky because activation causes outbound transmission of user prompts to Zhipu's API, creating avoidable privacy and data-handling exposure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The description says to use the skill when the user asks for 'web search, latest news, or needs current information.' The phrase 'needs current information' is broad and could match many ordinary requests without clearly defining when this skill should or should not activate.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This skill transmits user queries and an API credential to an external third-party service, creating data exposure and supply-chain/privacy risk if used with sensitive prompts. The risk is increased by the broad invocation guidance, which could cause more user requests than necessary to be sent off-platform.

Content

Scanner excerpt · skill/SKILL.md (reported line 40)May include surrounding context.

bash
export ZHIPU_API_KEY="your_key"

curl -s -X POST "https://open.bigmodel.cn/api/paas/v4/chat/completions" \
  -H "Authorization: Bearer $ZHIPU_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The 'When to Use' section includes broad phrases like 'find information about' and 'User needs current information from the web' without defining boundaries or negative examples. This can cause unintended invocation for general research or factual questions that do not truly require web search.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill/scripts/search.sh (reported line 45)May include surrounding context.

sh
}')

# Call Zhipu API with TLS verification
RESULT=$(curl -s --proto =https --tlsv1.2 -m 30 -X POST "https://open.bigmodel.cn/api/paas/v4/chat/completions" \
  -H "Authorization: Bearer $KEY" \
  -H "Content-Type: application/json" \
  -d "$PAYLOAD")