T09 · Insecure Skill Coding Practices
- Location
skill/scripts/search.sh:43- Finding
Zhipu API Key Exposed in Process Command-Line Arguments
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a disclosed Zhipu web-search skill that sends search queries to Zhipu using the user's API key, with no hidden persistence or destructive behavior found.
Install only if you intend to use Zhipu for web search. Do not submit secrets, private internal data, or sensitive personal information as search queries, and use a scoped or revocable Zhipu API key on a trusted single-user machine because the key may be visible to local process inspection while curl runs.
skill/scripts/search.sh:43Zhipu API Key Exposed in Process Command-Line Arguments
The skill uses 'shell' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
The skill description is broad enough to match many ordinary information-seeking requests, which can cause the agent to invoke this skill more often than necessary. That increases unnecessary external data transmission to a third-party service and may send user queries off-platform without sufficiently explicit user intent or exclusion rules.
This skill sends user-supplied search content and an API credential to an external third-party endpoint via curl. While external search is the skill's purpose, the transmission is still security-relevant because user queries may contain sensitive data, and the documented use of an Authorization header with a shell command can expose operational risk in logs, shell history, or surrounding tooling.
export ZHIPU_API_KEY="your_key"
curl -s -X POST "https://open.bigmodel.cn/api/paas/v4/chat/completions" \
-H "Authorization: Bearer $ZHIPU_API_KEY" \
-H "Content-Type: application/json" \
-d '{
The 'When to Use' section uses ambiguous trigger phrases like 'find information about' and 'look up' without guardrails, so the skill may activate for general questions that do not require web access. In context, this is risky because activation causes outbound transmission of user prompts to Zhipu's API, creating avoidable privacy and data-handling exposure.
The description says to use the skill when the user asks for 'web search, latest news, or needs current information.' The phrase 'needs current information' is broad and could match many ordinary requests without clearly defining when this skill should or should not activate.
This skill transmits user queries and an API credential to an external third-party service, creating data exposure and supply-chain/privacy risk if used with sensitive prompts. The risk is increased by the broad invocation guidance, which could cause more user requests than necessary to be sent off-platform.
export ZHIPU_API_KEY="your_key"
curl -s -X POST "https://open.bigmodel.cn/api/paas/v4/chat/completions" \
-H "Authorization: Bearer $ZHIPU_API_KEY" \
-H "Content-Type: application/json" \
-d '{
The 'When to Use' section includes broad phrases like 'find information about' and 'User needs current information from the web' without defining boundaries or negative examples. This can cause unintended invocation for general research or factual questions that do not truly require web search.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
}')
# Call Zhipu API with TLS verification
RESULT=$(curl -s --proto =https --tlsv1.2 -m 30 -X POST "https://open.bigmodel.cn/api/paas/v4/chat/completions" \
-H "Authorization: Bearer $KEY" \
-H "Content-Type: application/json" \
-d "$PAYLOAD")