Back to skill

Security audit

Data Intelligence

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent data-collection purpose, but it needs Review because it tells users to run an unverified remote installer and handles API credentials insecurely.

Review the skill before installing. Do not run the `curl | bash` installer unless you have independently verified PinchTab and the exact installer contents. Prefer setting `APIFY_TOKEN` through a secure environment or secret manager, keep `.env` out of source control with restrictive permissions, and run scraping/browser automation only on data and accounts you are authorized to use.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
README.md:31
Finding

Unpinned Remote Installer Executed Directly by Bash

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/competitor-monitor.sh:28
Finding

Competitor Identifier Allows Output Path Traversal

Content
View full analysis
"$DATA_DIR/${competitor}-${DATE}.json" 2>/dev/null ``` ### Technical Analysis Each line from the user-selected competitor list is used directly as part of an output pathname: ```bash "$DATA_DIR/${competitor}-${DATE}.json" ``` Shell quoting prevents word splitting and shell metacharacter execution, but it does not prevent pathname traversal. A competitor value containing directory separators and `..` components can cause the redirection target to resolve outside `competitor-data`. The script appends `-YYYYMMDD.json`, which constrains the exact filename an attacker can target, but it does not guarantee that the resulting file remains inside the intended output directory. Parent directories must also already exist for a traversal path to succeed. The same untrusted value is interpolated into JSON without JSON-aware escaping. Special characters can corrupt or alter the actor input, although this does not directly create local shell command injection because the argument remains quoted. ### Attack Path 1. An attacker supplies or modifies the competitor-list file passed to the script. 2. The file contains a crafted line with traversal components, such as a value beginning with `../`. 3. The script reads the line into `competitor` without validation. 4. The crafted value becomes part of the shell redirection target. 5. Path resolution escapes the intended `competitor-data` directory. 6. If the destination directory exists and t ...[truncated 883 chars]
Remediation
View remediation
&2 continue fi ``` 2. Reject directory separators, `..`, control characters, empty identifiers, and identifiers beginning with unexpected option characters. 3. Construct the destination and verify its canonical parent remains under the canonical data directory. 4. Create output files with restrictive permissions by setting an appropriate `umask`, such as `umask 077`. 5. Generate the actor input with a JSON-aware utility instead of string interpolation: ```bash actor_input=$(jq -cn --arg competitor "$competitor" \ '{usernames: [$competitor]}') ``` 6. Use `printf` rather than interpolated `echo` for predictable diagnostic output. 7. Treat competitor-list files as untrusted input when they originate from uploads, shared repositories, or external automation. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
skill.md:360
Finding

Apify API Token Stored in an Unprotected Plaintext Environment File

Content
View full analysis
.env << EOF APIFY_TOKEN=your_apify_token_here PINCHTAB_PORT=9867 EOF ``` ### Technical Analysis The setup instructions place the Apify bearer token in a plaintext `.env` file without first establishing restrictive permissions. The resulting permissions depend on the user's current `umask`, and the documentation does not instruct users to exclude the file from version control. The scripts subsequently load the token and send it as an authorization header to `mcp.apify.com`. That network transmission is consistent with the declared Apify functionality, and the audit found no evidence that the token is intentionally sent to an unrelated endpoint. The confirmed weakness is local secret storage and handling. Because `.env` is created in the current working directory, it may be included in repository commits, development archives, shared workspaces, backups, or other automated file collection. ### Attack Path 1. A user follows the documented configuration procedure and places a real Apify token in `.env`. 2. The file is created with permissions determined by the current environment rather than an explicitly restrictive policy. 3. The file is read by another local account, copied into a shared artifact, collected by backup tooling, or accidentally committed to source control. 4. An attacker obtains the bearer token. 5. The attacker authenticates to Apify with the stolen credential until it expires or is revoked. ### Impact Assessment The effective impact depends on the permissions assigned to the stolen Apify token. Potential consequences include: - Unauthorized use of paid scraping actors and consumption of account resources. - Access to Apify data, actor runs, or datasets permitted by the token. - Exposure of collection targets and business-intelligence activity. - Mo ...[truncated 310 chars]
Remediation
View remediation
.env <<'EOF' APIFY_TOKEN=replace_with_token PINCHTAB_PORT=9867 EOF chmod 600 .env ``` 3. Add `.env` and related secret files to `.gitignore`. 4. Provide a committed `.env.example` containing placeholders only. 5. Avoid placing real tokens in documentation, command history, logs, generated reports, or support output. 6. Use a narrowly scoped Apify token where the platform supports scope restrictions. 7. Establish token expiration and rotation procedures, and immediately revoke credentials suspected of being committed or disclosed. 8. Validate that scripts never print authorization headers or token values during debugging. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (30)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The README instructs users to download and immediately execute a remote shell script via curl piped to bash. This bypasses review and integrity verification, so if the hosting site, network path, or script is compromised, arbitrary code will run on the user's machine with the user's privileges.

Content

Scanner excerpt · README.md (reported line 31)May include surrounding context.

md
npm install -g @apify/mcpc

# PinchTab
curl -fsSL https://pinchtab.com/install.sh | bash

# 配置
export APIFY_TOKEN=your_token

Chaining Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The use of '| bash' creates a command chain that executes untrusted remote content immediately, eliminating opportunities for user inspection or policy controls. In the context of a skill README, this is especially risky because it normalizes unsafe installation behavior for users who may copy and run the command verbatim.

Content

Scanner excerpt · README.md (reported line 31)May include surrounding context.

md
npm install -g @apify/mcpc

# PinchTab
curl -fsSL https://pinchtab.com/install.sh | bash

# 配置
export APIFY_TOKEN=your_token

Credential Access

High
Category
Privilege Escalation
Confidence
92% confidence
Finding

The script imports APIFY_TOKEN from .env using export $(grep APIFY_TOKEN .env | xargs), which is unsafe parsing. A crafted .env line can inject additional shell words or malformed assignments, leading to unintended environment manipulation and potentially unsafe behavior in subsequent commands. In a data-automation skill that users may run locally, trusting and loosely parsing a local file increases risk if the repository or working directory is untrusted.

Content

Scanner excerpt · scripts/competitor-monitor.sh (reported line 19)May include surrounding context.

sh
# 检查 APIFY_TOKEN
if [ -z "$APIFY_TOKEN" ]; then
  if [ -f .env ]; then
    export $(grep APIFY_TOKEN .env | xargs)
  else
    echo "❌ 错误: 未设置 APIFY_TOKEN"

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

This finding refers to the same unsafe credential-loading block that reads .env with grep and xargs. While the script does not appear to steal credentials, its method of loading secrets is brittle and can allow unintended shell/environment effects from a malicious or malformed .env file. Because the token is then used for authenticated outbound requests, compromise of this value or shell state could affect external service access.

Content

Scanner excerpt · scripts/competitor-monitor.sh (reported line 20)May include surrounding context.

sh
# 检查 APIFY_TOKEN
if [ -z "$APIFY_TOKEN" ]; then
  if [ -f .env ]; then
    export $(grep APIFY_TOKEN .env | xargs)
  else
    echo "❌ 错误: 未设置 APIFY_TOKEN"
    exit 1

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The script loads APIFY_TOKEN from .env using export $(grep APIFY_TOKEN .env | xargs), which is an unsafe pattern for handling secrets. It can mis-parse crafted .env content, unintentionally export extra variables, and expose the workflow to environment manipulation if the local .env file is attacker-controlled or untrusted.

Content

Scanner excerpt · scripts/data-collection.sh (reported line 18)May include surrounding context.

sh
# 检查 APIFY_TOKEN
if [ -z "$APIFY_TOKEN" ]; then
  if [ -f .env ]; then
    export $(grep APIFY_TOKEN .env | xargs)
  else
    echo "❌ 错误: 未设置 APIFY_TOKEN"

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

This finding refers to the same unsafe secret-loading behavior from the local .env file. In the context of a data-collection script that will often be run in varied local environments, trusting a nearby .env file without validation increases the risk of accidental secret exposure or shell/environment manipulation.

Content

Scanner excerpt · scripts/data-collection.sh (reported line 19)May include surrounding context.

sh
# 检查 APIFY_TOKEN
if [ -z "$APIFY_TOKEN" ]; then
  if [ -f .env ]; then
    export $(grep APIFY_TOKEN .env | xargs)
  else
    echo "❌ 错误: 未设置 APIFY_TOKEN"
    echo "请设置环境变量: export APIFY_TOKEN=your_token"

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

The skill instructs users to write an API token directly into a plaintext .env file and then load it into the shell. While common in development, this creates credential exposure risk through accidental commits, insecure file permissions, shell history leakage, or reuse in shared workspaces.

Content

Scanner excerpt · skill.md (reported line 100)May include surrounding context.

md
npm install -g @apify/mcpc

# 2. 配置 Token
echo "APIFY_TOKEN=your_token_here" > .env

# 3. 验证
export $(grep APIFY_TOKEN .env | xargs) && mcpc --version

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

Loading APIFY_TOKEN from a local .env file using shell expansion normalizes insecure credential handling and may expose the token in shared or poorly secured environments. The danger is increased because the skill repeatedly encourages this pattern as standard practice.

Content

Scanner excerpt · skill.md (reported line 103)May include surrounding context.

echo "APIFY_TOKEN=your_token_here" > .env

3. 验证

export $(grep APIFY_TOKEN .env | xargs) && mcpc --version

text

**标准工作流:**

Credential Access

High
Category
Privilege Escalation
Confidence
87% confidence
Finding

This command combines reading a token from .env and passing it as a Bearer header for remote API calls. Although functional, it exposes users to credential mishandling and makes it easy to run authenticated scraping operations without emphasizing secure token lifecycle management.

Content

Scanner excerpt · skill.md (reported line 124)May include surrounding context.

bash
# 快速预览(仅显示结果,不保存文件)
export $(grep APIFY_TOKEN .env | xargs) && mcpc --json mcp.apify.com \
  --header "Authorization: Bearer $APIFY_TOKEN" \
  tools-call run-actor \
  actor:="compass/crawler-google-places" \

Credential Access

High
Category
Privilege Escalation
Confidence
87% confidence
Finding

The example repeats insecure token-loading behavior while exporting collected results to local files, increasing the chance of both credential exposure and storage of scraped data without safeguards. This is particularly risky in collaborative repositories or analyst machines where outputs may be synced or committed.

Content

Scanner excerpt · skill.md (reported line 131)May include surrounding context.

md
input:='{"searchStrings": ["coffee shop"], "location": "New York"}'

# 导出 CSV
export $(grep APIFY_TOKEN .env | xargs) && mcpc --json mcp.apify.com \
  --header "Authorization: Bearer $APIFY_TOKEN" \
  tools-call run-actor \
  actor:="compass/crawler-google-places" \

Credential Access

High
Category
Privilege Escalation
Confidence
87% confidence
Finding

The same token handling pattern is used for JSON export workflows, reinforcing insecure secret practices across the skill. Because the skill encourages repeated authenticated scraping, a leaked token could enable unauthorized use of the user's Apify account or quotas.

Content

Scanner excerpt · skill.md (reported line 139)May include surrounding context.

md
| jq -r '.content[0].text' > results.csv

# 导出 JSON
export $(grep APIFY_TOKEN .env | xargs) && mcpc --json mcp.apify.com \
  --header "Authorization: Bearer $APIFY_TOKEN" \
  tools-call run-actor \
  actor:="apify/instagram-profile-scraper" \

Credential Access

High
Category
Privilege Escalation
Confidence
86% confidence
Finding

This mixed workflow combines browser automation, extracted content, and authenticated API usage while still sourcing the token from .env. In a skill focused on broad data collection and competitor monitoring, insecure credential handling can amplify abuse if the environment or workspace is compromised.

Content

Scanner excerpt · skill.md (reported line 176)May include surrounding context.

md
grep -oE '(instagram|facebook|tiktok)\.com/[^" ]+' competitor-content.txt > social-links.txt

# Step 3: 使用 Apify 分析其社交媒体
export $(grep APIFY_TOKEN .env | xargs) && mcpc --json mcp.apify.com \
  --header "Authorization: Bearer $APIFY_TOKEN" \
  tools-call run-actor \
  actor:="apify/instagram-profile-scraper" \

Credential Access

High
Category
Privilege Escalation
Confidence
86% confidence
Finding

The lead-generation example encourages authenticated scraping of business data and later local transformation to CSV while using a plaintext token-loading pattern. This creates dual risk: unauthorized account use if the token leaks and uncontrolled persistence of collected contact data.

Content

Scanner excerpt · skill.md (reported line 272)May include surrounding context.

md
OUTPUT_FILE="coffee-shops-$(date +%Y%m%d).csv"

# Step 1: Apify 采集 Google Maps
export $(grep APIFY_TOKEN .env | xargs) && mcpc --json mcp.apify.com \
  --header "Authorization: Bearer $APIFY_TOKEN" \
  tools-call run-actor \
  actor:="compass/crawler-google-places" \

Credential Access

High
Category
Privilege Escalation
Confidence
86% confidence
Finding

The competitor-monitoring automation repeatedly performs authenticated collection at scale using a token read from .env. Repetition across looped scripts raises operational risk because the token may be broadly reused and the script may be copied into insecure environments.

Content

Scanner excerpt · skill.md (reported line 302)May include surrounding context.

md
echo "分析 $competitor..."

  # Apify 采集数据
  export $(grep APIFY_TOKEN .env | xargs) && mcpc --json mcp.apify.com \
    --header "Authorization: Bearer $APIFY_TOKEN" \
    tools-call run-actor \
    actor:="apify/instagram-profile-scraper" \

Credential Access

High
Category
Privilege Escalation
Confidence
86% confidence
Finding

This trend-scraping workflow uses the same insecure credential pattern in a script intended for repeated content-generation tasks. If the token is exposed, an attacker could misuse API access or consume paid resources under the user's account.

Content

Scanner excerpt · skill.md (reported line 329)May include surrounding context.

md
# trend-to-content.sh

# Step 1: Apify 采集 TikTok 趋势
export $(grep APIFY_TOKEN .env | xargs) && mcpc --json mcp.apify.com \
  --header "Authorization: Bearer $APIFY_TOKEN" \
  tools-call run-actor \
  actor:="clockworks/tiktok-trends-scraper" \

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs users to fetch a remote installation script over the network and pipe it directly to bash. This is dangerous because it executes unreviewed code immediately, allowing compromise if the source is malicious, hijacked, or tampered with in transit or at origin.

Content

Scanner excerpt · skill.md (reported line 357)May include surrounding context.

md
npm install -g @apify/mcpc

# 2. PinchTab 浏览器自动化
curl -fsSL https://pinchtab.com/install.sh | bash

# 3. 配置环境变量
cat > .env << EOF

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

Piping curl output into bash is a classic command-chaining anti-pattern that removes any review barrier between remote content retrieval and local execution. In a skill file meant to be copied by users, this pattern materially increases the chance of arbitrary code execution on the analyst's machine.

Content

Scanner excerpt · skill.md (reported line 357)May include surrounding context.

md
npm install -g @apify/mcpc

# 2. PinchTab 浏览器自动化
curl -fsSL https://pinchtab.com/install.sh | bash

# 3. 配置环境变量
cat > .env << EOF

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The install section explicitly instructs creation of a plaintext .env containing a live API token. Because installation steps are often copy-pasted verbatim, this is one of the highest-risk credential-handling examples in the file and may directly lead to secret leakage via local compromise or source control mistakes.

Content

Scanner excerpt · skill.md (reported line 360)May include surrounding context.

md
curl -fsSL https://pinchtab.com/install.sh | bash

# 3. 配置环境变量
cat > .env << EOF
APIFY_TOKEN=your_apify_token_here
PINCHTAB_PORT=9867
EOF

Credential Access

High
Category
Privilege Escalation
Confidence
86% confidence
Finding

The verification step again loads the token from .env, reinforcing insecure handling throughout the lifecycle from setup to execution. The risk is contextualized by the skill's intended use in automation-heavy environments where secrets often propagate into scripts and shared workspaces.

Content

Scanner excerpt · skill.md (reported line 370)May include surrounding context.

bash
# 验证 Apify
export $(grep APIFY_TOKEN .env | xargs) && mcpc --version

# 验证 PinchTab
pinchtab --version

Credential Access

High
Category
Privilege Escalation
Confidence
86% confidence
Finding

The one-line pipeline combines token loading, authenticated remote execution, JSON processing, and analysis, making it easy to run powerful operations without reviewing security implications. Such convenience pipelines can spread quickly and normalize poor credential hygiene.

Content

Scanner excerpt · skill.md (reported line 439)May include surrounding context.

bash
# 数据采集 + 分析一站式
export $(grep APIFY_TOKEN .env | xargs) && \
mcpc --json mcp.apify.com \
  --header "Authorization: Bearer $APIFY_TOKEN" \
  tools-call run-actor \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file promotes cloud scraping, local Chrome control, and an install-via-curl shell command, but does not include any user-facing warning about effects on privacy, collected third-party data, or system changes. Under the markdown criteria for SQP-2, skill descriptions should warn when behavior could affect user data, privacy, or system integrity.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Comments and runtime output such as error and status messages are written only in Chinese, with no option for the user to select another language. The policy requires avoiding forced language or locale choices unless explicitly justified or opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This shell script sends each competitor username to mcp.apify.com and includes the APIFY_TOKEN in the Authorization header. Although the script prints progress messages, it does not disclose to the user that data is being sent to a third-party service or that an API credential is used for the request.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's comments and terminal output are written in Chinese, which imposes a specific language on users regardless of their locale or preference. The file does not offer any language selection, fallback, or documentation that this is a region-specific tool where Chinese is required.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill heavily promotes web scraping, browser automation, token-based API access, and exporting collected data to local files, but it does not give clear user-facing warnings about handling sensitive data, respecting privacy boundaries, or the fact that commands will write files into the working directory. In this context, the omission is risky because the skill is explicitly designed for collecting third-party data at scale, including contact information and emails, which raises privacy, compliance, and accidental data exposure concerns.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.