Back to skill

Security audit

qianfan-deepresearch

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a legitimate Baidu Qianfan report generator, but it needs Review because it sends research content to a third-party API, encourages command-line API keys, and automatically approves remote workflow steps.

Install only if you are comfortable sending research prompts, generated outlines, and report contents to Baidu Qianfan and receiving remote download links. Prefer `QIANFAN_API_KEY` from a protected environment or credential store instead of `--api-key`, avoid confidential inputs unless approved, and monitor API quota/costs for long-running runs.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/deepresearch.py:64
Finding

API Key Exposed Through Command-Line Arguments

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:211
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (13)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill instructs the agent to access environment variables for secrets and to invoke a network-capable script, but it does not declare any tool scope or permission boundaries. This creates an over-privilege and transparency problem: an orchestrator may grant broader access than intended, and users are not clearly informed that secrets and external network calls are required.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file requires the final user-facing response to follow a fixed Chinese template verbatim, including exact Chinese phrases that must not be changed. This imposes a specific language on all users without offering a language choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 36)May include surrounding context.

请求示例(使用 version):

bash
curl -X POST "https://qianfan.baidubce.com/v2/agent/deepresearch/create" \
  -H "Authorization: Bearer {api_key}" \
  -H "Content-Type: application/json" \
  -d '{"version": "lite"}'

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The structured_outline schema example sets locale to 简体中文, and later examples repeat this locale, which can imply a fixed language expectation. The document does not state that locale is configurable or user-selected, creating a potential language/locale policy issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation explicitly encourages automatically sending "跳过" for clarification and "确认" for outline approval, which removes user review at two decision points. In a research/report-generation skill, this can cause the system to proceed with misunderstood scope, unwanted assumptions, or unreviewed content structure, increasing the risk of inaccurate or policy-problematic outputs without informed user consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documented workflow explicitly auto-skips clarification and auto-confirms the generated outline, removing meaningful user review before sending follow-up actions to the external research agent. In a research/report-generation skill, this can cause unintended scope expansion, inaccurate or risky outputs, and silent transmission of user intent without informed approval.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/workflow.md (reported line 146)May include surrounding context.

md
def create_conversation():
    """Step 1: 创建会话,获取 conversation_id"""
    resp = requests.post(
        f"{BASE_URL}/agent/deepresearch/create",
        headers=HEADERS,
        json={"version": VERSION},

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

The /run call transmits the query payload, conversation state, interrupt_id, and structured outline to an external service. Because this skill is designed to automate full research execution, user prompts and derived content may be forwarded off-platform without an explicit per-run consent or data-sensitivity warning, making unintended disclosure more likely.

Content

Scanner excerpt · references/workflow.md (reported line 163)May include surrounding context.

md
early_stop: callable(event) -> bool,返回 True 时提前退出
    """
    events = []
    with requests.post(
        f"{BASE_URL}/agent/deepresearch/run",
        headers=HEADERS,
        json=payload,

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · references/workflow.md (reported line 168)May include surrounding context.

md
headers=HEADERS,
        json=payload,
        stream=True,
        timeout=None,  # 不设整体超时,用空闲超时控制
    ) as resp:
        resp.raise_for_status()
        last_data_time = time.time()

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
88% confidence
Finding

The HTTP request for the SSE stream is made with timeout=None, which allows the connection to remain open indefinitely at the requests layer. Although the code tracks IDLE_TIMEOUT while processing chunks, a peer that stalls before yielding data or drip-feeds data can keep the process, socket, and worker occupied for a long time, enabling denial-of-service or resource exhaustion in an automated agent environment.

Content

Scanner excerpt · scripts/deepresearch.py (reported line 131)May include surrounding context.

python
headers=make_headers(api_key),
        json=payload,
        stream=True,
        timeout=None,  # 不设整体超时,通过 IDLE_TIMEOUT 控制
    ) as resp:
        resp.raise_for_status()

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script automatically submits the generated outline back to the remote DeepResearch service using the fixed query "确认" and the extracted structured_outline, without any user review or approval step. In an agent setting, this can cause unintended external actions, unwanted compute/resource consumption, and commitment to a report structure the user did not validate, which is especially relevant because the skill advertises a fully automatic end-to-end workflow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The file-output section and final response examples show generated report files with url and download_url, indicating report artifacts are created and made retrievable. The documentation does not warn users that generated content may be stored remotely or exposed through downloadable links, which is relevant to data handling and privacy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language docstring, CLI descriptions, and user-facing messages are presented exclusively in Chinese, with no indication that users can select another language or locale. This can violate language/locale policy where skills should not force a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/deepresearch.py:31