Back to skill

Security audit

IP归属地信息查询

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it says, but it sends the user's API key and queried IP addresses over unencrypted HTTP, which makes credential and lookup data exposure a real concern.

Review before installing. Use this only if you are comfortable sending queried public IP addresses to Juhe, and avoid using it on sensitive customer, incident-response, or internal infrastructure data. Do not pass the API key with --key; prefer an environment variable. The publisher should change the script endpoint to HTTPS before this is treated as low risk.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/ip_lookup.py:25
Finding

API Key and Queried IP Addresses Transmitted over Plaintext HTTP

Content
View full analysis

Vulnerability Details

File Location: scripts/ip_lookup.py, lines 25 and 113–117
Vulnerability Type: Plaintext transmission of sensitive information
Risk Level: High

Vulnerable code:

python
API_URL = "http://apis.juhe.cn/ip/ipNewV3"
python
params = urllib.parse.urlencode({"key": api_key, "ip": ip})
url = f"{API_URL}?{params}"

try:
    with urllib.request.urlopen(url, timeout=10) as resp:
        data = json.loads(resp.read().decode("utf-8"))

Technical Analysis

The script includes the Juhe API key and user-supplied IP address in a URL query string sent over unencrypted HTTP. Because TLS is not used, network observers can read both values. An active man-in-the-middle can also modify API responses or redirect traffic, potentially causing the script to present forged geolocation data.

Transmitting queried public IP addresses to the declared Juhe service is necessary for the Skill's stated functionality. However, plaintext transport is not necessary and exceeds an acceptable least-exposure design. The Skill documentation itself shows an HTTPS endpoint, confirming that protected transport is expected.

Query-string credentials may additionally be captured by intermediary proxy logs or other URL-logging infrastructure.

Attack Path

  1. A user invokes the script with a valid Juhe API key and one or more public IP addresses.
  2. The script constructs an HTTP URL containing both the API key and queried IP address.
  3. An attacker observes or controls a network segment between the client and API service, such as an untrusted Wi-Fi network, compromised gateway, or transparent proxy.
  4. The attacker captures the plaintext request and extracts the API key and lookup target.
  5. The attacker can reuse the key to consume the victim's API quota.
  6. If actively intercepting traffic, the attacker can alter the response and cause the script to display false location or ISP information.

...[truncated 397 chars]

Remediation
View remediation

Remediation Suggestions

  • Change the endpoint to https://apis.juhe.cn/ip/ipNewV3.
  • Do not implement fallback or downgrade to plaintext HTTP.
  • Retain normal TLS certificate and hostname verification.
  • If supported by the provider, transmit the credential through an authorization header or request body rather than a query string.
  • Avoid logging complete request URLs containing credentials.
  • Rotate any API key that may previously have been used over the plaintext endpoint.
  • Add a test asserting that the configured API URL uses the https scheme.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/ip_lookup.py:67
Finding

API Key Exposure through Command-Line Arguments and Unprotected Plaintext Storage

Content
View full analysis

Vulnerability Details

File Location: scripts/ip_lookup.py, lines 67–75 and 198–203; SKILL.md, lines 35–39
Vulnerability Type: Insecure credential handling
Risk Level: Medium

Vulnerable code and documented usage:

python
env_file = Path(__file__).parent / ".env"
if env_file.exists():
    for line in env_file.read_text(encoding="utf-8").splitlines():
        line = line.strip()
        if line.startswith("JUHE_IP_KEY="):
            val = line.split("=", 1)[1].strip().strip('"').strip("'")
            if val:
                return val
python
if "--key" in args:
    idx = args.index("--key")
    if idx + 1 < len(args):
        cli_key = args[idx + 1]
        args = args[:idx] + args[idx + 2:]
    else:
        print("错误: --key 后需要提供 API Key 值")
        sys.exit(1)
bash
echo "JUHE_IP_KEY=你的AppKey" > scripts/.env
python scripts/ip_lookup.py --key 你的AppKey 8.8.8.8

Technical Analysis

The Skill supports passing an API key directly in command-line arguments. Depending on the operating system and shell, command-line secrets can be retained in shell history and may be visible to process-inspection tools while the command is running.

The documentation also recommends creating a plaintext .env file without requiring restrictive file permissions. The reviewed project structure contains no demonstrated ignore rule protecting scripts/.env from accidental source-control inclusion.

A dedicated environment variable is already available and is sufficient for the Skill's functionality. The command-line option and permissive plaintext-file workflow therefore increase credential exposure beyond the minimum required.

Attack Path

Command-line exposure:

  1. A user follows the documented --key example.
  2. The shell records the command, including the API key, in its history, or the operating system exposes the process arguments during executio ...[truncated 918 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove or strongly discourage the --key option.
  • Prefer the existing JUHE_IP_KEY environment variable or integration with a protected secret manager.
  • If interactive credential entry is needed, use a non-echoing prompt such as getpass.getpass().
  • Add scripts/.env to .gitignore.
  • Document creation of the file with restrictive permissions, such as:
    bash
    install -m 600 /dev/null scripts/.env
    printf '%s\n' 'JUHE_IP_KEY=your_key' > scripts/.env
    
  • At runtime, reject or warn about .env files that are readable by group or other users on platforms supporting POSIX permissions.
  • Advise users to remove affected shell-history entries and rotate keys previously supplied on the command line or stored insecurely.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (11)

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

Passing the API key directly on the command line can expose it through shell history, process listings, audit logs, or command telemetry. In the context of an agent skill, this is more dangerous because automation layers may capture or echo commands, creating multiple opportunities for secret leakage.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

md
export JUHE_IP_KEY=你的AppKey

# 方式二:.env 文件(在脚本目录创建)
echo "JUHE_IP_KEY=你的AppKey" > scripts/.env

# 方式三:每次命令行传入
python scripts/ip_lookup.py --key 你的AppKey 8.8.8.8

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

md
API Key 配置(任选其一,优先级从高到低):
    1. 环境变量: export JUHE_IP_KEY=your_api_key
    2. 脚本同目录的 .env 文件: JUHE_IP_KEY=your_api_key
    3. 直接传参: python ip_lookup.py --key your_api_key <IP>

免费申请 API Key: https://www.juhe.cn/docs/api/id/1

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/ip_lookup.py (reported line 13)May include surrounding context.

python
API Key 配置(任选其一,优先级从高到低):
    1. 环境变量: export JUHE_IP_KEY=your_api_key
    2. 脚本同目录的 .env 文件: JUHE_IP_KEY=your_api_key
    3. 直接传参: python ip_lookup.py --key your_api_key <IP>

免费申请 API Key: https://www.juhe.cn/docs/api/id/1

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/ip_lookup.py (reported line 222)May include surrounding context.

python
API Key 配置(任选其一,优先级从高到低):
    1. 环境变量: export JUHE_IP_KEY=your_api_key
    2. 脚本同目录的 .env 文件: JUHE_IP_KEY=your_api_key
    3. 直接传参: python ip_lookup.py --key your_api_key <IP>

免费申请 API Key: https://www.juhe.cn/docs/api/id/1

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/ip_lookup.py (reported line 62)May include surrounding context.

python
if env_key:
        return env_key

    env_file = Path(__file__).parent / ".env"
    if env_file.exists():
        for line in env_file.read_text(encoding="utf-8").splitlines():
            line = line.strip()

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill documentation indicates it will use environment variables, read local files such as scripts/.env, and make outbound network requests, but it does not declare an explicit tool scope or permissions boundary. This can cause the agent to invoke capabilities the user did not clearly authorize, increasing the risk of unintended secret access or data egress.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger examples are broad enough that the skill may activate on generic user requests like '查一下这个IP' or batch lookups without making the third-party lookup behavior explicit. Overbroad activation can lead to accidental transmission of user-supplied IPs to an external service when the user may have expected a local-only explanation or validation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill description does not prominently warn that queried IP addresses will be sent to a third-party API provider. Because IP addresses can be sensitive operational or personal data in some contexts, failing to disclose this external transmission creates a privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script sends both the queried IP address and the API key to a third-party service using plain HTTP, allowing interception or modification by any network observer or man-in-the-middle. Because IPs may be sensitive operational data and the API key is a credential, this creates real confidentiality and integrity risk in normal use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

All user-facing instructions and output strings in this file are written in Chinese, with no indication that users may select another language or that the tool is intentionally limited to a Chinese-speaking context. The policy explicitly calls out forcing a specific language without user opt-in as a violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest states the Juhe API offers '每天500次调用', but the script's user-facing help says '每天50次免费调用'. This is an active documentation contradiction that can mislead users about the service limits even though the code logic is otherwise aligned with the skill purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.