T08 · Insecure Dependencies
- Location
SKILL.md:36- Finding
Unpinned Third-Party Dependencies Create a Supply-Chain Risk
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a straightforward Kimi web-search helper that uses a Moonshot API key and sends search queries to Moonshot as expected.
Install this only if you are comfortable sending your search queries to Moonshot's API and using a Moonshot/Kimi API key from environment variables or the documented local key files. Prefer a virtual environment and pinned dependency versions if you need reproducible installs.
SKILL.md:36Unpinned Third-Party Dependencies Create a Supply-Chain Risk
The skill requires environment variables, reads credential files, and performs network access, but it does not declare any explicit tool scope or permissions. This weakens reviewability and sandbox policy enforcement, increasing the chance that a host agent or user invokes the skill without understanding it can access secrets and send data externally.
The documentation tells users to configure API credentials and use a web-search feature, but it does not clearly warn that user queries and related content will be transmitted to a third-party external service. This creates a privacy and data-governance risk, especially if users enter sensitive prompts assuming processing is local or internal.
The behavior description states that in raw mode the system prompt is replaced with a strictly Chinese format, which imposes a locale requirement regardless of user preference. This is a natural-language policy concern because the skill otherwise claims to support both Chinese and English search, but does not provide opt-in or explain why Chinese-only output is required.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
if not api_key:
print("Error: MOONSHOT_API_KEY not found.")
print("Please set it as environment variable or create ~/.config/moonshot/api_key")
print("Get your API key from: https://platform.moonshot.cn/")
sys.exit(1)
The RAW_OUTPUT_SYSTEM prompt explicitly instructs the model in Chinese and requires a fixed output format in Chinese. This imposes a specific language choice regardless of the user's language or preference, which matches the language/locale policy violation criteria.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Create HTTP client with timeout
http_client = httpx.Client(
base_url="https://api.moonshot.cn/v1",
timeout=60.0,
follow_redirects=True,
)
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Create HTTP client with timeout
http_client = httpx.Client(
base_url="https://api.moonshot.cn/v1",
timeout=60.0,
follow_redirects=True,
)
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Create HTTP client with timeout
http_client = httpx.Client(
base_url="https://api.moonshot.cn/v1",
timeout=60.0,
follow_redirects=True,
)
The script reads API credentials not only from environment variables but also from local files under user-specific paths that are not declared in the skill interface. This expands the skill's access to sensitive local secrets beyond what a simple web-search capability implies, creating unnecessary secret-discovery behavior and increasing the risk of unintended credential use in agent environments.
No suspicious patterns detected.