Back to skill

Security audit

Kimi Search 极简版

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward Kimi web-search helper that uses a Moonshot API key and sends search queries to Moonshot as expected.

Install this only if you are comfortable sending your search queries to Moonshot's API and using a Moonshot/Kimi API key from environment variables or the documented local key files. Prefer a virtual environment and pinned dependency versions if you need reproducible installs.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:36
Finding

Unpinned Third-Party Dependencies Create a Supply-Chain Risk

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (9)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill requires environment variables, reads credential files, and performs network access, but it does not declare any explicit tool scope or permissions. This weakens reviewability and sandbox policy enforcement, increasing the chance that a host agent or user invokes the skill without understanding it can access secrets and send data externally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation tells users to configure API credentials and use a web-search feature, but it does not clearly warn that user queries and related content will be transmitted to a third-party external service. This creates a privacy and data-governance risk, especially if users enter sensitive prompts assuming processing is local or internal.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The behavior description states that in raw mode the system prompt is replaced with a strictly Chinese format, which imposes a locale requirement regardless of user preference. This is a natural-language policy concern because the skill otherwise claims to support both Chinese and English search, but does not provide opt-in or explain why Chinese-only output is required.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/kimi_search.py (reported line 48)May include surrounding context.

python
if not api_key:
        print("Error: MOONSHOT_API_KEY not found.")
        print("Please set it as environment variable or create ~/.config/moonshot/api_key")
        print("Get your API key from: https://platform.moonshot.cn/")
        sys.exit(1)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The RAW_OUTPUT_SYSTEM prompt explicitly instructs the model in Chinese and requires a fixed output format in Chinese. This imposes a specific language choice regardless of the user's language or preference, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 82)May include surrounding context.

md
# Create HTTP client with timeout
    http_client = httpx.Client(
        base_url="https://api.moonshot.cn/v1",
        timeout=60.0,
        follow_redirects=True,
    )

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/kimi_search.py (reported line 86)May include surrounding context.

python
# Create HTTP client with timeout
    http_client = httpx.Client(
        base_url="https://api.moonshot.cn/v1",
        timeout=60.0,
        follow_redirects=True,
    )

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/kimi_search.py (reported line 92)May include surrounding context.

python
# Create HTTP client with timeout
    http_client = httpx.Client(
        base_url="https://api.moonshot.cn/v1",
        timeout=60.0,
        follow_redirects=True,
    )

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script reads API credentials not only from environment variables but also from local files under user-specific paths that are not declared in the skill interface. This expands the skill's access to sensitive local secrets beyond what a simple web-search capability implies, creating unnecessary secret-discovery behavior and increasing the risk of unintended credential use in agent environments.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.