T09 · Insecure Skill Coding Practices
- Location
scripts/bank_branch_query.py:164- Finding
AppKey Exposed in the Request URL Query String
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent bank-branch lookup tool, but it has under-disclosed credential-routing risks that users should review before installing.
Install only if you trust JikeAPI with the bank lookup queries and the AppKey. Prefer setting JIKE_BANK_BRANCH_QUERY_KEY as an environment secret, avoid using --key on the command line, do not set JIKE_API_BASE_URL unless you fully trust the endpoint, and rotate the AppKey if it may have been exposed in logs or shell history.
scripts/bank_branch_query.py:164AppKey Exposed in the Request URL Query String
scripts/bank_branch_query.py:19Unrestricted API Base URL Override Can Redirect Credentials to an Untrusted Server
scripts/bank_branch_query.py:35Command-Line AppKey Input Can Leak Through Process and Command-History Records
The request URL is built from API_BASE_URL, which is taken directly from the JIKE_API_BASE_URL environment variable and then passed to urllib.request.urlopen. In an agent or shared runtime, an attacker who can influence environment variables can redirect requests to an arbitrary host, causing SSRF-style behavior and disclosure of the AppKey in the query string to an attacker-controlled endpoint.
"""
url = f"{API_BASE_URL}{API_PATH_MAP[command]}?{urllib.parse.urlencode({**params, 'appkey': appkey})}"
try:
with urllib.request.urlopen(url, timeout=15) as response:
return json.loads(response.read().decode("utf-8"))
except urllib.error.HTTPError as exc:
return {"code": exc.code, "message": f"接口请求失败: HTTP {exc.code}", "data": ""}
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
if env_value:
return env_value
env_file = Path(__file__).parent / ".env"
if not env_file.exists():
return ""
The skill invokes a Python script and declares reliance on environment variables for API keys, which implies network access and secret handling, but it does not explicitly constrain tool permissions or allowed tools. In an agent environment, this can lead to over-broad execution capability, making it easier for the skill to access files, read secrets, or perform unintended network actions beyond the narrow bank-query use case.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"title": "银行支行、联行号查询 - 即刻数据",
"description": "根据银行名称、省市代码、支行关键词查询支行名称、联行号、省份和城市。",
"env": "JIKE_BANK_BRANCH_QUERY_KEY",
"api_url": "https://api.jikeapi.cn/v1/bank/branch/query",
"homepage": "https://www.jikeapi.cn/"
}
No suspicious patterns detected.