Back to skill

Security audit

银行支行、联行号查询 - 即刻数据

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent bank-branch lookup tool, but it has under-disclosed credential-routing risks that users should review before installing.

Install only if you trust JikeAPI with the bank lookup queries and the AppKey. Prefer setting JIKE_BANK_BRANCH_QUERY_KEY as an environment secret, avoid using --key on the command line, do not set JIKE_API_BASE_URL unless you fully trust the endpoint, and rotate the AppKey if it may have been exposed in logs or shell history.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/bank_branch_query.py:164
Finding

AppKey Exposed in the Request URL Query String

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/bank_branch_query.py:19
Finding

Unrestricted API Base URL Override Can Redirect Credentials to an Untrusted Server

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/bank_branch_query.py:35
Finding

Command-Line AppKey Input Can Leak Through Process and Command-History Records

Content
View full analysis
str: """ Function that loads the AppKey. """ if cli_key: return cli_key.strip() ``` The value is supplied by the `--key` command-line option and is later used as the API credential. ### Technical Analysis Command-line arguments are not an appropriate channel for long-lived secrets. Depending on the operating system and execution environment, arguments can be exposed through process inspection, shell history, audit records, CI job output, orchestration metadata, or diagnostic telemetry. The application gives the command-line value priority over environment-based and file-based configuration. A user following this option for temporary testing may therefore expose a valid AppKey outside the process. ### Attack Path 1. A user invokes the script with a command such as `--key SECRET`. 2. The shell records the command in its history, or a process-monitoring facility captures the argument vector while the process is running. 3. Another local user, administrator, CI log reader, or monitoring-system operator accesses the recorded arguments. 4. The party extracts the AppKey and reuses it to access the API. ### Impact Assessment The exposed secret grants the API access and quota associated with the AppKey. Potential consequences include unauthorized requests, quota consumption, service charges, or disruption caused by key revocation. This issue does not grant additional operating-system privileges by itself. The practical scope is the API account represented by the leaked credential, and exploitation generally requires access to process metadata, shell history, or collected execution logs. ]]>
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Tainted flow: 'url' from os.environ.get (line 173, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
93% confidence
Finding

The request URL is built from API_BASE_URL, which is taken directly from the JIKE_API_BASE_URL environment variable and then passed to urllib.request.urlopen. In an agent or shared runtime, an attacker who can influence environment variables can redirect requests to an arbitrary host, causing SSRF-style behavior and disclosure of the AppKey in the query string to an attacker-controlled endpoint.

Content

Scanner excerpt · scripts/bank_branch_query.py (reported line 175)May include surrounding context.

python
"""
    url = f"{API_BASE_URL}{API_PATH_MAP[command]}?{urllib.parse.urlencode({**params, 'appkey': appkey})}"
    try:
        with urllib.request.urlopen(url, timeout=15) as response:
            return json.loads(response.read().decode("utf-8"))
    except urllib.error.HTTPError as exc:
        return {"code": exc.code, "message": f"接口请求失败: HTTP {exc.code}", "data": ""}

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/bank_branch_query.py (reported line 53)May include surrounding context.

python
if env_value:
            return env_value

    env_file = Path(__file__).parent / ".env"
    if not env_file.exists():
        return ""

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill invokes a Python script and declares reliance on environment variables for API keys, which implies network access and secret handling, but it does not explicitly constrain tool permissions or allowed tools. In an agent environment, this can lead to over-broad execution capability, making it easier for the skill to access files, read secrets, or perform unintended network actions beyond the narrow bank-query use case.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · _meta.json (reported line 8)May include surrounding context.

json
"title": "银行支行、联行号查询 - 即刻数据",
  "description": "根据银行名称、省市代码、支行关键词查询支行名称、联行号、省份和城市。",
  "env": "JIKE_BANK_BRANCH_QUERY_KEY",
  "api_url": "https://api.jikeapi.cn/v1/bank/branch/query",
  "homepage": "https://www.jikeapi.cn/"
}

Static analysis

No suspicious patterns detected.