Back to skill

Security audit

银行卡类型及真伪查询 - 即刻数据

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent bank-card lookup purpose, but it handles full card numbers and an API key in ways that need careful review before installation.

Review this before installing if you may enter real payment-card numbers. Only use it with explicit user intent, avoid JSON output for card lookups unless downstream logs are controlled, do not set JIKE_API_BASE_URL outside trusted testing, and assume submitted card numbers and the API key may appear in service or proxy URL logs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/bank_card_query.py:23
Finding

Configurable API Endpoint Can Exfiltrate API Credentials and Full Card Numbers

Content
View full analysis

Vulnerability Details

File Location: scripts/bank_card_query.py, lines 23 and 198–200
Vulnerability Type: Unrestricted destination override for sensitive network requests
Risk Level: High

Vulnerable Code

python
API_BASE_URL = os.environ.get("JIKE_API_BASE_URL", "https://api.jikeapi.cn").rstrip("/")
python
url = f"{API_BASE_URL}{API_PATH_MAP[command]}?{urllib.parse.urlencode({**params, 'appkey': appkey})}"
try:
    with urllib.request.urlopen(url, timeout=15) as response:
        return json.loads(response.read().decode("utf-8"))

Technical Analysis

The API destination can be replaced through the undocumented JIKE_API_BASE_URL environment variable. The script does not validate the URL scheme, hostname, port, or resolved destination before sending a request.

The generated request includes the AppKey and all business parameters in its query string. For a card query, those parameters include the full card number. Consequently, setting the base URL to an attacker-controlled HTTP or HTTPS endpoint causes the script to disclose both values.

HTTPS is not enforced, and the destination is not restricted to the declared api.jikeapi.cn service. The request implementation may also follow redirects, while the code does not verify that the final destination remains within an approved origin.

Attack Path

  1. An attacker, compromised launcher, malicious wrapper, or unsafe runtime configuration sets JIKE_API_BASE_URL to an attacker-controlled URL.
  2. The user or AI Agent invokes the documented card command with a bank card number.
  3. load_appkey() obtains the configured JikeAPI credential.
  4. request_api() appends the credential and complete card number to the attacker-selected URL.
  5. urllib.request.urlopen() transmits the request to the attacker-controlled server.
  6. The attacker records and reuses the AppKey and obtains the submitted payment-card data.

Impact

...[truncated 609 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the production endpoint override and use a fixed, reviewed API origin.
  • If an override is required for testing, enable it only through an explicit development mode.
  • Parse the URL and require the https scheme, the exact approved hostname api.jikeapi.cn, and an approved port.
  • Reject URLs containing user information, fragments, unexpected ports, or unapproved hosts.
  • Prevent or validate redirects so that sensitive values cannot be forwarded to another origin.
  • Put the AppKey in an authorization header rather than the URL.
  • Send the card number in a POST body rather than a query string.
  • Ensure application, proxy, and server logs redact credentials and card data.
  • Add automated tests confirming that HTTP URLs, lookalike domains, embedded credentials, and cross-origin redirects are rejected.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/bank_card_query.py:313
Finding

JSON Output Bypasses Default Bank Card Number Masking

Content
View full analysis

Vulnerability Details

File Location: scripts/bank_card_query.py, lines 313–315
Vulnerability Type: Sensitive payment data exposure in output
Risk Level: Medium

Vulnerable Code

python
if args.json_output:
    print(json.dumps(payload, ensure_ascii=False, indent=2))
    return 0 if int(payload.get("code", 0) or 0) == 200 else 2

Technical Analysis

Human-readable card output calls mask_bank_card() unless the user explicitly supplies --no-mask. JSON output instead serializes the complete API response without applying the masking policy.

If the API response includes data.bank_card, JSON mode prints that value verbatim. The documented JSON command does not require --no-mask, so selecting an output format implicitly disables a security control that is otherwise enabled by default.

Full card numbers may consequently enter terminal scrollback, shell-session captures, AI Agent context, orchestration logs, continuous-integration logs, or other systems that collect standard output.

Attack Path

  1. A user or AI Agent invokes the card query with the documented --json option.
  2. The full card number is sent to the API.
  3. The API returns a payload containing the data.bank_card field.
  4. The JSON branch serializes the payload directly without calling mask_bank_card().
  5. The full card number is exposed to any process, person, or logging system that can access standard output.

Impact Assessment

This issue does not provide elevated local privileges or code execution. Its impact is unauthorized disclosure and retention of payment-card data.

Exposure can extend to terminal users, Agent operators, log administrators, monitoring platforms, build systems, and downstream programs consuming the JSON. The practical scope depends on where command output is captured and how long it is retained.

Remediation
View remediation

Remediation Suggestions

  • Create a sanitized copy of the response before JSON serialization.
  • Mask or omit data.bank_card by default in both text and JSON modes.
  • Only return the complete value when the user explicitly supplies --no-mask.
  • Consider requiring an additional confirmation mechanism before emitting complete payment-card data.
  • Document the sensitive-output behavior clearly.
  • Add tests proving that --json alone never prints a full card number and that masking preserves only the intended BIN and final four digits.
  • Review downstream logging and retention policies to ensure payment-card data is not stored unnecessarily.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/bank_card_query.py:198
Finding

API Key and Full Card Number Are Transmitted in URL Query Parameters

Content
View full analysis

Vulnerability Details

File Location: scripts/bank_card_query.py, line 198
Vulnerability Type: Sensitive information placed in request URLs
Risk Level: Medium

Vulnerable Code

python
url = f"{API_BASE_URL}{API_PATH_MAP[command]}?{urllib.parse.urlencode({**params, 'appkey': appkey})}"

Technical Analysis

The script combines all business parameters with the AppKey and encodes them into the request URL. For the card command, params contains the full bank card number.

Even when HTTPS protects data in transit, URLs are commonly recorded by destination access logs, reverse proxies, API gateways, monitoring agents, tracing systems, debugging tools, and exception telemetry. Placing credentials and payment-card data in a URL therefore increases their exposure beyond the components that need to process them.

The AppKey also functions as a reusable credential. Its presence in retained URL logs can permit later unauthorized API use.

Attack Path

  1. A user performs an ordinary card query.
  2. The script builds a URL containing both bank_card and appkey.
  3. The request passes through the API service and any configured proxy, gateway, monitoring, or tracing infrastructure.
  4. One or more components record the complete request URL.
  5. An individual with log access, or an attacker who later compromises the logging system, extracts the AppKey and full card number.
  6. The exposed AppKey may be reused against the API within its assigned permissions and quota.

Impact Assessment

Exploitation does not grant local system privileges. It can expose a reusable API credential and sensitive payment-card identifiers to parties with access to network or application logs.

The scope includes infrastructure that records complete URLs and every card query retained there. Credential misuse may consume account quota, incur service costs, or access API functionality authorized to the exposed key.

Remediation
View remediation

Remediation Suggestions

  • Change the card lookup to an HTTPS POST request.
  • Place the AppKey in a dedicated authorization header.
  • Put the card number in the POST body rather than the URL.
  • Ensure redirects do not forward authorization headers or sensitive bodies to unapproved origins.
  • Configure clients, proxies, API gateways, and server logs to redact card numbers and authorization data.
  • Avoid including complete request bodies or authorization headers in debug and exception telemetry.
  • Rotate any AppKeys that may already have been retained in accessible URL logs.
  • Establish retention and access controls appropriate for logs that may historically contain card numbers.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (7)

Tainted flow: 'url' from os.environ.get (line 202, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
94% confidence
Finding

The request URL is built from API_BASE_URL, which is directly influenced by the JIKE_API_BASE_URL environment variable, and then used in urllib.request.urlopen without validation. In a skill context, this enables SSRF-style redirection of outbound requests and can leak sensitive query data such as bank card numbers and the appkey to an attacker-controlled endpoint if the environment is manipulated.

Content

Scanner excerpt · scripts/bank_card_query.py (reported line 204)May include surrounding context.

python
"""
    url = f"{API_BASE_URL}{API_PATH_MAP[command]}?{urllib.parse.urlencode({**params, 'appkey': appkey})}"
    try:
        with urllib.request.urlopen(url, timeout=15) as response:
            return json.loads(response.read().decode("utf-8"))
    except urllib.error.HTTPError as exc:
        return {"code": exc.code, "message": f"接口请求失败: HTTP {exc.code}", "data": ""}

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/bank_card_query.py (reported line 54)May include surrounding context.

python
if env_value:
            return env_value

    env_file = Path(__file__).parent / ".env"
    if not env_file.exists():
        return ""

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares executable capabilities requiring environment access and network use, but does not define any explicit tool scope such as permissions or allowed-tools. That creates an overbroad execution model where a host agent may grant more access than is necessary, increasing the risk of unintended data exposure or misuse of the API key and network functions.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

The skill sends user-supplied bank card numbers to an external third-party API endpoint, which is a real data exfiltration surface because card numbers are sensitive financial data. Even if the service is legitimate and the intent appears benign, transmitting full PAN-like data to an external provider creates privacy, compliance, and retention risks if users are not clearly informed and consent is not obtained.

Content

Scanner excerpt · _meta.json (reported line 8)May include surrounding context.

json
"title": "银行卡类型及真伪查询 - 即刻数据",
  "description": "输入银行卡号,查询卡类型、卡名称、卡 BIN、发卡行、银行官网和客服电话。",
  "env": "JIKE_BANK_CARD_QUERY_KEY",
  "api_url": "https://api.jikeapi.cn/v1/bank/card/query",
  "homepage": "https://www.jikeapi.cn/"
}

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill transmits full bank card numbers to a third-party remote API during execution, but there is no runtime confirmation or explicit user-facing warning at the point the data leaves the system. Although the feature requires remote lookup to function, bank card numbers are sensitive financial data, and the skill context increases risk because users may assume masking in output also means masking in transit.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The title and description are written entirely in Chinese, and the manifest does not state that the skill is China-specific or offer any language choice. That can amount to a language/locale policy issue because it implicitly forces a specific language without documented user opt-in or justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The manifest description says only '输入银行卡号,查询…', which describes a very general condition based on any bank-card-number input but does not define when this skill should or should not activate. In a manifest file, that lack of specificity can create ambiguous routing or unintended invocation if other skills also handle numeric or financial inputs.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.