T09 · Insecure Skill Coding Practices
- Location
scripts/calendar_foto_query.py:23- Finding
API Credential Exposure Through a Configurable Request Destination
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill performs the advertised Buddhist calendar lookup, but its script can send the configured API key to an environment-selected request destination that is not disclosed in the skill instructions.
Review before installing. Only use this skill with a Jike API key you are comfortable exposing to this integration, avoid passing keys on the command line, and ensure the runtime environment cannot set JIKE_API_BASE_URL to an untrusted host. The publisher should remove or strictly validate that override, avoid putting the key in URLs if the API supports another method, and narrow the trigger description to Buddhist calendar/date lookups.
scripts/calendar_foto_query.py:23API Credential Exposure Through a Configurable Request Destination
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
"""
url = f"{API_BASE_URL}{API_PATH}?{urllib.parse.urlencode({'date': date_value, 'appkey': appkey})}"
try:
with urllib.request.urlopen(url, timeout=15) as response:
return json.loads(response.read().decode("utf-8"))
except urllib.error.HTTPError as exc:
return {"code": exc.code, "message": f"接口请求失败: HTTP {exc.code}", "data": ""}
整体上,代码与主要功能描述基本一致:它确实根据阳历日期查询佛历详细信息,并展示佛历日期、说明、节日、斋日、星宿和吉凶等内容,也确实使用即刻数据接口。读取 AppKey、参数解析、错误处理和 JSON 输出都属于实现细节,不构成越权或未声明能力。但声明中的“适用场景”包含“行情查询”,这是与实际代码行为明显不符的额外用途描述,因为代码没有任何行情类接口、字段或逻辑。因此应判定存在描述与行为不一致,但不属于恶意或隐蔽能力,属于声明范围中混入了不相关场景。
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
env_value = os.environ.get(env_name, "").strip()
if env_value:
return env_value
env_file = Path(__file__).parent / ".env"
if not env_file.exists():
return ""
for line in env_file.read_text(encoding="utf-8").splitlines():
The skill declares environment, file-read, and network-capable behavior but does not specify any explicit tool scope such as permissions or allowed-tools. This weakens containment and reviewability, increasing the chance that an agent invokes the skill with broader capabilities than necessary, especially since it accesses an API key and performs outbound requests.
The trigger conditions are overly broad and ambiguous, which can cause the agent to invoke this skill in contexts beyond simple date lookup. Because the skill sends user-supplied query data to a third-party API, broad triggering increases the risk of unnecessary external transmission and accidental handling of unrelated user content.
The markdown instructs use of an external API but does not warn that user query data will be transmitted to a third-party service. This creates a privacy and consent problem: users and downstream agents may disclose dates or surrounding contextual data externally without clear notice or approval.
The skill explicitly performs external network transmission to a third-party endpoint using an API key. In this skill's context, outbound access is expected, but it still carries security risk because user-supplied inputs and secrets are involved, and the request example places the appkey in the URL where it may be logged by intermediaries.
直接调用 API:
GET https://api.jikeapi.cn/v1/calendar/foto/detail?appkey=YOUR_APPKEY
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"title": "佛历查询 - 即刻数据",
"description": "输入阳历日期,查询佛历日期、完整说明、佛教节日、斋日、星宿和吉凶等信息。",
"env": "JIKE_CALENDAR_FOTO_QUERY_KEY",
"api_url": "https://api.jikeapi.cn/v1/calendar/foto/detail",
"homepage": "https://www.jikeapi.cn/"
}
The script places the AppKey in the query string, which can leak credentials through logs, browser/history-like tooling, reverse proxies, monitoring systems, and exception traces. Even when using HTTPS, URL query parameters are commonly captured by infrastructure components, increasing the chance of credential exposure.
The title and description are presented exclusively in Chinese, which can imply a fixed language/locale experience without any stated opt-in or scope limitation. Under the policy rule, language constraints should either offer a user choice or clearly document that the skill is intended for a specific locale.
No suspicious patterns detected.