Back to skill

Security audit

老黄历查询 - 即刻数据

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it says, but it handles an API key in a way that can send it to an undocumented configurable endpoint.

Review before installing. Use a low-privilege JikeAPI key, avoid passing the key with --key where shell history or process lists may expose it, do not set JIKE_API_BASE_URL unless you fully trust the endpoint, and assume requested date/time plus the AppKey are sent to a third-party service.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/calendar_lunar_query.py:139
Finding

API Credential Exposed Through a Configurable URL Query String

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (10)

Tainted flow: 'url' from os.environ.get (line 139, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

The request URL is partly derived from the environment variable JIKE_API_BASE_URL, which is treated as untrusted input and is used directly in urllib.request.urlopen. If an attacker can influence the runtime environment, they can redirect requests to an arbitrary host, causing SSRF-style outbound connections and exfiltration of the AppKey in the query string. In this skill context, the script is intended to call a fixed third-party API, so allowing endpoint override increases risk beyond the business need.

Content

Scanner excerpt · scripts/calendar_lunar_query.py (reported line 141)May include surrounding context.

python
params = {"date": date_value, "time": time_value, "appkey": appkey}
    url = f"{API_BASE_URL}{API_PATH}?{urllib.parse.urlencode(params)}"
    try:
        with urllib.request.urlopen(url, timeout=15) as response:
            return json.loads(response.read().decode("utf-8"))
    except urllib.error.HTTPError as exc:
        return {"code": exc.code, "message": f"接口请求失败: HTTP {exc.code}", "data": ""}

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/calendar_lunar_query.py (reported line 51)May include surrounding context.

python
if env_value:
            return env_value

    env_file = Path(__file__).parent / ".env"
    if not env_file.exists():
        return ""

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares executable/network capabilities via metadata and usage instructions but does not define an explicit tool scope such as allowed-tools or permissions. In an agent environment, this can allow broader-than-intended access to environment variables, file reads, and outbound network use, reducing policy enforceability and increasing the blast radius if the skill is misused or invoked unexpectedly.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger description includes broad natural-language examples like '今天宜忌是什么' and '某天适合结婚搬家吗', which can cause the skill to activate in loosely related conversations without clear user intent. Unexpected invocation can lead to unintended external API calls and disclosure of user-supplied date/time data to a third party.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation instructs direct third-party API use but does not clearly warn that user-provided date/time and an API credential will be transmitted to api.jikeapi.cn. This creates a transparency and privacy issue, and may cause operators or users to send data externally without informed consent or proper credential-handling expectations.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The skill performs external transmission to a third-party API, which is expected for its function, but it still introduces data egress and dependency risk. Because the request includes user-supplied inputs and the example places the app key in the URL query string, logs, proxies, or monitoring systems may capture sensitive request details and credentials.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

直接调用 API:

text
GET https://api.jikeapi.cn/v1/calendar/lunar/detail?date=2024-02-02&time=10:30:00&appkey=YOUR_APPKEY

AI 使用步骤

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · _meta.json (reported line 8)May include surrounding context.

json
"title": "老黄历查询 - 即刻数据",
  "description": "输入阳历日期和时间,查询农历日期、黄历宜忌、黄黑道、吉神凶煞、生肖、星座、节气和神位方位等信息。",
  "env": "JIKE_CALENDAR_LUNAR_QUERY_KEY",
  "api_url": "https://api.jikeapi.cn/v1/calendar/lunar/detail",
  "homepage": "https://www.jikeapi.cn/"
}

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

文档整体以中文说明并围绕“老黄历”输出内容展开,但没有说明这是面向中文用户或特定文化场景的区域性技能,也未提供语言/locale 选择。按规则,若技能实际限定特定语言或地区,应明确记录该约束或提供用户选择。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest presents the skill name and behavior description only in Chinese, with no indication that users can opt into another language or that the skill is limited to a Chinese-speaking or region-specific audience. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script presents user-facing error and result text in Chinese only, including command descriptions and printed output. This can violate a language/locale policy when no user opt-in or documented justification for Chinese-only behavior is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.