Back to skill

Security audit

道历查询 - 即刻数据

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly does what it says, but it has an undisclosed API endpoint override that can redirect the user's AppKey to another server.

Install only if you trust the publisher and runtime environment. Do not set JIKE_API_BASE_URL unless you intentionally control the destination, prefer the documented JIKE_CALENDAR_TAO_QUERY_KEY environment variable, and avoid passing the AppKey with --key in command lines or logs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/calendar_tao_query.py:23
Finding

Unvalidated API Base URL Allows AppKey Exfiltration

Content
View full analysis

Vulnerability Details

File Location: scripts/calendar_tao_query.py, lines 23 and 111
Vulnerability Type: Unvalidated endpoint override and credential disclosure
Risk Level: High

Vulnerable Code

python
API_BASE_URL = os.environ.get("JIKE_API_BASE_URL", "https://api.jikeapi.cn").rstrip("/")
python
url = f"{API_BASE_URL}{API_PATH}?{urllib.parse.urlencode({'date': date_value, 'appkey': appkey})}"

Technical Analysis

The undocumented JIKE_API_BASE_URL environment variable can override the intended API origin with an arbitrary URL. The value is used without validating its scheme, hostname, port, or trust relationship.

The application subsequently places the AppKey in the URL query string and sends the request to the configured origin. Consequently, a malicious or compromised launcher that can inject environment variables can redirect the request to an attacker-controlled endpoint. Supplying an http:// endpoint would also permit plaintext transmission.

Query-string credentials may additionally be retained by HTTP server logs, reverse proxies, monitoring systems, and other URL-processing infrastructure.

Attack Path

  1. An attacker compromises or controls the process launcher, service configuration, CI job, wrapper script, or other mechanism that defines the skill's environment.
  2. The attacker sets JIKE_API_BASE_URL to an attacker-controlled endpoint, such as https://attacker.example.
  3. A legitimate AppKey remains available through JIKE_CALENDAR_TAO_QUERY_KEY, JIKE_APPKEY, --key, or scripts/.env.
  4. The user or agent invokes the documented calendar query.
  5. The script constructs a URL under the attacker-controlled origin and embeds both date and appkey in its query string.
  6. The attacker's server receives and records the AppKey and queried date.

Impact Assessment

The attacker can obtain the API credential used by the skill and then perform request ...[truncated 438 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the JIKE_API_BASE_URL override if custom API endpoints are not a required feature.
  2. If configurability is required, parse the URL and enforce an explicit allowlist:
    • Require the https scheme.
    • Require the exact approved hostname, such as api.jikeapi.cn.
    • Reject embedded user information, fragments, unexpected ports, and deceptive subdomains.
  3. Construct URLs from a fixed trusted origin rather than concatenating an unrestricted environment value.
  4. Prefer transmitting credentials in an authorization header instead of the query string if the API supports it.
  5. Ensure launch configurations and environment-variable sources are writable only by trusted principals.
  6. Add tests confirming that HTTP URLs, unrelated hosts, deceptive subdomains, and malformed endpoint values are rejected.

T09 · Insecure Skill Coding Practices

Note
Location
scripts/calendar_tao_query.py:44
Finding

Command-Line AppKey Input Can Expose Credentials to Local Observers

Content
View full analysis

Vulnerability Details

File Location: scripts/calendar_tao_query.py, lines 44–45 and 81
Vulnerability Type: Sensitive credential exposure through command-line arguments
Risk Level: Low

Vulnerable Code

python
if cli_key:
    return cli_key.strip()
python
parser.add_argument("--key", dest="cli_key", help="临时传入即刻数据 AppKey")

Technical Analysis

The script permits an AppKey to be supplied directly through the --key command-line argument. Command-line arguments are commonly visible in process listings and process-inspection interfaces while the program is running. They may also be retained in shell history, terminal logs, audit records, CI output, orchestration metadata, or diagnostic telemetry.

Treating a command-line argument as a credential-input mechanism therefore expands the number of locations in which the secret may be exposed or persisted.

Attack Path

  1. A user or automation system invokes the script with a command such as python3 scripts/calendar_tao_query.py --date 2025-01-15 --key SECRET.
  2. The complete command line is recorded in shell history, process metadata, audit logs, job configuration, or telemetry.
  3. A local user or log reader with access to one of those sources retrieves the AppKey.
  4. The exposed key is reused to make unauthorized requests to the API.

Impact Assessment

An attacker who recovers the argument can act with the API permissions assigned to the AppKey and consume the victim's API quota. This finding does not independently provide elevated local privileges or arbitrary code execution.

The practical scope depends on local process-visibility controls, logging practices, shell configuration, and the permissions associated with the exposed key.

Remediation
View remediation

Remediation Suggestions

  1. Remove or deprecate the --key option and use a protected environment variable or secret manager instead.
  2. If interactive credential entry is necessary, read the key from standard input with terminal echo disabled, for example through Python's getpass facility.
  3. Ensure any local credential file has restrictive permissions and is excluded from source control, logs, and packaged artifacts.
  4. Document that credentials must not be supplied in shell commands, job arguments, or other routinely logged fields.
  5. Rotate any AppKey that may already have been passed through command-line arguments and review relevant histories and logs for exposure.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (7)

Tainted flow: 'url' from os.environ.get (line 113, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

The request URL is built using API_BASE_URL sourced from an environment variable and then passed directly to urlopen. In an agent/skill environment, this allows runtime redirection of outbound requests to an attacker-controlled host, which can exfiltrate the AppKey in the query string and enable SSRF-style network access beyond the intended jikeapi endpoint.

Content

Scanner excerpt · scripts/calendar_tao_query.py (reported line 115)May include surrounding context.

python
"""
    url = f"{API_BASE_URL}{API_PATH}?{urllib.parse.urlencode({'date': date_value, 'appkey': appkey})}"
    try:
        with urllib.request.urlopen(url, timeout=15) as response:
            return json.loads(response.read().decode("utf-8"))
    except urllib.error.HTTPError as exc:
        return {"code": exc.code, "message": f"接口请求失败: HTTP {exc.code}", "data": ""}

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/calendar_tao_query.py (reported line 51)May include surrounding context.

python
env_value = os.environ.get(env_name, "").strip()
        if env_value:
            return env_value
    env_file = Path(__file__).parent / ".env"
    if not env_file.exists():
        return ""
    for line in env_file.read_text(encoding="utf-8").splitlines():

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill invokes a Python script, reads environment variables for API keys, and makes outbound network requests, but it does not declare any explicit tool scope such as permissions or allowed-tools. This creates an authorization gap where an agent platform may grant broader capabilities than users or operators expect, increasing the risk of unintended file, environment, or network access.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description says the skill is suitable not only for date queries but also for broad '行情查询' scenarios, which can cause the agent to activate this skill for unrelated user requests. Over-broad routing increases the chance of unnecessary external calls and data exposure, especially when the skill uses credentials and network access.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

md
"title": "道历查询 - 即刻数据",
  "description": "输入阳历日期,查询道历日期、完整说明、道教节日、三会三元、八节、五腊、戊日等信息。",
  "env": "JIKE_CALENDAR_TAO_QUERY_KEY",
  "api_url": "https://api.jikeapi.cn/v1/calendar/tao/detail",
  "homepage": "https://www.jikeapi.cn/"
}

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · _meta.json (reported line 8)May include surrounding context.

json
"title": "道历查询 - 即刻数据",
  "description": "输入阳历日期,查询道历日期、完整说明、道教节日、三会三元、八节、五腊、戊日等信息。",
  "env": "JIKE_CALENDAR_TAO_QUERY_KEY",
  "api_url": "https://api.jikeapi.cn/v1/calendar/tao/detail",
  "homepage": "https://www.jikeapi.cn/"
}

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This manifest presents the skill name and behavior description only in Chinese, with no indication that the user can select another language or that the locale restriction is intentional. Under the policy, hard-coded language constraints without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.