Back to skill

Security audit

新华字典 - 即刻数据

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a disclosed Chinese dictionary API wrapper, but it has an undocumented endpoint override that could send the API key and queries to another host if the runtime environment is manipulated.

Review before installing. Use this only in an environment where JIKE_API_BASE_URL cannot be set by untrusted users or inherited from unsafe launch contexts, and treat the Jike AppKey as a secret because it is transmitted in request URLs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/character_query.py:25
Finding

Unvalidated API Endpoint Override Can Disclose the AppKey

Content
View full analysis

Vulnerability Details

File Location: scripts/character_query.py:25 and scripts/character_query.py:147
Vulnerability Type: Unvalidated destination override and credential disclosure
Risk Level: Medium

Vulnerable code:

python
API_BASE_URL = os.environ.get("JIKE_API_BASE_URL", "https://api.jikeapi.cn").rstrip("/")
python
url = f"{API_BASE_URL}{API_PATH_MAP[command]}?{urllib.parse.urlencode({**params, 'appkey': appkey})}"

Technical Analysis

The undocumented JIKE_API_BASE_URL environment variable completely controls the origin to which API requests are sent. The application does not validate the URL scheme, hostname, port, or resolved destination before appending the API path and transmitting the request.

The request URL includes the AppKey as a query parameter. Consequently, anyone able to influence the process environment can redirect a legitimate invocation to an attacker-controlled endpoint and receive both the AppKey and the submitted dictionary query. Allowing arbitrary destinations can also cause requests to be issued to internal network services or loopback addresses, creating a limited server-side request forgery condition in the runtime's network context.

Exploitation requires the attacker to control or poison the environment used to launch the skill. This finding does not establish that such control is available to an unauthenticated remote attacker.

Attack Path

  1. An attacker gains the ability to define environment variables for the process that runs the skill, such as through a compromised launcher, deployment configuration, wrapper script, or inherited shell environment.
  2. The attacker sets JIKE_API_BASE_URL to an endpoint under their control, for example https://attacker.example.
  3. A user invokes any documented dictionary query while a legitimate AppKey is configured.
  4. load_appkey() retrieves the legitimate credential from the command line, environme ...[truncated 1032 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the JIKE_API_BASE_URL override from production builds and use the fixed trusted endpoint https://api.jikeapi.cn.
  2. If endpoint customization is required for testing, require an explicit development-mode option and reject it in production.
  3. Parse customized URLs and enforce all of the following:
    • The scheme must be https.
    • The hostname must exactly match an approved allowlist.
    • User information and URL fragments must be absent.
    • Ports must be restricted to approved values.
    • Loopback, link-local, private, and otherwise sensitive network destinations must be rejected where arbitrary hosts are supported.
  4. Construct URLs with validated URL components rather than concatenating an untrusted base string.
  5. If supported by the service, transmit the AppKey in an authorization header instead of the query string to reduce exposure through URL logs, proxies, and monitoring systems.
  6. Document all supported configuration variables and ensure launchers sanitize inherited environment variables.
  7. Add tests confirming that HTTP URLs, unapproved hosts, loopback addresses, embedded credentials, and malformed endpoint values are rejected before any request is sent.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Tainted flow: 'url' from os.environ.get (line 154, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

The request URL is built from JIKE_API_BASE_URL, which is taken directly from an environment variable, and then fetched with urlopen. In an agent/runtime environment, an attacker who can influence that variable can redirect requests to an arbitrary host, causing the AppKey and user query parameters to be sent to an attacker-controlled endpoint; this is effectively SSRF plus credential exfiltration.

Content

Scanner excerpt · scripts/character_query.py (reported line 156)May include surrounding context.

python
"""
    url = f"{API_BASE_URL}{API_PATH_MAP[command]}?{urllib.parse.urlencode({**params, 'appkey': appkey})}"
    try:
        with urllib.request.urlopen(url, timeout=15) as response:
            return json.loads(response.read().decode("utf-8"))
    except urllib.error.HTTPError as exc:
        return {"code": exc.code, "message": f"接口请求失败: HTTP {exc.code}", "data": ""}

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/character_query.py (reported line 54)May include surrounding context.

python
env_value = os.environ.get(env_name, "").strip()
        if env_value:
            return env_value
    env_file = Path(__file__).parent / ".env"
    if not env_file.exists():
        return ""
    for line in env_file.read_text(encoding="utf-8").splitlines():

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill invokes a Python script that uses environment variables for API keys and makes external network requests, but the manifest does not declare any explicit tool scope such as allowed tools or permissions. This creates an authorization and transparency gap: a host agent may permit broader capabilities than users expect, making it harder to review or sandbox the skill's access to secrets, files, and network destinations.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · _meta.json (reported line 8)May include surrounding context.

json
"title": "新华字典 - 即刻数据",
  "description": "支持拼音列表、部首列表、按拼音查汉字、按部首查汉字、汉字详情查询。",
  "env": "JIKE_CHARACTER_QUERY_KEY",
  "api_url": "https://api.jikeapi.cn/v1/character/chinese/detail",
  "homepage": "https://www.jikeapi.cn/"
}

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script places both the AppKey and query data into the URL query string for a GET request. Query strings are commonly logged by proxies, servers, browser/debug tooling, and agent infrastructure, so secrets and potentially sensitive user input may be exposed beyond the intended recipient even when using HTTPS.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

All user-facing natural-language documentation and CLI descriptions in this file are presented exclusively in Chinese, with no option to select another language. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.