Back to skill

Security audit

人民币汇率查询 - 即刻数据

Security checks for vulnerabilities and agentic risk

Overview

This exchange-rate skill largely does what it claims, but it needs review because an undocumented setting can redirect API-key-bearing requests away from the stated provider.

Review before installing. Use it only if you are comfortable sending currencies, amounts, and a Jike AppKey to the provider. Prefer setting JIKE_CNY_EXCHANGE_RATE_KEY in a protected environment, avoid the --key argument, and do not set JIKE_API_BASE_URL unless you fully trust and intend the alternate endpoint.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/cny_exchange_rate.py:31
Finding

AppKey Exfiltration Through an Unrestricted API Base URL Override

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/cny_exchange_rate.py:213
Finding

AppKey Exposure Through Command-Line Arguments and URL Query Parameters

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (9)

Tainted flow: 'url' from os.environ.get (line 214, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The request URL is partially derived from the JIKE_API_BASE_URL environment variable and then passed directly to urllib.request.urlopen. In an agent or hosted execution environment, environment variables can be influenced by deployment configuration, enabling SSRF-style behavior, unexpected outbound requests, or silent exfiltration of the AppKey to an attacker-controlled endpoint.

Content

Scanner excerpt · scripts/cny_exchange_rate.py (reported line 217)May include surrounding context.

python
url = f"{API_BASE_URL}{API_PATH_MAP[command]}?{urllib.parse.urlencode(request_params)}"

    try:
        with urllib.request.urlopen(url, timeout=15) as response:
            return json.loads(response.read().decode("utf-8"))
    except urllib.error.HTTPError as exc:
        return {"code": exc.code, "message": f"接口请求失败: HTTP {exc.code}", "data": ""}

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/cny_exchange_rate.py (reported line 60)May include surrounding context.

python
if env_value:
            return env_value

    env_file = Path(__file__).parent / ".env"
    if not env_file.exists():
        return ""

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill declares capabilities that imply environment-variable access, file reads, and network use, but it does not declare an explicit tool/permission scope. That weakens least-privilege controls and transparency for reviewers and users, making it easier for the skill to access sensitive runtime data or perform network actions without clear policy boundaries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says the service is provided by a third party, but it does not clearly warn users that their query parameters will be transmitted to an external API. This reduces informed consent and may expose user financial interests or entered amounts/currencies to an outside service unexpectedly.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The activation guidance is broad enough that the skill may trigger for general finance or currency-related prompts without clear constraints. Over-broad triggering can cause unnecessary external API calls and disclosure of user-provided query data to a third party when a local or safer response would have sufficed.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

md
"title": "人民币汇率查询 - 即刻数据",
  "description": "支持外汇牌价币种列表、人民币外汇牌价查询和汇率转换。",
  "env": "JIKE_CNY_EXCHANGE_RATE_KEY",
  "api_url": "https://api.jikeapi.cn/v1/cny_exchange_rate/query",
  "homepage": "https://www.jikeapi.cn/"
}

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

md
"title": "人民币汇率查询 - 即刻数据",
  "description": "支持外汇牌价币种列表、人民币外汇牌价查询和汇率转换。",
  "env": "JIKE_CNY_EXCHANGE_RATE_KEY",
  "api_url": "https://api.jikeapi.cn/v1/cny_exchange_rate/query",
  "homepage": "https://www.jikeapi.cn/"
}

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
"title": "人民币汇率查询 - 即刻数据",
  "description": "支持外汇牌价币种列表、人民币外汇牌价查询和汇率转换。",
  "env": "JIKE_CNY_EXCHANGE_RATE_KEY",
  "api_url": "https://api.jikeapi.cn/v1/cny_exchange_rate/query",
  "homepage": "https://www.jikeapi.cn/"
}

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · _meta.json (reported line 8)May include surrounding context.

json
"title": "人民币汇率查询 - 即刻数据",
  "description": "支持外汇牌价币种列表、人民币外汇牌价查询和汇率转换。",
  "env": "JIKE_CNY_EXCHANGE_RATE_KEY",
  "api_url": "https://api.jikeapi.cn/v1/cny_exchange_rate/query",
  "homepage": "https://www.jikeapi.cn/"
}

Static analysis

No suspicious patterns detected.