Back to skill

Security audit

菜谱查询 - 即刻数据

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent cookbook-query skill, but it includes an undocumented endpoint override that could send the configured API key to an arbitrary server.

Review before installing. Use it only if you are comfortable sending cookbook search terms, recipe IDs, and a Jike AppKey to the provider. Do not set JIKE_API_BASE_URL unless you fully control and validate the destination; a safer version would remove that override or restrict it to https://api.jikeapi.cn.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/cookbook_query.py:23
Finding

Environment-Controlled API Endpoint Can Disclose the AppKey

Content
View full analysis

Vulnerability Details

File Location: scripts/cookbook_query.py, lines 23 and 194–196
Vulnerability Type: Unvalidated destination for sensitive API credentials
Risk Level: Medium

Vulnerable Code

python
API_BASE_URL = os.environ.get(
    "JIKE_API_BASE_URL",
    "https://api.jikeapi.cn"
).rstrip("/")
python
url = f"{API_BASE_URL}{API_PATH_MAP[command]}?{urllib.parse.urlencode({**params, 'appkey': appkey})}"
try:
    with urllib.request.urlopen(url, timeout=15) as response:
        return json.loads(response.read().decode("utf-8"))

Technical Analysis

The destination used for API requests can be overridden through the undocumented JIKE_API_BASE_URL environment variable. The value is accepted without validating its scheme or hostname.

Every request appends the AppKey to the URL query string. Consequently, a process or deployment configuration capable of influencing JIKE_API_BASE_URL can redirect the request—and the credential—to an arbitrary server. The implementation also does not require HTTPS, so an override using an http:// URL can transmit the credential without transport encryption.

The attacker-controlled server can return syntactically valid JSON that the script will process and present as cookbook data. This creates both a credential-confidentiality risk and a response-integrity risk.

Attack Path

  1. An attacker or compromised deployment component modifies the process environment and sets JIKE_API_BASE_URL to an attacker-controlled endpoint, such as https://attacker.example.
  2. A legitimate AppKey remains configured through JIKE_COOKBOOK_QUERY_KEY, JIKE_APPKEY, the --key option, or the local .env file.
  3. A user or agent invokes any supported command, such as search, detail, ingredient, or random.
  4. The script constructs a URL against the attacker-controlled base URL and adds the AppKey as the appkey query parameter.
  5. `urllib. ...[truncated 839 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the JIKE_API_BASE_URL override from production builds if custom endpoints are not an explicit requirement.
  2. If endpoint customization is required, parse the configured URL and enforce:
    • The https scheme.
    • An exact allowlist of approved hostnames, preferably only api.jikeapi.cn.
    • No embedded username or password.
    • No unexpected port, fragment, or path components.
  3. Construct requests from a fixed trusted origin rather than concatenating an unrestricted environment value.
  4. Prefer transmitting the AppKey in a supported authorization header instead of the query string. This reduces exposure through URL logs, monitoring systems, and error reports.
  5. Reject invalid endpoint configuration before loading or transmitting the AppKey.
  6. Add automated tests confirming that HTTP URLs, unapproved domains, deceptive subdomains, and URLs containing user information are rejected.
  7. Document any intentionally supported endpoint override and its security constraints in SKILL.md.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (7)

Tainted flow: 'url' from os.environ.get (line 240, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
97% confidence
Finding

The request target is derived from JIKE_API_BASE_URL, an environment variable, and then passed directly into urllib.request.urlopen while also appending the secret appkey as a query parameter. If an attacker can influence the environment, they can redirect requests to an arbitrary host and exfiltrate the AppKey or force the skill to make unexpected outbound requests (SSRF-style behavior).

Content

Scanner excerpt · scripts/cookbook_query.py (reported line 242)May include surrounding context.

python
"""
    url = f"{API_BASE_URL}{API_PATH_MAP[command]}?{urllib.parse.urlencode({**params, 'appkey': appkey})}"
    try:
        with urllib.request.urlopen(url, timeout=15) as response:
            return json.loads(response.read().decode("utf-8"))
    except urllib.error.HTTPError as exc:
        return {"code": exc.code, "message": f"接口请求失败: HTTP {exc.code}", "data": ""}

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/cookbook_query.py (reported line 53)May include surrounding context.

python
env_value = os.environ.get(env_name, "").strip()
        if env_value:
            return env_value
    env_file = Path(__file__).parent / ".env"
    if not env_file.exists():
        return ""
    for line in env_file.read_text(encoding="utf-8").splitlines():

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill invokes a Python script that reads environment variables and makes outbound network requests, but the manifest does not declare any explicit tool scope such as permissions or allowed-tools. This weakens least-privilege controls and makes the skill harder to govern or sandbox, increasing risk if the script is modified or misused.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

L03 的适用场景包含“随机推荐几个菜”这类通用日常表述,缺少更明确的技能边界或排除条件。该短语可能与一般闲聊式推荐请求重叠,增加在非菜谱查询语境下被误调用的风险。

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · _meta.json (reported line 8)May include surrounding context.

json
"title": "菜谱查询 - 即刻数据",
  "description": "支持食材列表查询、菜谱搜索、菜谱详情和随机菜谱,返回菜名、分类、耗时、口味、主料辅料和做法步骤。",
  "env": "JIKE_COOKBOOK_QUERY_KEY",
  "api_url": "https://api.jikeapi.cn/v1/cookbook/search",
  "homepage": "https://www.jikeapi.cn/"
}

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module docstring and subsequent CLI help/output strings indicate the skill is designed to operate entirely in Chinese. This imposes a specific language on users without any documented opt-in or alternative locale, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

L03 及全文均以中文描述技能用途和交互示例,没有说明是否仅面向中文用户,也未提供语言/locale 选择。按规则,若技能隐含强制特定语言而无用户选择或合理限定,属于自然语言策略问题。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.