T09 · Insecure Skill Coding Practices
- Location
scripts/couplet_query.py:144- Finding
Environment-Controlled API Endpoint Can Expose the AppKey
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This couplet lookup skill mostly does what it says, but it needs review because it can send the API key to an environment-selected server that the docs do not disclose.
Install only if you are comfortable giving this skill a Jike API key and sending couplet keywords to Jike's API. Review or remove the JIKE_API_BASE_URL override before use, and avoid setting that variable unless you fully trust the destination.
scripts/couplet_query.py:144Environment-Controlled API Endpoint Can Expose the AppKey
The request URL is partly derived from the JIKE_API_BASE_URL environment variable, which is untrusted input. In an agent or hosted runtime, an attacker who can influence environment configuration could redirect requests, exfiltrate the AppKey in the query string, or cause SSRF to internal services. The skill context increases risk because it automatically performs outbound HTTP requests and includes credentials in every request.
"""
url = f"{API_BASE_URL}{API_PATH_MAP[command]}?{urllib.parse.urlencode({**params, 'appkey': appkey})}"
try:
with urllib.request.urlopen(url, timeout=15) as response:
return json.loads(response.read().decode("utf-8"))
except urllib.error.HTTPError as exc:
return {"code": exc.code, "message": f"接口请求失败: HTTP {exc.code}", "data": ""}
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
env_value = os.environ.get(env_name, "").strip()
if env_value:
return env_value
env_file = Path(__file__).parent / ".env"
if not env_file.exists():
return ""
for line in env_file.read_text(encoding="utf-8").splitlines():
The skill invokes a Python script, reads environment variables for API keys, and performs network access, but it does not declare any explicit tool scope such as permissions or allowed-tools. This creates a trust gap where the runtime capabilities are broader than what is transparently documented or constrained, increasing the risk of unintended data access or outbound requests if the script is modified or misused.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"title": "中文对联查询 - 即刻数据",
"description": "中文对联查询。支持按上联或下联关键词搜索,也支持随机返回对联。",
"env": "JIKE_COUPLET_QUERY_KEY",
"api_url": "https://api.jikeapi.cn/v1/couplet/query",
"homepage": "https://www.jikeapi.cn/"
}
该文件的模块说明、参数帮助和输出标题均以中文固定呈现,未见任何语言切换、用户选择或地域合规说明。按照语言/locale 策略,强制单一语言而无用户 opt-in 属于自然语言层面的政策问题。
argparse 描述、--key/--json 帮助文本以及后续错误信息都固定为中文,意味着非中文用户在未选择的情况下被强制使用特定语言。该问题属于自然语言策略范畴,而非代码安全漏洞。
No suspicious patterns detected.