Back to skill

Security audit

中文对联查询 - 即刻数据

Security checks for vulnerabilities and agentic risk

Overview

This couplet lookup skill mostly does what it says, but it needs review because it can send the API key to an environment-selected server that the docs do not disclose.

Install only if you are comfortable giving this skill a Jike API key and sending couplet keywords to Jike's API. Review or remove the JIKE_API_BASE_URL override before use, and avoid setting that variable unless you fully trust the destination.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/couplet_query.py:144
Finding

Environment-Controlled API Endpoint Can Expose the AppKey

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Tainted flow: 'url' from os.environ.get (line 149, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
93% confidence
Finding

The request URL is partly derived from the JIKE_API_BASE_URL environment variable, which is untrusted input. In an agent or hosted runtime, an attacker who can influence environment configuration could redirect requests, exfiltrate the AppKey in the query string, or cause SSRF to internal services. The skill context increases risk because it automatically performs outbound HTTP requests and includes credentials in every request.

Content

Scanner excerpt · scripts/couplet_query.py (reported line 151)May include surrounding context.

python
"""
    url = f"{API_BASE_URL}{API_PATH_MAP[command]}?{urllib.parse.urlencode({**params, 'appkey': appkey})}"
    try:
        with urllib.request.urlopen(url, timeout=15) as response:
            return json.loads(response.read().decode("utf-8"))
    except urllib.error.HTTPError as exc:
        return {"code": exc.code, "message": f"接口请求失败: HTTP {exc.code}", "data": ""}

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/couplet_query.py (reported line 52)May include surrounding context.

python
env_value = os.environ.get(env_name, "").strip()
        if env_value:
            return env_value
    env_file = Path(__file__).parent / ".env"
    if not env_file.exists():
        return ""
    for line in env_file.read_text(encoding="utf-8").splitlines():

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill invokes a Python script, reads environment variables for API keys, and performs network access, but it does not declare any explicit tool scope such as permissions or allowed-tools. This creates a trust gap where the runtime capabilities are broader than what is transparently documented or constrained, increasing the risk of unintended data access or outbound requests if the script is modified or misused.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · _meta.json (reported line 8)May include surrounding context.

json
"title": "中文对联查询 - 即刻数据",
  "description": "中文对联查询。支持按上联或下联关键词搜索,也支持随机返回对联。",
  "env": "JIKE_COUPLET_QUERY_KEY",
  "api_url": "https://api.jikeapi.cn/v1/couplet/query",
  "homepage": "https://www.jikeapi.cn/"
}

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

该文件的模块说明、参数帮助和输出标题均以中文固定呈现,未见任何语言切换、用户选择或地域合规说明。按照语言/locale 策略,强制单一语言而无用户 opt-in 属于自然语言层面的政策问题。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

argparse 描述、--key/--json 帮助文本以及后续错误信息都固定为中文,意味着非中文用户在未选择的情况下被强制使用特定语言。该问题属于自然语言策略范畴,而非代码安全漏洞。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.