Back to skill

Security audit

成语词典 - 即刻数据

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Chinese idiom lookup skill, but it has an under-documented endpoint override that can send the API key to an arbitrary URL.

Review before installing. Use this only with a Jike API key you are comfortable using from this tool, avoid passing the key on the command line, do not set JIKE_API_BASE_URL unless you fully trust the destination, and rotate the key if it may have been sent to an untrusted endpoint or logged.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/idiom_query.py:23
Finding

API Credential Exposure Through Query Strings and an Unrestricted Endpoint Override

Content
View full analysis

Vulnerability Details

File Location: scripts/idiom_query.py:23 and scripts/idiom_query.py:238
Vulnerability Type: API credential exposure and unrestricted destination configuration
Risk Level: Medium

Vulnerable Code

python
API_BASE_URL = os.environ.get("JIKE_API_BASE_URL", "https://api.jikeapi.cn").rstrip("/")
python
url = f"{API_BASE_URL}{API_PATH_MAP[command]}?{urllib.parse.urlencode({**params, 'appkey': appkey})}"

Technical Analysis

The script appends the AppKey directly to the request URL as an appkey query parameter. URLs are commonly recorded by destination servers, reverse proxies, monitoring systems, network diagnostics, and application logs. Consequently, the credential may be retained in more locations than necessary and become accessible to operators or systems that can inspect those records.

The destination is also controlled by the undocumented JIKE_API_BASE_URL environment variable without scheme or hostname validation. The code accepts arbitrary hosts and non-TLS schemes. An attacker who can influence the process environment or a compromised launcher can redirect requests to an attacker-controlled endpoint. Because the AppKey and user-provided idiom query are included in the URL, the destination receives both values.

This does not grant local privilege escalation by itself, and exploitation of the endpoint override requires influence over the execution environment. Nevertheless, the combination creates a direct credential-exfiltration path.

Attack Path

  1. An attacker compromises or controls the wrapper, launcher, CI job, shell profile, or other configuration that starts the Skill.
  2. The attacker sets JIKE_API_BASE_URL to an endpoint under their control, potentially using unencrypted HTTP.
  3. A user invokes a documented command while a valid AppKey is supplied through the CLI, environment, or local .env file.
  4. request_api() constructs a URL cont ...[truncated 881 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the JIKE_API_BASE_URL override if custom endpoints are not a required feature.
  2. If endpoint customization is required, parse the URL and enforce:
    • The https scheme.
    • An explicit allowlist of trusted hostnames.
    • Expected ports and path constraints.
    • Rejection of embedded credentials, fragments, loopback addresses, link-local addresses, and untrusted redirects.
  3. Prefer sending the AppKey in an API-supported authentication header rather than in the query string.
  4. If the upstream API only accepts a query parameter, ensure clients, proxies, servers, and monitoring systems redact appkey from logs.
  5. Disable or strictly validate redirects so a trusted endpoint cannot redirect authenticated requests to an untrusted host.
  6. Document every supported environment variable and its security implications.
  7. Rotate any key suspected of appearing in logs or having been sent to an untrusted endpoint.
  8. Add automated tests confirming that non-HTTPS and non-allowlisted API base URLs are rejected before any network request occurs.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Tainted flow: 'url' from os.environ.get (line 241, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/idiom_query.py (reported line 243)May include surrounding context.

python
"""
    url = f"{API_BASE_URL}{API_PATH_MAP[command]}?{urllib.parse.urlencode({**params, 'appkey': appkey})}"
    try:
        with urllib.request.urlopen(url, timeout=15) as response:
            return json.loads(response.read().decode("utf-8"))
    except urllib.error.HTTPError as exc:
        return {"code": exc.code, "message": f"接口请求失败: HTTP {exc.code}", "data": ""}

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/idiom_query.py (reported line 53)May include surrounding context.

python
env_value = os.environ.get(env_name, "").strip()
        if env_value:
            return env_value
    env_file = Path(__file__).parent / ".env"
    if not env_file.exists():
        return ""
    for line in env_file.read_text(encoding="utf-8").splitlines():

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill invokes a Python script, reads environment variables for API keys, and makes network requests, but the manifest does not declare any explicit tool scope such as allowed tools or permissions. This creates an authorization gap where an agent may execute broader capabilities than reviewers or runtime policy expect, increasing the risk of unintended file, env, or network access.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · _meta.json (reported line 8)May include surrounding context.

json
"title": "成语词典 - 即刻数据",
  "description": "支持搜索成语、成语详情、随机成语和成语接龙,返回拼音、解释、出处、用法、近义词和反义词。",
  "env": "JIKE_IDIOM_QUERY_KEY",
  "api_url": "https://api.jikeapi.cn/v1/idiom/query",
  "homepage": "https://www.jikeapi.cn/"
}

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language documentation and CLI help text that assume Chinese-language use exclusively. Under the policy, forcing a specific language without user opt-in is a locale/language policy violation unless the restriction is explicitly documented and justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The natural-language instructions and examples are exclusively in Chinese, which may effectively force a specific language/locale for users and agents without documenting a choice. The policy allows locale constraints when users are given an opt-in or when the constraint is clearly justified, but neither is stated here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.