T09 · Insecure Skill Coding Practices
- Location
scripts/ip_query_v4.py:25- Finding
Unvalidated API Endpoint Override Can Disclose the AppKey
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill does the advertised IPv4 lookup, but it has an undocumented endpoint override that could send the API key and queried IP to a different server if the environment is altered.
Review before installing. Use it only if you are comfortable sending queried IPv4 addresses and your Jike AppKey to the provider, and run it in an environment where JIKE_API_BASE_URL cannot be set by untrusted parties. Prefer configuring the AppKey through a protected environment variable rather than command-line arguments or a checked-in .env file.
scripts/ip_query_v4.py:25Unvalidated API Endpoint Override Can Disclose the AppKey
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
url = f"{API_BASE_URL}{API_PATH}?{params}"
try:
with urllib.request.urlopen(url, timeout=15) as response:
return json.loads(response.read().decode("utf-8"))
except urllib.error.HTTPError as exc:
return {"code": exc.code, "message": f"接口请求失败: HTTP {exc.code}", "data": ""}
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
本地测试可在脚本目录创建 .env:
echo "JIKE_IP_QUERY_V4_KEY=你的AppKey" > scripts/.env
不要把真实 AppKey 写进公开仓库或上传到 Skill 包中。
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
if env_value:
return env_value
env_file = Path(__file__).parent / ".env"
if not env_file.exists():
return ""
The skill requires environment access, file reads, and outbound network access, but it does not declare any explicit tool scope or permissions boundary. This creates a capability mismatch where an agent may invoke the skill without clear policy constraints, increasing the chance of over-broad execution and unintended data access or transmission.
The trigger phrasing uses broad natural-language examples like asking where an IP is from, without clear invocation boundaries or user-consent cues. In agent environments, this can cause the skill to auto-trigger in ordinary conversation and send queried IP addresses to the external provider without the user realizing a third-party lookup is occurring.
The description explains the functionality but does not clearly warn that submitted IP addresses are transmitted to jikeapi.cn for processing. Even though IP addresses are the subject of the query, they can still be sensitive operational or user data, so failing to disclose third-party transmission weakens informed consent and privacy expectations.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"title": "IPv4地址查询 - 即刻数据",
"description": "输入 IPv4 地址,实时查询国家、省份、城市、运营商和 long_ip 数值。",
"env": "JIKE_IP_QUERY_V4_KEY",
"api_url": "https://api.jikeapi.cn/v1/ip/query/v4",
"homepage": "https://www.jikeapi.cn/"
}
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"title": "IPv4地址查询 - 即刻数据",
"description": "输入 IPv4 地址,实时查询国家、省份、城市、运营商和 long_ip 数值。",
"env": "JIKE_IP_QUERY_V4_KEY",
"api_url": "https://api.jikeapi.cn/v1/ip/query/v4",
"homepage": "https://www.jikeapi.cn/"
}
This code sends the queried IPv4 address and the AppKey to an external API using an HTTP request. Although the module docstring says it calls the API, there is no runtime confirmation or explicit user-facing warning that executing the script transmits potentially sensitive query data and credentials off-host.
No suspicious patterns detected.