Back to skill

Security audit

IPv4地址查询 - 即刻数据

Security checks for vulnerabilities and agentic risk

Overview

The skill does the advertised IPv4 lookup, but it has an undocumented endpoint override that could send the API key and queried IP to a different server if the environment is altered.

Review before installing. Use it only if you are comfortable sending queried IPv4 addresses and your Jike AppKey to the provider, and run it in an environment where JIKE_API_BASE_URL cannot be set by untrusted parties. Prefer configuring the AppKey through a protected environment variable rather than command-line arguments or a checked-in .env file.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/ip_query_v4.py:25
Finding

Unvalidated API Endpoint Override Can Disclose the AppKey

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (9)

Tainted flow: 'url' from os.environ.get (line 123, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/ip_query_v4.py (reported line 126)May include surrounding context.

python
url = f"{API_BASE_URL}{API_PATH}?{params}"

    try:
        with urllib.request.urlopen(url, timeout=15) as response:
            return json.loads(response.read().decode("utf-8"))
    except urllib.error.HTTPError as exc:
        return {"code": exc.code, "message": f"接口请求失败: HTTP {exc.code}", "data": ""}

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

本地测试可在脚本目录创建 .env:

bash
echo "JIKE_IP_QUERY_V4_KEY=你的AppKey" > scripts/.env

不要把真实 AppKey 写进公开仓库或上传到 Skill 包中。

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/ip_query_v4.py (reported line 55)May include surrounding context.

python
if env_value:
            return env_value

    env_file = Path(__file__).parent / ".env"
    if not env_file.exists():
        return ""

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill requires environment access, file reads, and outbound network access, but it does not declare any explicit tool scope or permissions boundary. This creates a capability mismatch where an agent may invoke the skill without clear policy constraints, increasing the chance of over-broad execution and unintended data access or transmission.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The trigger phrasing uses broad natural-language examples like asking where an IP is from, without clear invocation boundaries or user-consent cues. In agent environments, this can cause the skill to auto-trigger in ordinary conversation and send queried IP addresses to the external provider without the user realizing a third-party lookup is occurring.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description explains the functionality but does not clearly warn that submitted IP addresses are transmitted to jikeapi.cn for processing. Even though IP addresses are the subject of the query, they can still be sensitive operational or user data, so failing to disclose third-party transmission weakens informed consent and privacy expectations.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 79)May include surrounding context.

md
"title": "IPv4地址查询 - 即刻数据",
  "description": "输入 IPv4 地址,实时查询国家、省份、城市、运营商和 long_ip 数值。",
  "env": "JIKE_IP_QUERY_V4_KEY",
  "api_url": "https://api.jikeapi.cn/v1/ip/query/v4",
  "homepage": "https://www.jikeapi.cn/"
}

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · _meta.json (reported line 8)May include surrounding context.

json
"title": "IPv4地址查询 - 即刻数据",
  "description": "输入 IPv4 地址,实时查询国家、省份、城市、运营商和 long_ip 数值。",
  "env": "JIKE_IP_QUERY_V4_KEY",
  "api_url": "https://api.jikeapi.cn/v1/ip/query/v4",
  "homepage": "https://www.jikeapi.cn/"
}

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This code sends the queried IPv4 address and the AppKey to an external API using an HTTP request. Although the module docstring says it calls the API, there is no runtime confirmation or explicit user-facing warning that executing the script transmits potentially sensitive query data and credentials off-host.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.