Back to skill

Security audit

IPv6地址查询 - 即刻数据

Security checks for vulnerabilities and agentic risk

Overview

The skill does an IPv6 lookup as advertised, but it has an undocumented API-host override that can redirect the user's API key and queried IP to another server.

Review before installing. Use this only if you are comfortable sending IPv6 addresses and a JikeAPI AppKey to the provider, and ensure JIKE_API_BASE_URL is unset or restricted to the legitimate HTTPS API host before running it.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/ip_query_v6.py:21
Finding

API Key Exfiltration Through an Unrestricted API Base URL Override

Content
View full analysis

Vulnerability Details

File Location: scripts/ip_query_v6.py:21, 108-110
Vulnerability Type: Unrestricted destination control for credential-bearing requests
Risk Level: Medium

Vulnerable Code

python
API_BASE_URL = os.environ.get("JIKE_API_BASE_URL", "https://api.jikeapi.cn").rstrip("/")
python
url = f"{API_BASE_URL}{API_PATH}?{urllib.parse.urlencode({'ip': ip_value, 'appkey': appkey})}"
try:
    with urllib.request.urlopen(url, timeout=15) as response:
        return json.loads(response.read().decode("utf-8"))

Technical Analysis

The undocumented JIKE_API_BASE_URL environment variable controls the complete request origin and scheme. The script does not require HTTPS and does not verify that the destination hostname is the intended api.jikeapi.cn service.

The application key is appended to the request URL as an appkey query parameter. Consequently, anyone capable of manipulating the process environment can redirect the request—and its credential—to an arbitrary HTTP or HTTPS endpoint. Query-string credentials may also be retained in web-server, reverse-proxy, monitoring, or network-device logs.

Exploitation requires control over the environment in which the skill is launched, such as a compromised wrapper, launcher configuration, deployment manifest, shell profile, or parent process.

Attack Path

  1. An attacker gains the ability to modify the skill's launch environment or configuration.
  2. The attacker sets JIKE_API_BASE_URL to an endpoint under their control, for example http://attacker.example.
  3. A user invokes the documented IPv6 lookup command.
  4. The script loads the user's API key from --key, JIKE_IP_QUERY_V6_KEY, JIKE_APPKEY, or the local .env file.
  5. The script constructs a request to the attacker-controlled origin with the IPv6 address and API key in the query string.
  6. The attacker's server receives and records the API key.
  7. The attacker can reuse the stolen key against the legiti ...[truncated 618 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the JIKE_API_BASE_URL override if alternate endpoints are not a required feature.
  2. If configurability is necessary, parse the configured URL and enforce:
    • The https scheme.
    • An explicit hostname allowlist, preferably only api.jikeapi.cn.
    • An approved port, path prefix, and absence of embedded user information.
  3. Construct the endpoint from a fixed trusted origin rather than concatenating an unrestricted string.
  4. Send the API key in a supported authorization header instead of the query string. If the upstream API only accepts a query parameter, ensure URLs are redacted from application, proxy, and server logs.
  5. Document any supported endpoint override and treat control over it as security-sensitive.
  6. Add tests confirming that HTTP URLs, unapproved hosts, embedded credentials, and malformed destinations are rejected before any request containing the key is sent.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Tainted flow: 'url' from os.environ.get (line 117, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
96% confidence
Finding

The request URL is built from API_BASE_URL, which is sourced from the JIKE_API_BASE_URL environment variable and then sent to urllib.request.urlopen without any allowlisting or validation. In an agent/runtime context, this creates a server-side request forgery style sink: if an attacker can influence environment configuration, they can redirect requests containing the queried IP and appkey to an arbitrary host and exfiltrate credentials or interact with internal services.

Content

Scanner excerpt · scripts/ip_query_v6.py (reported line 119)May include surrounding context.

python
"""
    url = f"{API_BASE_URL}{API_PATH}?{urllib.parse.urlencode({'ip': ip_value, 'appkey': appkey})}"
    try:
        with urllib.request.urlopen(url, timeout=15) as response:
            return json.loads(response.read().decode("utf-8"))
    except urllib.error.HTTPError as exc:
        return {"code": exc.code, "message": f"接口请求失败: HTTP {exc.code}", "data": ""}

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/ip_query_v6.py (reported line 50)May include surrounding context.

python
if env_value:
            return env_value

    env_file = Path(__file__).parent / ".env"
    if not env_file.exists():
        return ""

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill invokes Python, reads environment variables for API keys, and makes outbound network requests, but it does not declare an explicit tool scope such as permissions or allowed-tools. This weakens sandboxing and reviewability because a host agent may grant broader capabilities than users expect, increasing the chance of unintended data access or network use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill sends user-supplied IPv6 addresses to a third-party provider, but the description does not clearly warn users that their input will be transmitted off-platform. IP addresses can be personal or sensitive metadata in some contexts, so lack of disclosure undermines informed consent and may create privacy or compliance issues.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The skill is designed to transmit user input to an external API endpoint, which is expected for its functionality, but it still constitutes an external data transfer risk. In this context the danger is reduced because the endpoint and purpose are openly documented, yet sending IP data and an app key to a third party can expose sensitive metadata if users query private, internal, or regulated addresses.

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

直接调用 API:

text
GET https://api.jikeapi.cn/v1/ip/query/v6?ip=240e:1f:1::1&appkey=YOUR_APPKEY

AI 使用步骤

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · _meta.json (reported line 8)May include surrounding context.

json
"title": "IPv6地址查询 - 即刻数据",
  "description": "输入 IPv6 地址,实时查询国家、省份、城市、地区、运营商和 long_ip 数值。",
  "env": "JIKE_IP_QUERY_V6_KEY",
  "api_url": "https://api.jikeapi.cn/v1/ip/query/v6",
  "homepage": "https://www.jikeapi.cn/"
}

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and all user-facing CLI text are written only in Chinese, which imposes a specific language on users without any opt-in or alternative locale. Under the policy, language constraints should either be optional for the user or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language instructions and description force a single language context for users, and the file does not provide an opt-in, alternative language, or justification for a Chinese-only constraint. Under the stated policy, language restrictions should either be optional or clearly documented as necessary.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.