T09 · Insecure Skill Coding Practices
- Location
scripts/map_geocode_query.py:22- Finding
Undocumented API Endpoint Override Enables AppKey and Location Disclosure
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This reverse-geocoding skill has a coherent purpose, but it needs review because an undocumented endpoint override can send exact coordinates and the API key to an arbitrary server.
Install only if you trust the runtime environment and the Jike API account being used. Before running it, ensure JIKE_API_BASE_URL is unset or locked to the intended HTTPS Jike endpoint, use a narrow and rotatable AppKey, and avoid submitting coordinates for sensitive places unless that third-party disclosure is acceptable.
scripts/map_geocode_query.py:22Undocumented API Endpoint Override Enables AppKey and Location Disclosure
scripts/map_geocode_query.py:119AppKey Is Transmitted in the Request URL Query String
The request URL is built from an environment-controlled base URL and then fetched with urlopen, which allows the execution environment to redirect requests to an arbitrary host. Because the query string includes both precise latitude/longitude and the AppKey, a modified JIKE_API_BASE_URL can exfiltrate secrets and sensitive location data to an attacker-controlled endpoint, making this a real SSRF/data-exfiltration risk in hostile or multi-tenant environments.
params = {"lng": lng, "lat": lat, "coordinate_system": coordinate_system, "appkey": appkey}
url = f"{API_BASE_URL}{API_PATH}?{urllib.parse.urlencode(params)}"
try:
with urllib.request.urlopen(url, timeout=15) as response:
return json.loads(response.read().decode("utf-8"))
except urllib.error.HTTPError as exc:
return {"code": exc.code, "message": f"接口请求失败: HTTP {exc.code}", "data": ""}
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
if env_value:
return env_value
env_file = Path(__file__).parent / ".env"
if not env_file.exists():
return ""
The skill performs sensitive capabilities including reading environment variables for an API key and making outbound network requests, but it does not declare an explicit tool scope such as permissions or allowed-tools. This weakens security boundaries because hosts or reviewers cannot clearly enforce or audit what the skill is allowed to access, increasing the chance of over-broad execution in capable runtimes.
The skill sends user-supplied coordinates to a third-party API, but the description does not clearly warn users that precise location data leaves the local environment. Coordinates can be highly sensitive personal data, so silent transmission creates a privacy risk and can violate user expectations or policy requirements.
This skill explicitly transmits location coordinates and an API key to an external service endpoint. Although external API use is central to the skill's purpose, the transmission still carries privacy and data-handling risk because precise geolocation may reveal sensitive places such as homes, workplaces, or live whereabouts.
直接调用 API:
GET https://api.jikeapi.cn/v1/map/geocode/query?lng=114.30394&lat=34.79646&coordinate_system=gps&appkey=YOUR_APPKEY
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"title": "经纬度位置查询 - 即刻数据",
"description": "输入经度、纬度和坐标系,查询完整地址、国家、省、市、区、乡镇和街道。",
"env": "JIKE_MAP_GEOCODE_QUERY_KEY",
"api_url": "https://api.jikeapi.cn/v1/map/geocode/query",
"homepage": "https://www.jikeapi.cn/"
}
This skill transmits exact user coordinates together with the API credential to a third-party service immediately at runtime, but provides no execution-time notice, consent step, or privacy warning. In a location lookup skill, sending coordinates is expected for functionality, but precise location is sensitive personal data, so the lack of explicit disclosure and minimization creates a genuine privacy risk.
The title and description force a specific language/locale in the skill's natural-language metadata. Under the policy, locale-specific language is a violation unless the skill offers a language choice or clearly documents a justified regional constraint.
The script’s natural-language interface, help text, and output messages are all written in Chinese, which forces a specific language on users without any opt-in or documented region-specific justification. This matches the language/locale policy concern for natural-language behavior.
No suspicious patterns detected.