Back to skill

Security audit

经纬度位置查询 - 即刻数据

Security checks for vulnerabilities and agentic risk

Overview

This reverse-geocoding skill has a coherent purpose, but it needs review because an undocumented endpoint override can send exact coordinates and the API key to an arbitrary server.

Install only if you trust the runtime environment and the Jike API account being used. Before running it, ensure JIKE_API_BASE_URL is unset or locked to the intended HTTPS Jike endpoint, use a narrow and rotatable AppKey, and avoid submitting coordinates for sensitive places unless that third-party disclosure is acceptable.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/map_geocode_query.py:22
Finding

Undocumented API Endpoint Override Enables AppKey and Location Disclosure

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/map_geocode_query.py:119
Finding

AppKey Is Transmitted in the Request URL Query String

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Tainted flow: 'url' from os.environ.get (line 125, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The request URL is built from an environment-controlled base URL and then fetched with urlopen, which allows the execution environment to redirect requests to an arbitrary host. Because the query string includes both precise latitude/longitude and the AppKey, a modified JIKE_API_BASE_URL can exfiltrate secrets and sensitive location data to an attacker-controlled endpoint, making this a real SSRF/data-exfiltration risk in hostile or multi-tenant environments.

Content

Scanner excerpt · scripts/map_geocode_query.py (reported line 127)May include surrounding context.

python
params = {"lng": lng, "lat": lat, "coordinate_system": coordinate_system, "appkey": appkey}
    url = f"{API_BASE_URL}{API_PATH}?{urllib.parse.urlencode(params)}"
    try:
        with urllib.request.urlopen(url, timeout=15) as response:
            return json.loads(response.read().decode("utf-8"))
    except urllib.error.HTTPError as exc:
        return {"code": exc.code, "message": f"接口请求失败: HTTP {exc.code}", "data": ""}

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/map_geocode_query.py (reported line 51)May include surrounding context.

python
if env_value:
            return env_value

    env_file = Path(__file__).parent / ".env"
    if not env_file.exists():
        return ""

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill performs sensitive capabilities including reading environment variables for an API key and making outbound network requests, but it does not declare an explicit tool scope such as permissions or allowed-tools. This weakens security boundaries because hosts or reviewers cannot clearly enforce or audit what the skill is allowed to access, increasing the chance of over-broad execution in capable runtimes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill sends user-supplied coordinates to a third-party API, but the description does not clearly warn users that precise location data leaves the local environment. Coordinates can be highly sensitive personal data, so silent transmission creates a privacy risk and can violate user expectations or policy requirements.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
83% confidence
Finding

This skill explicitly transmits location coordinates and an API key to an external service endpoint. Although external API use is central to the skill's purpose, the transmission still carries privacy and data-handling risk because precise geolocation may reveal sensitive places such as homes, workplaces, or live whereabouts.

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

直接调用 API:

text
GET https://api.jikeapi.cn/v1/map/geocode/query?lng=114.30394&lat=34.79646&coordinate_system=gps&appkey=YOUR_APPKEY

AI 使用步骤

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · _meta.json (reported line 8)May include surrounding context.

json
"title": "经纬度位置查询 - 即刻数据",
  "description": "输入经度、纬度和坐标系,查询完整地址、国家、省、市、区、乡镇和街道。",
  "env": "JIKE_MAP_GEOCODE_QUERY_KEY",
  "api_url": "https://api.jikeapi.cn/v1/map/geocode/query",
  "homepage": "https://www.jikeapi.cn/"
}

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This skill transmits exact user coordinates together with the API credential to a third-party service immediately at runtime, but provides no execution-time notice, consent step, or privacy warning. In a location lookup skill, sending coordinates is expected for functionality, but precise location is sensitive personal data, so the lack of explicit disclosure and minimization creates a genuine privacy risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The title and description force a specific language/locale in the skill's natural-language metadata. Under the policy, locale-specific language is a violation unless the skill offers a language choice or clearly documents a justified regional constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script’s natural-language interface, help text, and output messages are all written in Chinese, which forces a specific language on users without any opt-in or documented region-specific justification. This matches the language/locale policy concern for natural-language behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.