Back to skill

Security audit

手机号码归属地查询 - 即刻数据

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but an undocumented endpoint override can redirect phone numbers and the API key to an arbitrary server.

Install only if you are comfortable sending queried phone numbers and your Jike AppKey to the provider. Before use, ensure the runtime environment does not set JIKE_API_BASE_URL, or constrain outbound traffic to https://api.jikeapi.cn; avoid using real personal numbers without consent.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/mobile_lookup.py:30
Finding

User-Controlled API Endpoint Can Expose the AppKey and Queried Mobile Numbers

Content
View full analysis

Vulnerability Details

File Location: scripts/mobile_lookup.py, lines 30 and 203–207
Vulnerability Type: Unvalidated API endpoint override and transmission of sensitive data in URL query parameters
Risk Level: Medium

Vulnerable Code

python
API_BASE_URL = os.environ.get("JIKE_API_BASE_URL", "https://api.jikeapi.cn").rstrip("/")
python
params = urllib.parse.urlencode({"mobile": mobile, "appkey": appkey})
url = f"{API_BASE_URL}{API_PATH}?{params}"

try:
    with urllib.request.urlopen(url, timeout=15) as response:
        payload = json.loads(response.read().decode("utf-8"))

Technical Analysis

The undocumented JIKE_API_BASE_URL environment variable controls the complete API origin. The implementation does not require HTTPS, validate the hostname, or restrict the destination to an allowlist.

The request also includes both the private AppKey and the queried mobile number in URL query parameters. Consequently, these values are sent to whichever origin is selected by JIKE_API_BASE_URL. Query-string credentials may additionally be retained in server, proxy, monitoring, or diagnostic logs.

Exploitation requires an attacker to influence the script's environment or the configuration of the process that launches it. No evidence shows that arbitrary remote users can set this variable directly.

Attack Path

  1. An attacker gains influence over the environment inherited by the Skill process, such as through a compromised launcher, deployment configuration, wrapper script, or orchestration setting.
  2. The attacker sets JIKE_API_BASE_URL to an attacker-controlled endpoint, for example http://attacker.example.
  3. A user or Agent invokes the mobile lookup with a legitimate AppKey.
  4. The script constructs a request to the attacker-controlled origin using /v1/mobile/query.
  5. The script places the AppKey and mobile number in the query string and sends the request.
  6. The att ...[truncated 867 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the JIKE_API_BASE_URL override from production builds and use a fixed API endpoint:

    python
    API_BASE_URL = "https://api.jikeapi.cn"
    
  2. If endpoint configurability is required for testing, parse and strictly validate it:

    • Require the https scheme.
    • Allow only explicitly approved hostnames.
    • Reject embedded credentials, fragments, unexpected ports, and nonempty paths.
    • Keep test endpoint overrides behind an explicit development-only option.
  3. Do not place the AppKey in the URL when the API supports a safer credential transport. Prefer an authorization header or a protected POST body. If the upstream API mandates a query parameter, ensure URLs are never logged and redact the appkey value from exceptions, telemetry, proxy logs, and debugging output.

  4. Add automated tests verifying that HTTP endpoints, unapproved hosts, malformed URLs, and redirect attempts are rejected.

  5. Review redirect handling and either disable redirects or revalidate every redirect destination before forwarding sensitive values.

  6. Rotate the AppKey if there is reason to believe the Skill has run with an untrusted JIKE_API_BASE_URL.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Tainted flow: 'url' from os.environ.get (line 204, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
96% confidence
Finding

The request URL is built from JIKE_API_BASE_URL, which is sourced from an environment variable and used directly in urlopen. In this script, the URL also contains sensitive query parameters including the full mobile number and appkey, so an attacker who can influence the environment can redirect requests to an arbitrary host and exfiltrate both PII and credentials.

Content

Scanner excerpt · scripts/mobile_lookup.py (reported line 207)May include surrounding context.

python
url = f"{API_BASE_URL}{API_PATH}?{params}"

    try:
        with urllib.request.urlopen(url, timeout=15) as response:
            payload = json.loads(response.read().decode("utf-8"))
    except urllib.error.HTTPError as exc:
        return {"success": False, "mobile": mobile, "error": f"接口请求失败: HTTP {exc.code}"}

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

md
功能说明:
1. 从命令行参数中读取一个或多个 11 位中国大陆手机号。
2. 按命令行参数、环境变量、脚本目录 .env 的优先级读取 AppKey。
3. 调用即刻数据开放接口 /v1/mobile/query 查询归属地。
4. 将结果格式化为适合 AI 客户端展示的文本或 JSON。

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

md
功能说明:
1. 从命令行参数中读取一个或多个 11 位中国大陆手机号。
2. 按命令行参数、环境变量、脚本目录 .env 的优先级读取 AppKey。
3. 调用即刻数据开放接口 /v1/mobile/query 查询归属地。
4. 将结果格式化为适合 AI 客户端展示的文本或 JSON。

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/mobile_lookup.py (reported line 7)May include surrounding context.

python
功能说明:
1. 从命令行参数中读取一个或多个 11 位中国大陆手机号。
2. 按命令行参数、环境变量、脚本目录 .env 的优先级读取 AppKey。
3. 调用即刻数据开放接口 /v1/mobile/query 查询归属地。
4. 将结果格式化为适合 AI 客户端展示的文本或 JSON。

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/mobile_lookup.py (reported line 55)May include surrounding context.

python
if env_value:
            return env_value

    env_file = Path(__file__).parent / ".env"
    if not env_file.exists():
        return ""

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill requires environment access, local file access, and outbound network access, but it does not declare an explicit tool/permission scope. That creates a transparency and least-privilege problem: a host or reviewer cannot easily tell what capabilities the skill needs before use, increasing the chance of over-broad execution in sensitive environments.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The skill transmits user-supplied phone numbers and an API key to an external service. External transmission is expected for this functionality, but it still creates real privacy and data-handling risk because personal data leaves the local environment and is processed by a third party.

Content

Scanner excerpt · SKILL.md (reported line 110)May include surrounding context.

直接调用 API

text
GET https://api.jikeapi.cn/v1/mobile/query?mobile=17611491111&appkey=YOUR_APPKEY

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill asks users to submit phone numbers for lookup but does not prominently warn that those numbers are transmitted to a third-party provider. Phone numbers are personal data, so omission of this disclosure can cause privacy violations, improper consent, and regulatory/compliance issues when users or agents send real numbers off-device.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · _meta.json (reported line 8)May include surrounding context.

json
"title": "手机号码归属地查询 - 即刻数据",
  "description": "输入中国大陆 11 位手机号,实时查询归属地省份/城市、运营商、运营商类型、区号、邮编和行政区划编码。",
  "env": "JIKE_MOBILE_KEY",
  "api_url": "https://api.jikeapi.cn/v1/mobile/query",
  "homepage": "https://www.jikeapi.cn/"
}

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script sends full phone numbers and the API key to a third-party service, which is expected for the skill's functionality, but it does so without any explicit user-facing notice or consent mechanism. Because phone numbers are personal data and the key is included in the request, this creates a real privacy and data-handling risk even if not an exploit in the classic sense.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.