Back to skill

Security audit

短链接 - 即刻数据

Security checks for vulnerabilities and agentic risk

Overview

This short-link skill mostly does what it claims, but it handles the API key in a way that can expose it, especially through an undocumented configurable API endpoint.

Install only if you trust the Jike API service and your execution environment. Do not shorten sensitive or internal URLs, avoid passing the AppKey on the command line, and ensure JIKE_API_BASE_URL is unset or locked to the legitimate HTTPS API host before use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/shortlink.py:185
Finding

API Credential Exposure Through Query Parameters and an Unvalidated Configurable API Endpoint

Content
View full analysis

Vulnerability Details

File Location: scripts/shortlink.py, lines 26 and 185–186
Vulnerability Type: API credential disclosure and insecure endpoint configuration
Risk Level: Medium

Vulnerable Code

python
API_BASE_URL = os.environ.get("JIKE_API_BASE_URL", "https://api.jikeapi.cn").rstrip("/")
python
request_params = {**params, "appkey": appkey}
url = f"{API_BASE_URL}{API_PATH_MAP[command]}?{urllib.parse.urlencode(request_params)}"

Technical Analysis

The script includes the AppKey directly in the URL query string. Query strings are commonly recorded by destination servers, reverse proxies, network-monitoring products, debugging systems, and application telemetry. This creates unnecessary opportunities for credential disclosure.

The risk is compounded by the undocumented JIKE_API_BASE_URL environment variable. Its value is used without validating the URL scheme or destination host. A party capable of influencing the process environment can set this variable to an attacker-controlled host or a plaintext HTTP endpoint. The next API operation will then transmit the AppKey and business parameters to that endpoint.

The URL validator applied to user-provided short links does not protect the API endpoint itself. There is no HTTPS requirement, hostname allowlist, or trusted-origin verification for API_BASE_URL.

Attack Path

  1. An attacker gains the ability to influence the environment used to launch the Skill, such as through a compromised wrapper, deployment configuration, automation job, or shared execution environment.
  2. The attacker sets JIKE_API_BASE_URL to an attacker-controlled URL, for example https://attacker.example.
  3. A user or agent invokes create, restore, or stat.
  4. The script constructs a request to the attacker-controlled endpoint and places the AppKey in the appkey query parameter.
  5. The attacker records the URL, extracts the AppKey, and may als ...[truncated 1030 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the unrestricted JIKE_API_BASE_URL override in production. If endpoint configurability is required, parse the configured URL and enforce:
    • The https scheme.
    • An explicit allowlist of trusted hostnames.
    • An expected port and normalized origin.
    • Rejection of embedded credentials, fragments, and unexpected path components.
  2. Send the AppKey in a protected request header, such as Authorization or a vendor-defined API-key header, rather than in the query string. Coordinate this change with the API provider if the current service only accepts query parameters.
  3. Configure clients and infrastructure not to log authorization headers or sensitive request data.
  4. Avoid supplying the key through the --key command-line option because process arguments may be visible to other local users or process-monitoring systems. Prefer a protected secret store or tightly controlled environment variable.
  5. Apply least privilege, quotas, and key rotation. Revoke and replace any key suspected of appearing in logs or being sent to an untrusted endpoint.
  6. Add tests confirming that non-HTTPS endpoints, unapproved hosts, and malformed base URLs are rejected before any network request occurs.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (10)

Tainted flow: 'url' from os.environ.get (line 188, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/shortlink.py (reported line 191)May include surrounding context.

python
url = f"{API_BASE_URL}{API_PATH_MAP[command]}?{urllib.parse.urlencode(request_params)}"

    try:
        with urllib.request.urlopen(url, timeout=15) as response:
            return json.loads(response.read().decode("utf-8"))
    except urllib.error.HTTPError as exc:
        return {"code": exc.code, "message": f"接口请求失败: HTTP {exc.code}", "data": ""}

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/shortlink.py (reported line 61)May include surrounding context.

python
if env_value:
            return env_value

    env_file = Path(__file__).parent / ".env"
    if not env_file.exists():
        return ""

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill performs network access and uses environment-provided secrets, but it does not declare an explicit tool or permission scope. That can cause an agent platform to grant broader-than-necessary capabilities or leave reviewers unable to enforce least privilege, increasing the chance of unintended external requests or secret exposure during execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description lists activation examples such as “帮我生成一个短链接” and “查一下这个短链访问次数”, but it does not define a constrained trigger set, exclusion conditions, or narrow invocation context. This can cause unintended activation because the examples are expressed as ordinary conversational requests rather than bounded command patterns.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
78% confidence
Finding

The skill sends user-supplied URLs and the app key to an external third-party API endpoint. Even though external transmission is expected for this skill's function, it still creates a real data-exfiltration and third-party trust boundary risk, especially if sensitive URLs or tokens are embedded in the links users submit.

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

直接调用 API

text
GET https://api.jikeapi.cn/v1/shortlink/create?target=https://www.jikeapi.cn/&appkey=YOUR_APPKEY
GET https://api.jikeapi.cn/v1/shortlink/restore?link=http://t.jikeapi.cn/s/NgZYJ&appkey=YOUR_APPKEY
GET https://api.jikeapi.cn/v1/shortlink/stat?link=http://t.jikeapi.cn/s/NgZYJ&appkey=YOUR_APPKEY

External Transmission

Medium
Category
Data Exfiltration
Confidence
78% confidence
Finding

The restore operation transmits the provided short link and app key to an external service, which leaks user activity and queried link data to a third party. Because the examples place the app key in the URL query string, the credential may also be exposed in logs, proxies, browser history, or telemetry systems.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

text
GET https://api.jikeapi.cn/v1/shortlink/create?target=https://www.jikeapi.cn/&appkey=YOUR_APPKEY
GET https://api.jikeapi.cn/v1/shortlink/restore?link=http://t.jikeapi.cn/s/NgZYJ&appkey=YOUR_APPKEY
GET https://api.jikeapi.cn/v1/shortlink/stat?link=http://t.jikeapi.cn/s/NgZYJ&appkey=YOUR_APPKEY

External Transmission

Medium
Category
Data Exfiltration
Confidence
79% confidence
Finding

The statistics endpoint sends short-link identifiers and credentials to an external API, exposing usage patterns and potentially sensitive operational metadata to a third party. In this context the transmission is functional, but it still broadens the data exposure surface and can reveal business or user behavior through analytics queries.

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

text
GET https://api.jikeapi.cn/v1/shortlink/create?target=https://www.jikeapi.cn/&appkey=YOUR_APPKEY
GET https://api.jikeapi.cn/v1/shortlink/restore?link=http://t.jikeapi.cn/s/NgZYJ&appkey=YOUR_APPKEY
GET https://api.jikeapi.cn/v1/shortlink/stat?link=http://t.jikeapi.cn/s/NgZYJ&appkey=YOUR_APPKEY

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The manifest declares transmission to an external third-party API endpoint, which means user-supplied URLs and related metadata may leave the local trust boundary. In a shortlink skill this is expected functionality, but it still creates privacy and data-handling risk, especially if sensitive links, tokens, or internal URLs are submitted to the service.

Content

Scanner excerpt · _meta.json (reported line 8)May include surrounding context.

json
"title": "短链接 - 即刻数据",
  "description": "支持生成短链接、短链接还原和短链接访问统计,可设置最大访问次数和到期时间。",
  "env": "JIKE_SHORTLINK_KEY",
  "api_url": "https://api.jikeapi.cn/v1/shortlink/create",
  "homepage": "https://www.jikeapi.cn/"
}

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
74% confidence
Finding

The natural-language metadata is entirely in Chinese, and the file does not indicate that the skill is region-specific or that users can opt into a preferred language. This may violate language/locale policy when skills are expected to avoid forcing a language without user choice or documented justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This JSON manifest describes the skill's capabilities but does not specify any concrete trigger phrases, activation boundaries, or exclusion conditions. For manifest files, that can make invocation criteria ambiguous and increase the chance of unintended activation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.