Back to skill

Security audit

AI 趋势分析

Security checks for vulnerabilities and agentic risk

Overview

The skill is purpose-aligned, but its scripts can send the API token to an environment-controlled endpoint, so users should review it before installing.

Install only if you are comfortable sending AI-industry search terms and selected insight IDs to the Jiqizhixin API. Treat JQZX_API_TOKEN as a secret, avoid running the scripts with an overridden BASE_URL, and prefer a version that pins or allowlists the API host and removes unsafe credential forwarding across redirects.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/query_insights.sh:4
Finding

API Token Disclosure Through an Unrestricted Search API Base URL

Content
View full analysis
Remediation
View remediation
&2 exit 1 ;; esac ``` 3. Require HTTPS and reject embedded credentials, unexpected ports, IP-address substitutions, and hostname suffix tricks. 4. Avoid following redirects for authenticated requests unless redirects are strictly necessary. Remove `--location`, or validate each redirect target and ensure authentication headers cannot cross trusted-origin boundaries. 5. Consider loading the token only after endpoint validation so the secret is never placed into a request prepared for an untrusted destination. 6. Rotate any token that may already have been used while `BASE_URL` pointed to an untrusted host, and review API access logs for misuse. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
scripts/query_insight_detail.sh:4
Finding

API Token Disclosure Through an Unrestricted Insight Detail API Base URL

Content
View full analysis
``` 6. The attacker records the credential and reuses it against the intended API service. ### Impact Assessment The attacker gains all API capabilities authorized for the stolen token. Potential consequences include unauthorized access to pr ...[truncated 309 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill advertises shell-capable scripts and direct API invocation but does not declare any tool scope or allowed-tools boundary. In agents that honor manifest permissions, this can lead to overbroad execution capability, making it easier for the skill to trigger shell actions or networked scripts without explicit least-privilege constraints.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill promotes direct API calls to a production external service but does not warn that user prompts, queries, and analysis context may be transmitted off-platform. In a research or enterprise setting, this can expose confidential business context, internal hypotheses, or sensitive user data to a third-party endpoint without meaningful notice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill description mandates use of this skill for AI-related questions, removing normal user choice and potentially routing sensitive or routine queries to an external workflow by default. This is risky because it can override safer local handling, create unnecessary data disclosure, and constrain user autonomy without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs users to set an API token in an environment variable but gives no warning about credential sensitivity, storage, masking, or log exposure. This increases the chance of accidental token leakage through shell history, screenshots, shared terminals, or verbose command output.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The workflow says the model may use its own memory to expand search keywords, which conflicts with the stated prohibition on relying on LLM memory for factual AI-industry answers. This inconsistency can cause hallucinated or biased query expansion, leading the agent to retrieve irrelevant or slanted material and undermining provenance guarantees.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script performs a network request and includes the sensitive environment variable JQZX_API_TOKEN in an HTTP header, but there is no comment, log message, or confirmation explaining that the token will be sent to a remote service. The existing messages only cover missing arguments and missing environment variables, not the fact that credentials are transmitted over the network.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's natural-language output strings for errors and usage guidance are exclusively in Chinese. Under the policy, forcing a specific language without opt-in or documented locale justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This shell script performs a network call to a remote endpoint and transmits the user-provided keyword and related query parameters, authenticated with a token from the environment. While the code validates that the token exists, it does not print or document that data will be sent off-host, which matches the missing-warning criterion for code files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This markdown file documents use of X-MCP-TOKEN and requires setting JQZX_API_TOKEN, which involves sensitive credentials. The section provides the mechanics of authentication but does not include any warning about protecting the token, avoiding disclosure in logs, or using secure environment handling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document title and instructional text are entirely in Chinese and present the keyword reference as the default operating language, with no indication that users may opt into another language or locale. Under the stated policy, a skill artifact that imposes a specific language without user choice can constitute a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

All user-facing output strings are in Chinese, which imposes a specific language on users without any opt-in or explanation. This can violate language/locale policy when the skill is expected to be generally usable across users or environments.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.