Back to skill

Security audit

zoomeye-org-search

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its ZoomEye search purpose, but it asks users to route a ZoomEye API key through the agent and installs an unpinned CLI package, so it needs review before use.

Before installing, prefer configuring ZoomEye yourself outside the chat, avoid pasting API keys into the agent, and rotate any key already shared this way. Install the CLI in a dedicated environment with a pinned trusted version where possible, and use `-save` only when you are comfortable storing search results locally.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:50
Finding

Unpinned Third-Party Package Installation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:58
Finding

ZoomEye API Key Exposed Through Chat and Command-Line Arguments

Content
View full analysis
" ``` It then validates the stored configuration with: ```bash zoomeye info ``` ### Technical Analysis A ZoomEye API key is a long-lived authentication credential. The Skill explicitly directs users to disclose this credential through the conversation and interpolates it into a shell command. This design can disclose the key through multiple channels: - Conversation history and AI service records - Agent traces and tool-call logs - Shell auditing or command logging - Process command-line inspection while the command runs - Diagnostic output, telemetry, or error reports - Persistent local ZoomEye configuration created by `zoomeye init` The command template also does not require validation of the key's character set before shell interpolation. Double-quote wrapping alone is not a general defense for arbitrary shell input, because shell expansions and quote termination can still become relevant if unexpected characters are accepted and the command is executed through a shell. ### Attack Path 1. The ZoomEye CLI reports that authentication is required. 2. Following the Skill instructions, the agent asks the user to send the API key in the conversation. 3. The user submits the credential, causing it to enter conversation records and agent processing logs. 4. The agent embeds the credential in the `zoomeye init -apikey` command. 5. The credential may additionally appear in tool traces, process arguments, command auditing, or error telemetry. 6. An operator, service component, local process, or other party with access to one of those records retrieves the API key ...[truncated 946 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly instructs the user to send their ZoomEye API key to the agent for initialization, but provides no warning about credential sensitivity, retention, or safer alternatives. API keys are secrets that can be reused to access the user's account, consume quota, and expose account-linked activity, so collecting them through the agent materially increases credential-handling risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The entire skill description, triggers, and operating guidance are presented only in Chinese, with no indication that users may choose another language or that the tool is intentionally limited to a Chinese-speaking context. Per the language/locale policy, forcing a specific language without user opt-in is a policy concern unless clearly justified.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the user to disclose their ZoomEye API key directly to the agent, unnecessarily routing a secret through the conversational system. Even if intended only for setup convenience, this increases the attack surface for accidental logging, leakage to third-party systems, or misuse of the credential.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill documents use of -save to export search results to a local JSON file without warning that potentially sensitive reconnaissance data will be written to disk. This can lead to unintended persistence of asset inventories or exposure data in shared environments, backups, or endpoint monitoring systems.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.