T08 · Insecure Dependencies
- Location
SKILL.md:50- Finding
Unpinned Third-Party Package Installation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill matches its ZoomEye search purpose, but it asks users to route a ZoomEye API key through the agent and installs an unpinned CLI package, so it needs review before use.
Before installing, prefer configuring ZoomEye yourself outside the chat, avoid pasting API keys into the agent, and rotate any key already shared this way. Install the CLI in a dedicated environment with a pinned trusted version where possible, and use `-save` only when you are comfortable storing search results locally.
SKILL.md:50Unpinned Third-Party Package Installation
SKILL.md:58ZoomEye API Key Exposed Through Chat and Command-Line Arguments
The skill explicitly instructs the user to send their ZoomEye API key to the agent for initialization, but provides no warning about credential sensitivity, retention, or safer alternatives. API keys are secrets that can be reused to access the user's account, consume quota, and expose account-linked activity, so collecting them through the agent materially increases credential-handling risk.
The entire skill description, triggers, and operating guidance are presented only in Chinese, with no indication that users may choose another language or that the tool is intentionally limited to a Chinese-speaking context. Per the language/locale policy, forcing a specific language without user opt-in is a policy concern unless clearly justified.
The skill instructs the user to disclose their ZoomEye API key directly to the agent, unnecessarily routing a secret through the conversational system. Even if intended only for setup convenience, this increases the attack surface for accidental logging, leakage to third-party systems, or misuse of the credential.
The skill documents use of -save to export search results to a local JSON file without warning that potentially sensitive reconnaissance data will be written to disk. This can lead to unintended persistence of asset inventories or exposure data in shared environments, backups, or endpoint monitoring systems.
No suspicious patterns detected.