Back to skill

Security audit

Exchange Rate - 全球货币汇率换算

Security checks for vulnerabilities and agentic risk

Overview

This exchange-rate skill does what it claims, but it handles the required API key in ways that can expose it.

Review before installing. Use a low-privilege Juhe key, avoid the --key command-line option, avoid committing scripts/.env, and prefer installation only after the API calls are changed to HTTPS or the provider's secure transport support is confirmed. This review did not find deception, destructive behavior, persistence, or unrelated data collection.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/exchange_rate.py:28
Finding

API Credential Transmitted in a Plaintext HTTP Query String

Content
View full analysis
dict: """发起 HTTP GET 请求""" full_url = f"{url}?{urllib.parse.urlencode(params)}" try: with urllib.request.urlopen(full_url, timeout=15) as resp: return json.loads(resp.read().decode("utf-8")) except Exception as e: return {"error_code": -1, "reason": f"网络请求失败: {e}"} ``` ```python def query_currency_list(api_key: str) -> dict: """查询支持的货币列表""" data = _request(LIST_API_URL, {"key": api_key}) ``` ```python data = _request(CURRENCY_API_URL, { "key": api_key, "from": from_curr, "to": to_curr, }) ``` ### Technical Analysis The Skill must communicate with the declared Juhe exchange-rate service to perform its intended function. Sending the API key to that service is therefore functionally necessary. However, both API endpoints use plaintext HTTP, and `_request()` places the credential in the URL query string. HTTP provides neither transport confidentiality nor server authentication. Any network observer or active intermediary between the host and the API service—including a compromised router, public Wi-Fi operator, transparent proxy, gateway, or malicious DNS/network operator—can read the API key and currency parameters. An active intermediary can also modify the response because its integrity is not protected. Placing the key in the URL creates additional exposure because complete URLs may be retained by proxies, network monitoring systems, access logs, or diagnostic tooling. This exceeds the minimum privilege necessary for the Skill: the key only needs to be disclosed securely to the intended API provi ...[truncated 1518 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/exchange_rate.py:163
Finding

API Key Accepted Through a Command-Line Argument

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

The documentation instructs users to place the API key into scripts/.env and also shows passing the key on the command line. Both practices increase the risk of credential exposure through accidental commits, local file disclosure, shell history, process listings, or logging.

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

md
# 方式一:环境变量(推荐)
export JUHE_EXCHANGE_KEY=你的AppKey

# 方式二:.env 文件
echo "JUHE_EXCHANGE_KEY=你的AppKey" > scripts/.env

# 方式三:命令行传入

Credential Access

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

The explicit example writing JUHE_EXCHANGE_KEY to scripts/.env encourages storing credentials in a repository-adjacent plaintext file. In a skill context with file-read capability, plaintext secret placement materially raises the chance of unintended exposure or leakage via tooling, backup, or source control.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

md
export JUHE_EXCHANGE_KEY=你的AppKey

# 方式二:.env 文件
echo "JUHE_EXCHANGE_KEY=你的AppKey" > scripts/.env

# 方式三:命令行传入
python scripts/exchange_rate.py --key 你的AppKey --from USD --to CNY

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/exchange_rate.py (reported line 13)May include surrounding context.

python
API Key 配置(任选其一,优先级从高到低):
    1. 环境变量: export JUHE_EXCHANGE_KEY=your_api_key
    2. 脚本同目录的 .env 文件: JUHE_EXCHANGE_KEY=your_api_key
    3. 直接传参: python exchange_rate.py --key your_api_key --from USD --to CNY

免费申请 API Key: https://www.juhe.cn/docs/api/id/80

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/exchange_rate.py (reported line 208)May include surrounding context.

python
API Key 配置(任选其一,优先级从高到低):
    1. 环境变量: export JUHE_EXCHANGE_KEY=your_api_key
    2. 脚本同目录的 .env 文件: JUHE_EXCHANGE_KEY=your_api_key
    3. 直接传参: python exchange_rate.py --key your_api_key --from USD --to CNY

免费申请 API Key: https://www.juhe.cn/docs/api/id/80

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/exchange_rate.py (reported line 41)May include surrounding context.

python
if env_key:
        return env_key

    env_file = Path(__file__).parent / ".env"
    if env_file.exists():
        for line in env_file.read_text(encoding="utf-8").splitlines():
            line = line.strip()

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill advertises executable behavior that uses environment variables, local files, and outbound network access, but it does not declare any explicit tool scope or permission boundary. This can lead to overly broad agent execution and weak user visibility into what resources the skill may access, especially since it reads credentials and contacts a third-party API.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases are broad enough that the skill could activate on vague requests like '汇率多少', which may cause unintended invocation. While not a direct exploit primitive, ambiguous activation increases the chance of unnecessary external calls and unintended disclosure of user query content to the third-party provider.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documents live requests to juhe.cn but does not clearly warn that user-supplied currency pair, amount, and the API key are transmitted to an external service. This weakens informed consent and can expose sensitive usage patterns or secrets, especially because the examples use query-string transmission to a third party.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script sends the API key to Juhe endpoints over plain HTTP, so the key and query parameters can be intercepted or modified by any attacker on the network path. Even though the key is for a data API, plaintext transport also permits tampering with responses and exposes user query activity.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

User-facing documentation, usage text, and runtime messages are written only in Chinese, imposing a specific language without user opt-in. This matches the language/locale policy concern because no alternative language or selection mechanism is offered.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.