Back to skill

Security audit

足球联赛查询 - 聚合数据

Security checks for vulnerabilities and agentic risk

Overview

This football-query skill is coherent, but it needs Review because it sends the user's Juhe API key over plaintext HTTP and documents weak key-handling options.

Review before installing. The skill does not show hidden persistence or unrelated data access, but it should be changed to HTTPS before use, and users should avoid passing the API key on the command line or storing it in the skill directory. Prefer a runtime environment variable or secret manager, and rotate any key already used through the plaintext HTTP version.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/football_query.py:25
Finding

API Credential Transmitted over Plaintext HTTP

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/football_query.py:238
Finding

API Key Exposure through Command-Line Arguments

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/football_query.py:288
Finding

Duplicate API Requests Unnecessarily Retransmit the Credential

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Credential Access

High
Category
Privilege Escalation
Confidence
81% confidence
Finding

The skill advises storing the API key in a .env file under the scripts directory, which can lead to accidental exposure through source control, packaging, backups, or overbroad file access by tools. In a skill context that already implies file-read capability, encouraging on-disk secret storage increases the chance the credential is unintentionally accessed or disclosed.

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

md
# 方式一:环境变量(推荐,一次配置永久生效)
export JUHE_FOOTBALL_KEY=你的 AppKey

# 方式二:.env 文件(在脚本目录创建)
echo "JUHE_FOOTBALL_KEY=你的 AppKey" > scripts/.env

# 方式三:每次命令行传入

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

The examples show passing the API key directly on the command line, which commonly exposes secrets via shell history, process listings, audit logs, and job runners. This is a well-known credential-handling weakness and is unnecessary when environment variables are already supported.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

md
export JUHE_FOOTBALL_KEY=你的 AppKey

# 方式二:.env 文件(在脚本目录创建)
echo "JUHE_FOOTBALL_KEY=你的 AppKey" > scripts/.env

# 方式三:每次命令行传入
python scripts/football_query.py  --key 你的 AppKey  --type yingchao

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/football_query.py (reported line 13)May include surrounding context.

python
API Key 配置(任选其一,优先级从高到低):
    1. 命令行参数:python football_query.py --key your_api_key ...
    2. 环境变量:export JUHE_FOOTBALL_KEY=your_api_key
    3. 脚本同目录的 .env 文件:JUHE_FOOTBALL_KEY=your_api_key

免费申请 API Key: https://www.juhe.cn/docs/api/id/90
"""

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/football_query.py (reported line 270)May include surrounding context.

python
API Key 配置(任选其一,优先级从高到低):
    1. 命令行参数:python football_query.py --key your_api_key ...
    2. 环境变量:export JUHE_FOOTBALL_KEY=your_api_key
    3. 脚本同目录的 .env 文件:JUHE_FOOTBALL_KEY=your_api_key

免费申请 API Key: https://www.juhe.cn/docs/api/id/90
"""

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/football_query.py (reported line 50)May include surrounding context.

python
if env_key:
        return env_key

    env_file = Path(__file__).parent / ".env"
    if env_file.exists():
        for line in env_file.read_text(encoding="utf-8").splitlines():
            line = line.strip()

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill advertises capabilities that imply reading environment variables, local files, and making network requests, but it does not declare an explicit tool scope such as permissions or allowed-tools. This weakens reviewability and least-privilege controls, making it harder for a host agent or user to understand what the skill can access before execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation instructs users to send the API key in a URL over plain HTTP, which exposes the secret to interception by network observers, proxies, logs, and browser or shell history. Because the key is transmitted as a query parameter, leakage risk is even higher than with a header or request body.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script sends the API key as a URL query parameter over plain HTTP to apis.juhe.cn, which exposes the credential to network interception and tampering by any attacker on the path. Because this is an agent skill that may run in varied environments, transmitting secrets without TLS materially increases the chance of credential theft and malicious response manipulation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The file consistently presents the skill description, setup steps, and operating guidance only in Chinese. This effectively forces a specific language/locale without documenting that limitation or offering a language choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

All natural-language help text, errors, and usage instructions are hard-coded in Chinese, and there is no option for users to select another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The comment at L296 suggests the program is merely outputting the JSON form of the already obtained result. Instead, L299-L302 issues a second network request by calling query_ranking/query_matches again, which adds an extra side effect and may return different data from the human-readable output above.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.