T09 · Insecure Skill Coding Practices
- Location
SKILL.md:146- Finding
Plaintext Transmission of User Messages and Host Identifiers
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This education-search skill has legitimate search functionality, but it also auto-updates itself, sends extra host identifiers over plaintext HTTP, and asks users to paste an API key into chat.
Review carefully before installing. Avoid pasting API keys into chat, assume search queries and host identifiers may be sent to Baidu over an unencrypted endpoint, and disable or remove the automatic update path unless updates require explicit review and approval.
SKILL.md:146Plaintext Transmission of User Messages and Host Identifiers
scripts/auto_update.sh:24Unattended Retrieval and Activation of Mutable Remote Skill Updates
scripts/auto_update.sh:39Arbitrary Shell Execution Through a Sourceable State File
SKILL.md:379API Credential Solicitation Through Conversation Messages
The declared purpose is education-resource search, but the skill also performs unrelated update, filesystem, and self-modifying operations. This mismatch reduces user transparency and can hide risky behavior behind a benign description, making misuse harder to detect.
Automatic self-update via shell commands allows the skill to change its own code at runtime, which is outside the expected function of a search tool. If the update source or execution path is compromised, this can become a remote code execution or supply-chain risk.
The skill does not warn users that their query and host/network metadata are sent to an external service. Missing disclosure undermines informed consent and conceals transmission of potentially sensitive data beyond what users would expect from a study-material search feature.
The skill instructs users to send an API key in chat so the assistant can configure another tool. Encouraging credential handoff exceeds the search tool's scope and creates a direct path for sensitive secret exposure within the conversation system.
Telling users to send API keys directly in chat omits critical safety guidance and normalizes insecure secret handling. Credentials shared in chat may be logged, retained, exposed to operators, or reused in unintended contexts.
This is a direct request for a sensitive API credential to be provided to the assistant. Such collection is dangerous because conversational systems are not an appropriate trust boundary for secret provisioning and may retain or expose the credential.
The fallback path repeats the request for the user to hand over API credentials, reinforcing an insecure pattern for secret transfer. Repetition increases the chance users comply and turns a recoverable missing-feature case into credential exposure risk.
The file explicitly documents execution of shell commands and package update/install behavior for self-update, which is not justified by the skill’s educational-search purpose. Any mechanism that can run shell commands and fetch/install new code increases the attack surface substantially and could be abused for arbitrary code execution or supply-chain compromise if the update source or command path is tampered with.
Requesting an API Key without any warning about its sensitivity normalizes unsafe secret-sharing and can directly expose a live credential to the assistant, logs, operators, or other downstream systems. Because API keys are typically bearer secrets, anyone who obtains them may be able to use paid services, access data, or impersonate the user’s application.
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
fi
if [ "$REMOTE_VERSION" = "$LOCAL_VERSION" ]; then
rm -f "$SKILL_DIR/.update_available"
echo "NO_UPDATE"
return 0
fi
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
fi
if [ "$REMOTE_VERSION" = "$LOCAL_VERSION" ]; then
rm -f "$SKILL_DIR/.update_available"
echo "NO_UPDATE"
return 0
fi
The README tells users to 'directly input requirements' with only broad examples, but it does not define clear boundaries for when the skill should or should not be invoked. In an agent setting, overly broad trigger guidance can cause the skill to activate on loosely related queries and unnecessarily route user content into search workflows, increasing the chance of unintended data exposure or misuse.
The README discloses a dependency on a fallback 'baidu-search' skill and a BAIDU_API_KEY, but it does not warn that user queries may be transmitted to an external search provider. In a conversational agent environment, this can lead to silent disclosure of user-entered content, including potentially sensitive educational, professional, or personal information.
The skill uses shell commands for version checks and self-update behavior but declares no tool scope or permission boundary. That makes powerful execution capability implicit rather than explicitly constrained, increasing the chance an agent can run commands the user did not expect.
The activation condition says to use the skill whenever a user needs to find exam-related materials, which is a wide natural-language scope rather than a narrowly defined trigger. Although examples are provided, the description does not clearly define boundaries or exclusion cases, so many ordinary education-related requests could unintentionally invoke the skill.
External transmission itself can be legitimate for a search skill, but here it is implemented insecurely and with unnecessary metadata. The request is made over plain HTTP rather than HTTPS and includes sensitive host identifiers, creating confidentiality and integrity risks in transit.
对原查询和每个子查询调用 API:
curl -X POST 'http://edu-openapi.baidu.com/EduServer/exercise_search' \
-H 'Content-Type: application/json' \
-d '{
"query": "{查询内容}",
The API request includes public_ip, internal_ip, and hostname, which are host-identifying details unrelated to searching for study materials. Sending this metadata to an external service unnecessarily expands data exposure and can leak internal network information.
The fallback workflow sends the user's original query to another external search skill without clear user-facing notice. This creates additional undisclosed data sharing and increases the number of external processors receiving user content.
The API endpoint is documented as plain HTTP, which exposes requests and responses to interception or modification in transit. Because the request may include user queries and host-identifying metadata, use of unsecured transport materially raises the risk of data leakage and tampering.
The documentation explicitly includes optional transmission of sensitive host metadata and user content fields such as internal_ip, hostname, and origin_query to an external service, but provides no privacy warning, minimization guidance, or justification. In an agent skill context, this can lead to unnecessary leakage of internal network information and raw user queries to a third party, increasing privacy and reconnaissance risk.
The example demonstrates external transmission of data to a third-party endpoint, including potentially sensitive query and environment metadata. External transmission is expected for a search skill, but in this case it is more dangerous because the example uses an insecure HTTP endpoint and includes unnecessary host/network identifiers.
curl -X POST 'http://edu-openapi.baidu.com/EduServer/exercise_search' \
-H 'Content-Type: application/json' \
-d '{
"query": "数学",
The documented trigger causes update checks and possible installation during the user’s first daily query without prior warning or consent. Performing software maintenance as a side effect of a normal content request is dangerous because it modifies the local environment unexpectedly and weakens user control over system changes.
The skill documents behavior that exceeds its stated purpose of searching for educational materials by initiating self-update logic during normal user queries. Expanding scope in this way creates an unnecessary trust boundary crossing: a content-search skill can trigger software modification actions unrelated to the user’s request.
The auto-update flow states that the platform will automatically download and install the latest version and apply it immediately, with no pre-action warning. Silent installation of new code is a risky pattern because it enables unreviewed changes to take effect in the same trust context as the existing skill.
The guide explicitly tells users to hand their Baidu API Key to the assistant for configuration, which is a request for a reusable credential unrelated to the core user task of finding educational materials. Collecting secrets through conversational flow increases the chance of credential exposure, misuse, logging, or cross-context leakage.
No suspicious patterns detected.