Back to skill

Security audit

house-hunter

Security checks for vulnerabilities and agentic risk

Overview

This skill is a real house-hunting research tool, but its browser bridge and setup flow create review-worthy risks around logged-in site data and persistent shell configuration.

Review before installing. Only use the browser bridge when you trust the skill and need logged-in housing-site data; stop it with Ctrl+C immediately after use and avoid browsing untrusted sites while it is running. Prefer an isolated Python environment, review any shell rc changes before sourcing them, do not paste untrusted strings as API keys, and consider disabling Tianditu until HTTPS transport is used.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/housing_bridge_server.py:196
Finding

Unauthenticated Localhost Bridge Exposes Authenticated Browser Content

Content
View full analysis
controller.abort(), timeout_ms); try { const r = await fetch(url, { credentials: "include", redirect: "follow", signal: controller.signal }); const html = await r.text(); const finalUrl = r.url; const isLogin = looksLikeLoginPage(html, finalUrl); return { status: r.status, final_url: finalUrl, content_length: html.length, html: html, ``` ### Technical Analysis The bridge binds to localhost by default but does not authenticate requests to `/fetch`, `/poll`, `/result`, `/heartbeat`, or `/health`. It also returns `Access-Control-Allow-Origin: *`, allowing JavaScript from an arbitrary website to send requests to the local service and read its responses. A request to `/fetch` becomes a task for the Chrome extension ...[truncated 1765 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/_common.py:565
Finding

Shell Command Injection Through Unescaped API-Key Persistence

Content
View full analysis
None: import re lines: list[str] = [] if os.path.isfile(rc_path): with open(rc_path, "r", encoding="utf-8") as f: lines = f.readlines() pattern = re.compile(r'^\s*export\s+' + re.escape(var) + r'\s*=') new_line = f'export {var}="{value}"\n' for i, line in enumerate(lines): if pattern.match(line): lines[i] = new_line with open(rc_path, "w", encoding="utf-8") as f: f.writelines(lines) return if lines and not lines[-1].endswith("\n"): lines[-1] += "\n" if section_tag and not any(section_tag in l for l in lines): lines.append(f"\n# {section_tag}\n") lines.append(new_line) with open(rc_path, "w", encoding="utf-8") as f: f.writelines(lines) ``` ### Technical Analysis The API-key value is inserted directly into an executable shell startup file using double-quoted shell syntax. The value is not validated and shell ...[truncated 1677 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/_common.py:446
Finding

Tianditu API Credentials and Location Queries Sent Over Plaintext HTTP

Content
View full analysis
bool: import json as _json key = os.environ.get("TIANDITU_API_KEY") or os.environ.get("TDT_KEY") if not key: return False post_str = _json.dumps({ "keyWord": "公园", "level": 12, "queryRadius": 5000, "pointLonlat": "116.40,39.90", "queryType": 3, "start": 0, "count": 1, }, ensure_ascii=False, separators=(",", ":")) params = urllib.parse.urlencode({"postStr": post_str, "type": "query", "tk": key}) data = http_get_json(f"http://api.tianditu.gov.cn/v2/search?{params}", timeout=5) ``` From `scripts/sources/tianditu.py:28`: ```python TIANDITU_BASE = "http://api.tianditu.gov.cn/v2/search" ``` From `scripts/sources/tianditu.py:168`: ```python url = f"http://api.tianditu.gov.cn/geocoder?{urllib.parse.urlencode({'ds': ds, 'tk': k})}" ``` ### Technical Analysis Tianditu requests use unencrypted HTTP. The API key is included in the URL query string together with search or geocoding parameters. For actual housing searches, these parameters can contain addresses, community names, coordinates, or nearby-place interests derived from the user's request. Without TLS, any party able to observe or modify network traffic can read the credential and query data. An on-path attacker can also alter responses, potentially corrupting geocoding and point-of-interest results used in housing recommendations. Placing the credential in the query string additionally increases its exposure to intermediary logs, proxy logs, browser or network diagnostics, and server access logs. ### Attack Path 1. The primary map providers fail or reach their quotas, causing Tianditu to be used as a fallback, or t ...[truncated 857 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/setup.py:23
Finding

Unpinned Dependencies and Execution of Unreviewed External Project Code

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (170)

Tainted flow: 'req' from os.environ.get (line 176, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/_common.py (reported line 121)May include surrounding context.

python
h.update(headers)
        try:
            req = urllib.request.Request(url, headers=h)
            with urllib.request.urlopen(req, timeout=timeout) as resp:
                data = resp.read()
                encoding = (resp.headers.get("Content-Encoding") or "").lower()
                if encoding == "gzip":

Tainted flow: 'req' from os.environ.get (line 176, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/_common.py (reported line 177)May include surrounding context.

python
h.update(headers)
        try:
            req = urllib.request.Request(url, headers=h)
            with urllib.request.urlopen(req, timeout=timeout) as resp:
                data = resp.read()
                encoding = (resp.headers.get("Content-Encoding") or "").lower()
                if encoding == "gzip":

Tainted flow: 'req' from os.environ.get (line 45, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/sources/housing_bridge.py (reported line 50)May include surrounding context.

python
headers={"Content-Type": "application/json"},
    )
    try:
        with urllib.request.urlopen(req, timeout=timeout_s) as r:
            return json.loads(r.read().decode("utf-8"))
    except urllib.error.HTTPError as e:
        try:

Tainted flow: 'url' from os.environ.get (line 64, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/sources/housing_bridge.py (reported line 66)May include surrounding context.

python
def _http_get_json(path: str, timeout_s: float = 5.0) -> dict | None:
    url = BRIDGE_URL.rstrip("/") + path
    try:
        with urllib.request.urlopen(url, timeout=timeout_s) as r:
            return json.loads(r.read().decode("utf-8"))
    except Exception:
        return None

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · .gitignore (reported line 25)May include surrounding context.

text
# Local secrets / config overrides
config/mcp_servers.local.json
.env
*.env
ke_open.env

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · .gitignore (reported line 26)May include surrounding context.

text
# Local secrets / config overrides
config/mcp_servers.local.json
.env
*.env
ke_open.env

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The installation prompt explicitly instructs the AI to download external code, install dependencies, write config files, and start background services automatically. This is dangerous because it encourages broad system modification and execution of third-party code with little user review, increasing the risk of supply-chain compromise, unsafe persistence, and unintended changes to the host environment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill documents external site scraping, HTML fetching, and use of authenticated housing-site sessions, but the high-risk scraping capability is not prominently disclosed in the top-level description. Hidden or underemphasized scraping using user-authenticated sessions can expose account data, violate user expectations, and create legal or privacy issues.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill documents external site scraping, HTML fetching, and use of authenticated housing-site sessions, but the high-risk scraping capability is not prominently disclosed in the top-level description. Hidden or underemphasized scraping using user-authenticated sessions can expose account data, violate user expectations, and create legal or privacy issues.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The skill documents external site scraping, HTML fetching, and use of authenticated housing-site sessions, but the high-risk scraping capability is not prominently disclosed in the top-level description. Hidden or underemphasized scraping using user-authenticated sessions can expose account data, violate user expectations, and create legal or privacy issues.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The skill documents external site scraping, HTML fetching, and use of authenticated housing-site sessions, but the high-risk scraping capability is not prominently disclosed in the top-level description. Hidden or underemphasized scraping using user-authenticated sessions can expose account data, violate user expectations, and create legal or privacy issues.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill documents external site scraping, HTML fetching, and use of authenticated housing-site sessions, but the high-risk scraping capability is not prominently disclosed in the top-level description. Hidden or underemphasized scraping using user-authenticated sessions can expose account data, violate user expectations, and create legal or privacy issues.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The skill documents external site scraping, HTML fetching, and use of authenticated housing-site sessions, but the high-risk scraping capability is not prominently disclosed in the top-level description. Hidden or underemphasized scraping using user-authenticated sessions can expose account data, violate user expectations, and create legal or privacy issues.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill documents external site scraping, HTML fetching, and use of authenticated housing-site sessions, but the high-risk scraping capability is not prominently disclosed in the top-level description. Hidden or underemphasized scraping using user-authenticated sessions can expose account data, violate user expectations, and create legal or privacy issues.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill documents external site scraping, HTML fetching, and use of authenticated housing-site sessions, but the high-risk scraping capability is not prominently disclosed in the top-level description. Hidden or underemphasized scraping using user-authenticated sessions can expose account data, violate user expectations, and create legal or privacy issues.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill documents external site scraping, HTML fetching, and use of authenticated housing-site sessions, but the high-risk scraping capability is not prominently disclosed in the top-level description. Hidden or underemphasized scraping using user-authenticated sessions can expose account data, violate user expectations, and create legal or privacy issues.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill documents external site scraping, HTML fetching, and use of authenticated housing-site sessions, but the high-risk scraping capability is not prominently disclosed in the top-level description. Hidden or underemphasized scraping using user-authenticated sessions can expose account data, violate user expectations, and create legal or privacy issues.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill documents external site scraping, HTML fetching, and use of authenticated housing-site sessions, but the high-risk scraping capability is not prominently disclosed in the top-level description. Hidden or underemphasized scraping using user-authenticated sessions can expose account data, violate user expectations, and create legal or privacy issues.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The skill documents external site scraping, HTML fetching, and use of authenticated housing-site sessions, but the high-risk scraping capability is not prominently disclosed in the top-level description. Hidden or underemphasized scraping using user-authenticated sessions can expose account data, violate user expectations, and create legal or privacy issues.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

The skill documents external site scraping, HTML fetching, and use of authenticated housing-site sessions, but the high-risk scraping capability is not prominently disclosed in the top-level description. Hidden or underemphasized scraping using user-authenticated sessions can expose account data, violate user expectations, and create legal or privacy issues.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill documents external site scraping, HTML fetching, and use of authenticated housing-site sessions, but the high-risk scraping capability is not prominently disclosed in the top-level description. Hidden or underemphasized scraping using user-authenticated sessions can expose account data, violate user expectations, and create legal or privacy issues.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill documents external site scraping, HTML fetching, and use of authenticated housing-site sessions, but the high-risk scraping capability is not prominently disclosed in the top-level description. Hidden or underemphasized scraping using user-authenticated sessions can expose account data, violate user expectations, and create legal or privacy issues.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill documents external site scraping, HTML fetching, and use of authenticated housing-site sessions, but the high-risk scraping capability is not prominently disclosed in the top-level description. Hidden or underemphasized scraping using user-authenticated sessions can expose account data, violate user expectations, and create legal or privacy issues.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill documents external site scraping, HTML fetching, and use of authenticated housing-site sessions, but the high-risk scraping capability is not prominently disclosed in the top-level description. Hidden or underemphasized scraping using user-authenticated sessions can expose account data, violate user expectations, and create legal or privacy issues.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill documents external site scraping, HTML fetching, and use of authenticated housing-site sessions, but the high-risk scraping capability is not prominently disclosed in the top-level description. Hidden or underemphasized scraping using user-authenticated sessions can expose account data, violate user expectations, and create legal or privacy issues.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
extension/manifest.json:15