Back to skill

Security audit

腾讯云LKE智能体对话

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Tencent Cloud chat API helper, but users should treat anything they send through it as leaving their local environment.

Install only if you intend to use Tencent Cloud LKE. Do not send secrets, regulated personal data, internal document URLs, or confidential prompts unless your organization permits Tencent Cloud processing; pin dependency versions before production use and avoid passing sensitive values through fields that may be printed to logs.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
references/requirements.txt:6
Finding

Unpinned third-party dependencies create mutable supply-chain exposure

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/sse_chat.py:126
Finding

Sensitive workflow values may be exposed through console logging

Content
View full analysis
50 else f" 系统角色: {system_role}") if custom_vars: print(f" 自定义变量: {json.dumps(custom_vars, ensure_ascii=False)}") ``` ### Technical Analysis The client prints system-role content and serializes the complete `custom_vars` object to standard output. Custom workflow variables can legitimately include user identifiers, order information, tenant-specific values, or other confidential application data. System-role text may also contain proprietary instructions. Standard output is frequently captured by CI systems, terminal recording, container logs, or centralized logging services. Consequently, data supplied for transmission to the declared Tencent Cloud endpoint is additionally disclosed to every system or person with access to those logs. The AppKey itself is not printed by this code. ### Attack Path 1. A user supplies confidential content through `--system-role` or `--custom-vars`. 2. The script prints that content before sending the request. 3. A shell recorder, CI runner, container platform, or centralized logging agent retains standard output. 4. A user with log-reading access obtains the exposed workflow values or role instructions. This path requires sensitive values to be supplied and an unauthorized or unnecessarily broad audience to have access to captured output. ### Impact Assessment The issue can disclose confidential prompt instructions and workflow data to local users, operators, or services that can read execution logs. It does not directly grant elevated system privileges, and the exposed scope is limited to values supplied in these arguments. The severity can increase if operators place credentials, access tokens, personal data, or privileged ide ...[truncated 34 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill clearly instructs users to call a remote Tencent Cloud endpoint, but the manifest does not declare any tool scope or allowed network capability. This creates a transparency and governance gap: an agent may exfiltrate prompts, identifiers, or file metadata over the network without an explicit permission boundary for users or platform policy to enforce.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill describes sending session identifiers, visitor identifiers, message content, and optional file URLs to a third-party cloud service, but provides no privacy notice, consent guidance, or data-handling warning. In an agent setting, this can cause inadvertent disclosure of personal, confidential, or regulated data to an external processor without the operator realizing what leaves the environment.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The example explicitly performs external transmission of conversation data to a remote SSE endpoint. While this is core to the skill's purpose, it is still security-relevant because prompts, identifiers, and optional document references may be sent off-platform and streamed back, increasing exposure if users assume the interaction is local or trusted by default.

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

2. 基本调用示例

bash
curl --location 'https://wss.lke.cloud.tencent.com/v1/qbot/chat/sse' \
--header 'Content-Type: application/json' \
--data '{
  "session_id": "a29bae68-cb1c-489d-8097-6be78f136acf",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file documents required request fields including a visitor identifier and free-form message content sent to a remote HTTPS endpoint, but it does not include any warning about privacy, data handling, or sensitivity of transmitted user data. Under the markdown-specific SQP-2 criteria, user-facing documentation should warn when skill behavior may affect user data or privacy.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api_reference.md (reported line 119)May include surrounding context.

md
| 460037 | 搜索资源已用尽 |
| 460038 | 该AppID请求存在异常行为 |

## cURL 完整示例

### 基础对话

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The workflow example shows sending custom variables such as a user ID and order type to the service, which can affect privacy and user data exposure. The documentation presents this as a normal usage pattern without any caution about minimizing, redacting, or protecting sensitive identifiers.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file’s natural-language interface, usage text, help strings, and runtime messages are entirely in Chinese, which imposes a specific language/locale on users. There is no indication that the tool is region-specific or that users can opt into another language.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script sends user-supplied message content plus optional metadata such as custom variables, visitor labels, and file information to Tencent Cloud, but it does not provide an explicit warning, consent prompt, or data-minimization guidance before transmission. In a reusable skill context, this can lead operators to unintentionally forward sensitive data to a third-party service, creating privacy and compliance risk rather than a code-execution flaw.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This code performs an outbound HTTPS POST to a third-party Tencent endpoint containing conversation content, identifiers, and optional metadata. External transmission is expected for this skill's purpose, but it still represents a real security/privacy boundary because sensitive prompts or attached metadata may be exfiltrated outside the local trust domain if users are not adequately informed or if untrusted inputs are passed through blindly.

Content

Scanner excerpt · scripts/sse_chat.py (reported line 136)May include surrounding context.

python
print("-" * 50)
    
    try:
        response = requests.post(
            url, 
            headers=headers, 
            json=payload,

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This plain-text requirements file uses Chinese headings and instructions throughout, but does not indicate that the skill is region-specific or provide any user opt-in for language/locale. Under the policy rule, forcing a specific language without documented justification can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.