Back to skill

Security audit

Google-AI Mode 搜索

Security checks for vulnerabilities and agentic risk

Overview

This Google AI search skill performs the advertised search, but it also has under-scoped feedback reporting, local retention, credential handling, and billing/account flows that need careful review.

Install only if you are comfortable sending search queries and some agent/session metadata to LinkFox, storing full search responses locally, and using LinkFox account and billing flows from the skill. Avoid entering sensitive queries, phone numbers, SMS codes, or payment actions unless you intentionally want LinkFox onboarding or purchase support, and prefer managing API keys through a secure credential store rather than shell startup files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:167
Finding

Silent Transmission of User Feedback and Intent to an External Service

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/google_ai_search.py:61
Finding

Unnecessary Transmission of Agent and Session Metadata

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/google_ai_search.py:115
Finding

Plaintext Retention of Search Responses in Cache, Session, and Temporary Directories

Content
View full analysis
str: """选择可写的 linkfox 根目录。 优先级: 1. $ACPX_WORKSPACES 第一个路径下的 linkfox/(真实的工作目录) 2. 当前工作目录下的 linkfox/ 3. ~/linkfox/ 4. $TMPDIR/linkfox/ 当某路径只读(如 cwd 为 /tmp 或只读目录)时,自动回退到后序选项。 选定结果在进程内缓存,保证同一次运行内所有落盘路径稳定一致。 """ cached = _SESSION_CACHE.get("_root") if cached: return cached candidates = [] acpx = (os.environ.get("ACPX_WORKSPACES") or "").strip() if acpx: acpx = acpx.split(os.pathsep)[0].strip() if acpx: candidates.append(os.path.join(acpx, "linkfox")) candidates.append(os.path.join(os.getcwd(), "linkfox")) candidates.append(os.path.join(os.path.expanduser("~"), "linkfox")) import tempfile candidates.append(os.path.join(tempfile.gettempdir(), "linkfox")) ``` ```python cache_path = _cache_path(params) result = _load_cache(cache_path) if use_cache else None if result is None: result = call_api(params) if use_cache: _save_cache(cache_path, result) serialized = json.dumps(result, ensure_ascii=False, indent=2) ts = int(time.time()) out_path = _resolve_output_path(ts) try: with open(out_path, "w") as f: f.write(serialized) print(f"Saved full response: {out_path} ({len(serialized)} bytes)") if result.get("_cache", {}).get("hit"): print(f"Cache hit: {cache_path}") except OSError as e: print(f"Failed to save to {out_path}: {e}", file=sys.stderr) ``` ### Technical Analysis The script writes complete API responses twice under normal cached operat ...[truncated 1841 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/onboarding.py:471
Finding

API Credential Exposed Through Standard Output and Plaintext Shell Configuration

Content
View full analysis
dict: masked = _mask_phone(phone) if not re.fullmatch(r"\d{11}", phone): return {"error": f"login: 手机号格式不正确: {phone}", "phone": masked} if not re.fullmatch(r"\d{4,8}", code): return {"error": f"login: 验证码格式不正确: {code}", "phone": masked} lg = _login_v3(phone, code, channel) if "error" in lg: return {"error": lg["error"], "phone": masked} if lg.get("is_new_user"): lbt = _login_by_token(lg["access_token"], lg["refresh_token"]) if "error" in lbt: print(f"{TAG} {lbt['error']}(不影响拿 key)", file=sys.stderr) info = _fetch_user_info_v3(lg["access_token"], lg["user_id"]) if "error" in info: return {"error": info["error"], "phone": masked} tok = _get_or_generate_api_token(lg["access_token"], lg["user_id"], info["group_id"]) if "error" in tok: return {"error": tok["error"], "phone": masked} return { "api_key": tok["api_key"], "phone": masked, "group_id": info["group_id"], "member_id": info["member_id"], "source": tok["source"], "nick_name": lg.get("nick_name", ""), "team_name": info.get("team_name", ""), "is_new_user": lg.get("is_new_user", False), } ``` The returned dictionary is printed directly: ```python def _emit(obj: dict) -> None: print(json.dumps(obj, ensure_ascii=False, indent=2)) def _cmd_login(args) -> int: r = login_and_get_key(args.phone.strip(), args.code.strip(), args.channel) _emit(r) if "api_key" in r: print(f"{TAG} 成功获取 API key(来源: {r['source']})", file=sys.stderr) re ...[truncated 2221 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
scripts/onboarding.py:162
Finding

Unpinned Runtime Dependency Installation Guidance

Content
View full analysis
dict: try: import qrcode except ImportError: err = "缺少 qrcode 依赖,请运行: pip install qrcode pillow" print(f"{TAG} render_qr: {err}", file=sys.stderr) return {"png_path": None, "ascii_qr": None, "error": err} ``` ```python def _require_requests() -> None: if requests is None: raise RuntimeError("缺少 requests 依赖,请运行: pip install requests") ``` ### Technical Analysis When dependencies are missing, the Skill instructs users to install `qrcode`, `pillow`, and `requests` without version constraints, hashes, a lockfile, or a verified package source. As a result, the installed code can vary over time and cannot be reliably matched to the audited version. No malicious or typosquatted dependency is directly specified in the project. The finding concerns supply-chain hardening and reproducibility rather than evidence that the listed packages are malicious. ### Attack Path 1. The onboarding script runs in an environment where one of the dependencies is absent. 2. The script displays an unpinned `pip install` command. 3. The user executes the command against the configured Python package index. 4. Pip resolves whatever versions are current or available from that index. 5. A compromised package release, compromised index, unsafe mirror, or incompatible future version is installed. 6. Package installation or later import executes the supplied third-party code in the user's environment. ### Impact Assessment Third-party Python packages execute with the privileges of the user running the installation or Skill. A compromised dependency could therefore access that user's files, environment variables, API credentials, and network access. There is no evidence in the audit ...[truncated 136 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (24)

Tainted flow: 'req' from os.environ.get (line 73, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
93% confidence
Finding

The request destination and headers are influenced by environment variables, most notably LINKFOX_TOOL_GATEWAY and multiple propagated metadata headers. This lets whoever controls the execution environment redirect authenticated requests to an arbitrary server and exfiltrate the API key and user/session metadata, which is especially risky for an agent skill expected to handle user-driven research queries.

Content

Scanner excerpt · scripts/google_ai_search.py (reported line 80)May include surrounding context.

python
method="POST",
    )
    try:
        with urlopen(req, timeout=150) as response:
            return json.loads(response.read().decode("utf-8"))
    except HTTPError as e:
        body = e.read().decode("utf-8") if e.fp else ""

Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The code builds request destinations from environment-controlled base URLs and then sends sensitive data and authorization headers to those endpoints via requests.post. If an attacker can influence environment variables, they can redirect SMS login, access tokens, refresh tokens, user identifiers, and generated API tokens to attacker-controlled infrastructure, creating a credential exfiltration path and possible SSRF-style behavior.

Content

Scanner excerpt · scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Tainted flow: 'req' from os.environ.get (line 244, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The gateway request path uses an environment-derived base URL and includes the API key in the Authorization header before calling urlopen. An attacker who can set the environment can redirect these authenticated requests to an arbitrary server and capture API keys, order/payment metadata, and account information, while also enabling outbound requests to unintended internal or external hosts.

Content

Scanner excerpt · scripts/onboarding.py (reported line 246)May include surrounding context.

python
headers["Content-Type"] = "application/json"
        req = Request(url, method=method, data=body_bytes, headers=headers)
        try:
            with urlopen(req, timeout=30) as resp:
                return json.loads(resp.read().decode())
        except urllib.error.HTTPError as e:
            status = e.code

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

If the referenced onboarding/API flows include SMS login, token handling, account lookup, package purchase, and payment operations, then the skill ecosystem enables account and billing actions far outside the stated search-summary purpose. Even when indirect via referenced docs, that is a dangerous capability expansion because it can lead to credential handling and financial side effects under a benign-seeming skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the referenced onboarding/API flows include SMS login, token handling, account lookup, package purchase, and payment operations, then the skill ecosystem enables account and billing actions far outside the stated search-summary purpose. Even when indirect via referenced docs, that is a dangerous capability expansion because it can lead to credential handling and financial side effects under a benign-seeming skill.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger criteria are intentionally broad, including cases where the user does not explicitly request Google AI functionality. Overbroad activation can cause unnecessary external transmission of user queries and context to this skill, creating both privacy risk and tool-routing abuse potential.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 121)May include surrounding context.

}

text

## Display Rules

1. **Render the Markdown directly**: `stdout` is already structured Markdown with headings, bullets, and citation links — preserve that structure when answering the user.
2. **Cite sources**: keep the inline reference links from `stdout` so the user can verify each claim.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/onboarding.md (reported line 14)May include surrounding context.

md
示 JSON 里的 phone/agreements
   - 收到验证码后:`python scripts/onboarding.py login <phone> <code>`
   - 拿到 `api_key` 后把下面三平台配置转发给用户,提示重启会话生效:
     - Windows PowerShell(永久):`setx LINKFOX_AGENT_API_KEY "<key>"`
     - macOS zsh:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.zshrc && source ~/.zshrc`
     - Linux bash:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.bashrc && source ~/.bashrc`
     - 变量名 `LINKFOX_AGENT_API_KEY`(主推)或 `LINKFOXAGENT_API_KEY`(老规范)任一即可

**billing 场景**:`errcode=402` 或消息含 `算力/余额/quota/insufficient/充值/套餐到期`。
- `python scripts/onboarding.py list-plans` → 有 AskUserQuestion 就弹菜单,否则输出编号清单让用户选
- 校验 `plan_id` ∈ 清单、支付方式 ∈ 该套餐 `available_methods`(通常 `wechat/alipay`)
- `python scripts/onboarding.py order <plan_id> <method>` → 展示优先级 PNG

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The module documentation promises that writing to /tmp is forbidden and that failure to write the current directory should cause an error, but the code instead silently falls back to home and temporary directories. This discrepancy is dangerous because operators may rely on the documented storage guarantees when handling sensitive search results, while the actual behavior can place data in less controlled locations such as shared temp storage.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file implements account onboarding, SMS verification, API key retrieval, billing, and order management, which is materially unrelated to the declared Google AI search summarization purpose of the skill. This mismatch is dangerous because it can socially engineer users or agents into invoking credential collection and monetization flows under the cover of a benign search feature.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code adds package enumeration, order creation, payment URL handling, and QR code rendering despite the skill being described as a web-search summarization tool. Hidden billing capability increases the risk of unauthorized purchases, deceptive upsell behavior, and collection of sensitive commercial/account metadata outside user expectations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This section performs SMS-based login, accesses user profile/team data, and retrieves or generates API tokens, all unrelated to the stated Google search task. In skill context, covert credential harvesting and token generation are especially dangerous because they can grant persistent access to a user's account or tenant and facilitate downstream abuse well beyond a single search request.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill describes capabilities that use environment variables, network access, and persistent file writes, but it does not declare any explicit tool scope or permission boundaries. This weakens least-privilege controls and makes it harder for the host agent to constrain unexpected data access, retention, or outbound transmission.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The follow-up design tells the agent to summarize prior answers and embed that summary into a new external search query. This creates a built-in data exfiltration path where previously received content, potentially including sensitive user context, is retransmitted to Google without a separate consent checkpoint.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill mandates persistent logging of complete responses into session-scoped files under the working directory, potentially capturing user queries, citations, account-related error content, and other sensitive data. Because storage is automatic and project-local, it can leak information to other tools, collaborators, repositories, or later sessions without the user's awareness.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs the agent to ask in English for US/UK/AU, Japanese for JP, German for DE, and so on. This is a language/locale policy concern because it directs output/query language based on market rather than offering the user a choice or obtaining opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The boundary guidance uses common phrases like '用谷歌搜一下' or generalized research wording, which overlaps with many ordinary assistant tasks. This increases the chance of accidental invocation and data sharing when the user may only want generic reasoning or non-external help.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
85% confidence
Finding

The skill explicitly instructs sending a keyword to an external endpoint and provides a live curl example targeting a remote service. In this skill's context, external transmission is expected functionality, but it still creates a real data-exfiltration surface because user queries may contain sensitive information and the documentation does not constrain or warn against transmitting secrets, personal data, or internal context.

Content

Scanner excerpt · references/api.md (reported line 52)May include surrounding context.

}

text

## curl 示例

```bash
curl -X POST https://tool-gateway.linkfox.com/aiMode/googleSearch \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation introduces a separate feedback API that accepts free-form content and user sentiment details but does not warn that user-provided text may be sent to an external third-party service. In an agent setting, this can lead to unintended disclosure of user prompts, private data, or sensitive business context if integrators automatically forward conversation content as feedback.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to collect a user's phone number and drive an OTP-based registration/login flow, but it provides no privacy notice, consent language, retention limits, or guidance on safe handling of sensitive data. In an agent context, this creates unnecessary exposure of personal data and authentication material, especially if the phone number or verification flow is logged, echoed back, or stored in transcripts.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill advertises a simple Google AI search capability, but the implementation also creates persistent per-session storage, metadata indexes, and a cache hierarchy on local disk. That hidden retention expands the data-handling surface: user queries, API responses, session identifiers, and metadata may be stored longer than users or integrators expect, creating privacy and data exposure risk if the workspace is shared or later exfiltrated.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill hard-codes the SMS area code to +86, and elsewhere describes the input as an 11-digit domestic mobile number, which enforces a specific locale and language context. The file does not offer a user choice of locale/region or document a justified region-specific restriction, so this is a natural-language policy violation under the locale policy rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The skill documentation is primarily presented in Chinese and does not indicate that language selection is optional or that the skill is intentionally region-specific. Per the policy rule, forcing a specific language without user opt-in can be a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.