Back to skill

Security audit

EchoTik-商品视频查询

Security checks for vulnerabilities and agentic risk

Overview

The skill can perform the advertised TikTok product-video lookup, but it also bundles account login, API-key, billing/payment, telemetry, and local storage behaviors that deserve careful review before use.

Review this skill before installing. Use it only if you trust LinkFox with product queries, session metadata, and any onboarding data you provide. Prefer obtaining an API key directly from the first-party site instead of giving the agent phone numbers or SMS codes, confirm any paid plan/order action yourself, protect and rotate exposed API keys, avoid setting endpoint override environment variables, and periodically delete local linkfox cache/session files if they may contain sensitive business data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (6)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:153
Finding

Automatic Transmission of Conversation-Derived Data Without Explicit Consent

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/echotik_list_product_video.py:36
Finding

Environment-Controlled API Endpoints Can Receive Production Credentials

Content
View full analysis
str: """Gateway base address: environment variable first.""" return (os.environ.get("LINKFOX_TOOL_GATEWAY") or "https://tool-gateway.linkfox.com").rstrip("/") def get_api_url(): sys.path.insert( 0, os.path.join( os.path.dirname(os.path.abspath(__file__)), "..", "..", "_shared", ), ) return get_api_base() + API_PATH def get_api_key(): key = ( os.environ.get("LINKFOX_AGENT_API_KEY") or os.environ.get("LINKFOXAGENT_API_KEY") ) if not key: print("API Key not configured", file=sys.stderr) sys.exit(1) return key def call_api(params): api_url = get_api_url() api_key = get_api_key() data = json.dumps(params).encode("utf-8") headers = { "Authorization": api_key, "Content-Type": "application/json", "User-Agent": "LinkFox-Skill/2.0", "SESSION_ID": os.environ.get("SESSION_ID", ""), "MESSAGE_ID": os.environ.get("MESSAGE_ID", ""), "MODE_ID": os.environ.get("MODE_ID", ""), "APP_NAME": os.environ.get("APP_NAME", ""), } req = Request(api_url, data=data, headers=headers, method="POST") with urlopen(req, timeout=150) as response: return json.loads(response.read().decode("utf-8")) ``` The onboarding script applies the same design to more sensitive authentication endpoints: ```python def _agent_base() -> str: return _env_base( "LINKFOX_AGENT_API_URL", "https://tool-gateway.linkfox.com", "LINKFOX_TOOL_GATEWAY", ) def _login_base() -> str: return _env_base( ...[truncated 2337 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/onboarding.py:486
Finding

Generated API Key Is Printed to Standard Output in Plaintext

Content
View full analysis
None: print(json.dumps(obj, ensure_ascii=False, indent=2)) def _cmd_login(args) -> int: r = login_and_get_key( args.phone.strip(), args.code.strip(), args.channel, ) _emit(r) if "api_key" in r: print( f"{TAG} Successfully obtained API key " f"(source: {r['source']})", file=sys.stderr, ) return 0 return 1 ``` ### Technical Analysis After SMS authentication, the full API key is included in a result dictionary and serialized directly to stdout. Standard output is commonly retained by Agent transcripts, terminal scrollback, shell redirections, CI logs, process supervisors, and automation frameworks. Masking the phone number does not protect the API key. The key is the principal credential used by the product-query and billing-related gateway functions. ### Attack Path 1. A user runs `python scripts/onboarding.py login `. 2. The script authenticates and retrieves or generates an API key. 3. `_cmd_login` passes the result to `_emit`. 4. `_emit` prints the complete key as JSON. 5. A transcript, log collector, redirected file, or another party with access to command output obtains the credential. 6. The credential can be reused against LinkFox gateway APIs until revoked or expired. ### Impact Assessment An exposed API key may allow unauthorized API requests, consumption of paid computational credits, access to account-associated data, ...[truncated 209 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/echotik_list_product_video.py:247
Finding

Unvalidated Session Identifier Allows Output-Path Traversal

Content
View full analysis
str: """Prefer SESSION_ID; otherwise generate a local identifier.""" env = os.environ.get("SESSION_ID") if env: return env.strip() if "_auto" not in _SESSION_CACHE: _SESSION_CACHE["_auto"] = ( time.strftime("%H%M%S", time.localtime(ts)) + "-" + secrets.token_hex(3) ) return _SESSION_CACHE["_auto"] def _ensure_session(ts: float) -> tuple[str, str]: date_str = time.strftime("%Y-%m-%d", time.localtime(ts)) sid = _session_id(ts) root = _linkfox_root() session_dir = os.path.join(root, date_str, sid) os.makedirs(session_dir, exist_ok=True) _ensure_meta(root, session_dir, date_str, sid, ts) return root, session_dir def _update_meta( session_dir: str, *, skill: str, kind: str, file_rel: str, ts: float, ) -> None: meta_path = os.path.join(session_dir, "_meta.json") try: with open(meta_path, encoding="utf-8") as f: meta = json.load(f) except (OSError, json.JSONDecodeError): return # ... with open(meta_path, "w", encoding="utf-8") as f: json.dump(meta, f, ensure_ascii=False, indent=2) ``` The onboarding implementation contains the same issue: ```python def session_dir() -> str: ts = time.time() sid = (os.environ.get("SESSION_ID") or "").strip() or ( time.strftime("%H%M%S", time.localtime(ts)) + "-" + secrets.token_hex(3) ) path = os.path.join( _linkfox_root(), time.strftime("%Y-%m-%d", time.localtime(ts)), sid, ) os.makedirs(path, exist_ok=True) return path ``` ### Technical Analysis `SESSION_I ...[truncated 1446 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/echotik_list_product_video.py:97
Finding

Complete API Responses Are Persisted in Multiple Locations With Default Permissions

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/onboarding.py:166
Finding

Runtime Prompts Recommend Installing Unpinned Third-Party Dependencies

Content
View full analysis
dict: try: import qrcode except ImportError: err = ( "Missing qrcode dependency; run: " "pip install qrcode pillow" ) print( f"{TAG} render_qr: {err}", file=sys.stderr, ) return { "png_path": None, "ascii_qr": None, "error": err, } ``` ```python def _require_requests() -> None: if requests is None: raise RuntimeError( "Missing requests dependency; run: " "pip install requests" ) ``` ### Technical Analysis The onboarding script recommends installing `qrcode`, `pillow`, and `requests` without pinning versions, constraining transitive dependencies, or verifying package hashes. The command also does not specify an isolated environment or trusted package index. No malicious dependency is embedded in the audited project. The risk arises because package contents can change after the Skill is reviewed, making future installations non-reproducible and expanding exposure to package-index compromise or compromised upstream releases. ### Attack Path 1. The user invokes a command requiring a missing dependency. 2. The script instructs the user to run an unconstrained `pip install` command. 3. The package manager resolves the latest available releases and transitive dependencies at installation time. 4. A compromised package release, dependency, package index, or index configuration supplies malicious installation or runtime code. 5. That code executes with the privileges of the user performing the installation or later importing the package. ### Impact Assessment A compromised dependency can execute arbitr ...[truncated 288 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (25)

Tainted flow: 'req' from os.environ.get (line 73, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/echotik_list_product_video.py (reported line 80)May include surrounding context.

python
method="POST",
    )
    try:
        with urlopen(req, timeout=150) as response:
            return json.loads(response.read().decode("utf-8"))
    except HTTPError as e:
        body = e.read().decode("utf-8") if e.fp else ""

Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
94% confidence
Finding

The code builds request destinations from environment-controlled base URLs and then sends authentication material, login tokens, phone numbers, and API-token generation traffic to those endpoints. If an attacker can influence environment variables in the skill runtime, they can redirect sensitive onboarding and credential flows to attacker-controlled infrastructure, causing credential exfiltration and SSRF-like outbound access.

Content

Scanner excerpt · scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Tainted flow: 'req' from os.environ.get (line 244, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
94% confidence
Finding

The gateway helper derives its base URL from environment variables and uses it for authenticated urllib requests with the API key in the Authorization header. A manipulated runtime environment could redirect these calls to an attacker-controlled server, leaking API keys and enabling unauthorized use of the user's LinkFox account or internal network reachability through crafted destinations.

Content

Scanner excerpt · scripts/onboarding.py (reported line 246)May include surrounding context.

python
headers["Content-Type"] = "application/json"
        req = Request(url, method=method, data=body_bytes, headers=headers)
        try:
            with urlopen(req, timeout=30) as resp:
                return json.loads(resp.read().decode())
        except urllib.error.HTTPError as e:
            status = e.code

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose is product-video analytics, but the referenced behavior includes authentication, API key generation, account/team queries, subscription/package listing, payment order creation, QR-code payment generation, and payment-status polling. This is a major scope expansion into account and billing operations, which can expose sensitive identity/payment flows and enable unexpected charges or credential lifecycle actions under the guise of a data-query skill.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

}

text

## Display Rules

1. **Present data in tables**: Show video description (truncated if long), views, likes, comments, shares, video sales, video GMV, publish date, and influencer ID
2. **Link to original**: When `officialUrl` is available, provide it so users can view the video on TikTok

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file documents authentication recovery, account registration, and billing flows that are unrelated to the skill’s stated purpose of TikTok product video analytics. This creates unjustified capability expansion: an agent invoking this skill could steer users into account onboarding and payment handling, increasing phishing, abuse, and unauthorized data-handling risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instructions explicitly enable registration/login via phone number and paid plan purchase, neither of which is justified by a read/analysis skill for TikTok product videos. Unrelated identity and payment workflows materially increase the attack surface and could be abused for unauthorized account creation, social engineering, or collecting sensitive user data.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/onboarding.md (reported line 14)May include surrounding context.

md
示 JSON 里的 phone/agreements
   - 收到验证码后:`python scripts/onboarding.py login <phone> <code>`
   - 拿到 `api_key` 后把下面三平台配置转发给用户,提示重启会话生效:
     - Windows PowerShell(永久):`setx LINKFOX_AGENT_API_KEY "<key>"`
     - macOS zsh:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.zshrc && source ~/.zshrc`
     - Linux bash:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.bashrc && source ~/.bashrc`
     - 变量名 `LINKFOX_AGENT_API_KEY`(主推)或 `LINKFOXAGENT_API_KEY`(老规范)任一即可

**billing 场景**:`errcode=402` 或消息含 `算力/余额/quota/insufficient/充值/套餐到期`。
- `python scripts/onboarding.py list-plans` → 有 AskUserQuestion 就弹菜单,否则输出编号清单让用户选
- 校验 `plan_id` ∈ 清单、支付方式 ∈ 该套餐 `available_methods`(通常 `wechat/alipay`)
- `python scripts/onboarding.py order <plan_id> <method>` → 展示优先级 PNG

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file implements LinkFox account onboarding, SMS login, API-key retrieval, subscription purchase, and payment operations, which are materially different from the declared TikTok product video analytics purpose. This capability mismatch is dangerous because users or orchestrators may invoke the skill expecting read-only analytics while it actually performs identity, billing, and credential-management actions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code creates orders, queries billing state, and renders payment QR codes for purchase flows unrelated to product video analytics. Embedding billing execution inside an analytics skill creates unauthorized-spend risk and can mislead users into approving financial actions they did not intend when requesting simple reporting data.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill can send SMS codes, log users in, exchange tokens, inspect team information, and generate or retrieve API keys. In the context of a purported analytics skill, these are highly sensitive account-takeover and credential-provisioning capabilities that can be abused to obtain durable access to user accounts far beyond the stated business need.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill documentation describes capabilities that use environment variables, network access, and file writes, but it does not declare any explicit tool scope or permission boundary. In an agent environment, this creates hidden authority: the skill can access credentials, persist data locally, and make outbound requests without transparent least-privilege constraints, increasing the chance of unintended data exposure or misuse.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation criteria are intentionally broad, allowing the skill to trigger even when the user does not explicitly mention EchoTik or product-video analysis. Over-broad triggering increases the risk of accidental invocation of a costly, networked skill on unrelated requests, which can cause unnecessary data access, external calls, and user charges.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs automatic use of a separate Feedback API unrelated to the core product-video lookup function and says not to interrupt the user's flow. Silent background reporting can transmit user content, session context, or behavioral data to another endpoint without clear consent, creating a privacy and data-governance risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 73)May include surrounding context.

}

text

## curl 示例

```bash
curl -X POST https://tool-gateway.linkfox.com/echotik/listProductVideo \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The onboarding flow instructs the agent to request a phone number and process SMS-code login without any privacy notice, minimization guidance, or disclosure of where that personal data is sent. This can expose users to unnecessary collection of personal and authentication data and normalizes sharing sensitive identifiers and one-time codes with the agent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The module documentation promises that writing to /tmp is forbidden and that failure should occur if the current directory is not writable, but the implementation silently falls back to the home directory or temporary directory. This mismatch is dangerous because operators and users may rely on the documented storage restrictions, while the code actually writes data to less controlled locations, increasing accidental disclosure risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script sends user-supplied parameters and multiple session-related environment values to a remote gateway without any explicit runtime disclosure to the user. In a skill context that appears to be a local analytics/query helper, this lack of transparency can lead to unintended external sharing of user data, identifiers, and business queries.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script persistently stores full API responses, cache entries, and session metadata on local disk, even though the skill is described as a query/analytics capability. Because the returned product-video analytics may include sensitive business data and the metadata ties outputs to sessions, this creates unnecessary data retention and local disclosure risk beyond what a read-only lookup skill needs.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module self-describes as a LinkFox account/environment onboarding CLI, directly contradicting the manifest's TikTok product video analytics intent. This mismatch is a strong signal of deceptive packaging, which increases the likelihood that sensitive credential and payment functionality is being smuggled under an unrelated skill label.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module docstring and CLI help text are written in Chinese and present the skill's interface in a single forced language. This can violate a language/locale policy when no user opt-in or alternative locale is offered.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The manifest description is primarily written in Chinese with embedded English trigger phrases, which can impose a language expectation without stating that users may interact in their preferred language. Under the language/locale policy, skills should avoid forcing a language unless choice or justification is documented.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file documents a POST request to an external endpoint and instructs readers to supply an API key from environment variables in the Authorization header. Under the markdown-specific warning rule, the description lacks an explicit warning that using the skill sends data off-system and uses sensitive credentials.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The natural-language instructions, prompts, and user-facing guidance are entirely in Chinese, and the skill does not indicate that users may interact in another language or that the locale restriction is intentional. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.