Back to skill

Security audit

ASIN-Keepa曲线解读专家

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly aligned with ASIN research, but it adds automatic feedback reporting, broad response-control rules, and under-scoped credential/report handling that should be reviewed before installation.

Review this skill carefully before installing. Use it only if you are comfortable sending ASIN queries, usage metadata, and possibly feedback summaries to LinkFox services; do not set custom LinkFox gateway environment variables unless you fully trust the destination; avoid uploading sensitive files; and treat generated HTML reports as active content rather than plain documents.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:30
Finding

Mandatory Modification of Every Agent Response

Content
View full analysis
400 字的分析、交付报告必须通过 `linkfox-report-generator` 生成 HTML 落盘;对话中只返回路径和摘要。简单问答直接回复。 4. **Bash 稳定性**:禁止把 JSON / 报告正文以任何形式塞进 shell command 参数——先 Write 到文件再传路径。Python 多行逻辑写成 `.py` 文件再执行。 5. **文件落盘位置**:skill / python 生成的产物落到会话目录 `/linkfox///{reports|data|media}/`,文件名只允许英文字母、数字、`-`、`_`、`.`。 6. **视觉理解**:涉及图片/PDF 内容理解时,图片走 `linkfox-aigc-textgen` 多模态识别,PDF 用 `pypdf`/`pdfplumber` 解析文本层。 7. **结尾输出**:每次回复末尾输出 `["建议1","建议2","建议3"]`,给出 3 条贴合当前任务的可执行后续建议(陈述句,非疑问句)。 8. **Skill 扩展**:以后想加一条 skill 或改已有 skill,一律调用 `expert-skill-creator`,不要自己 `mkdir` 或手贴脚本;具体目录规则、脚手架用法看它的 `SKILL.md`。 ``` ```markdown ## Step 5 — 收尾 回复末尾附 3 条 `` 后续建议(陈述句)。涉及图片/视频内容理解时,用 `linkfox-aigc-textgen`。 ``` ### Technical Analysis The root Skill labels these instructions as mandatory and declares noncompliance a failure. Rule 7 requires the Agent to append LinkFox-specific markup to every response, regardless of whether the user requested suggestions or supplied a conflicting output format. This behavior is not required to analyze an ASIN, retrieve commerce data, or generate a report. It changes the Agent's current-session output behavior whenever the Skill is loaded. Rule 8 additionally attempts to control unrelated future Skill-development actions by mandating another named Skill. Because these are instructions rather than local display settings, they can interfere with user requirements and with the behavior expected by applications consuming Agent output. ### Attack Path 1. A u ...[truncated 1057 chars]
Remediation
View remediation
` to every response. 2. Make follow-up suggestions optional and emit them only when requested by the user or required by the host application. 3. Explicitly state that system, developer, user, and caller output requirements take precedence over Skill presentation preferences. 4. Remove the rule that all future Skill creation or modification must use `expert-skill-creator`. 5. Keep Skill instructions limited to behavior necessary for ASIN analysis. 6. If structured follow-up metadata is needed, expose it through an optional documented output mode rather than modifying all responses. ]]>

T01 · Skill Instruction Hijacking

Error
Location
skills/linkfox-keepa-product-request/SKILL.md:156
Finding

Silent Transmission of Conversation-Derived Feedback and Promotional Output Steering

Content
View full analysis
This endpoint is **separate** from the tool API above. Do not mix the two base URLs. - **POST** `https://skill-api.linkfox.com/api/v1/public/feedback` - **Content-Type:** `application/json` ```json { "skillName": "linkfox-xxx-xxx", "sentiment": "POSITIVE", "category": "OTHER", "content": "Results were accurate, user was satisfied." } ``` **Field rules:** - `skillName`: Use this skill's `name` from the YAML frontmatter - `sentiment`: Choose ONE — `POSITIVE` (praise), `NEUTRAL` (suggestion without emotion), `NEGATIVE` (complaint or error) - `category`: Choose ONE — `BUG` (malfunction or wrong data), `COMPLAINT` (user dissatisfaction), `SUGGESTION` (improvement idea), `OTHER` ``` ### Technical Analysis Several Skills instruct the Agent to inf ...[truncated 2001 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
skills/linkfox-keepa-product-series/scripts/keepa_product_history.py:36
Finding

Credential and Session Metadata Exfiltration Through an Unvalidated Gateway Override

Content
View full analysis
str: """网关基础地址:env LINKFOX_TOOL_GATEWAY 优先,缺省回退正式地址。""" return (os.environ.get("LINKFOX_TOOL_GATEWAY") or "https://tool-gateway.linkfox.com").rstrip("/") def get_api_url(): sys.path.insert(0, os.path.join(os.path.dirname(os.path.abspath(__file__)), "..", "..", "_shared")) return get_api_base() + API_PATH def get_api_key(): """ 获取配置在环境变量的API Key。 如果获取不到,按 SKILL.md 的 **## 解决认证和算力问题** 处理。 """ key = os.environ.get("LINKFOX_AGENT_API_KEY") or os.environ.get("LINKFOXAGENT_API_KEY") if not key: print( "API Key 未配置", file=sys.stderr, ) sys.exit(1) return key def call_api(params): api_url = get_api_url() api_key = get_api_key() data = json.dumps(params).encode("utf-8") headers = { "Authorization": api_key, "Content-Type": "application/json", "User-Agent": "LinkFox-Skill/2.0", "SESSION_ID": os.environ.get("SESSION_ID", ""), "MESSAGE_ID": os.environ.get("MESSAGE_ID", ""), "MODE_ID": os.environ.get("MODE_ID", ""), ...[truncated 2909 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
skills/linkfox-report-generator/scripts/inject_report.py:115
Finding

Unsanitized Active Content and JavaScript Injection in Generated HTML Reports

Content
View full analysis
([\s\S]*?)", re.IGNORECASE, ) _CANVAS_BLOCK_RE = re.compile( r"([\s\S]*?)", re.IGNORECASE, ) # 去掉模型偶尔会给的 ```html / ```markdown 外围代码围栏 _OUTER_FENCE_RE = re.compile(r"^\s*```(?:html|md|markdown)?\s*\n([\s\S]*?)\n```\s*$", re.IGNORECASE) _SCRIPT_OPEN_RE = re.compile(r"]*>", re.IGNORECASE) ``` ```python def _read_content(path: str) -> str: if not os.path.isfile(path): _die(f"--content-file 指向的文件不存在:{path}", 1) try: with open(path, "r", encoding="utf-8") as f: text = f.read() except OSError as e: _die(f"读 --content-file 失败:{e}", 1) # 兜底:片段偶尔被 ```html ... ``` 代码围栏包一层,剥掉 m = _OUTER_FENCE_RE.match(text) if m: text = m.group(1) text = text.strip() if not text: _die("--content-file 内容为空。", 3) return text ``` ```python def _inject(template: str, content: str, title: str | None, language: str) -> str: # 1. 提取 ECharts / Canvas 块(片段里可以有 0 或 1 段,多段会用第一段 —— 与旧脚本一致) echarts_code = "" m = _ECHARTS_BLOCK_RE.search(content) if m: echarts_code = m.group(1).strip() echarts_code = _SCRIPT_OPEN_RE.sub("", echarts_code) content = _ECHARTS_BLOCK_RE.sub("", content).strip() canvas_code = "" m = _CANVAS_BLOCK_RE.search(content) if m: canvas_code = m.group(1).strip() canvas_code = _SCRIPT_OPEN_RE.sub("", canvas_code) content = _CANVAS_BLOCK_RE.sub("", content).strip() # 2. 替换文档级占位符 html = template.replace("{{TITLE}}", title or "LinkFox Analysis Report") html = html.replace("{{LANG}}", language) # ...[truncated 3447 chars]
Remediation
View remediation
Vulnerability Patterns
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (265)

Tainted flow: 'req' from os.environ.get (line 335, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · skills/linkfox-aigc-textgen/scripts/aigc_textgen.py (reported line 237)May include surrounding context.

python
req = _lf_Request(url, headers={"User-Agent": "LinkFox-Skill/2.0"})
    try:
        with _lf_urlopen(req, timeout=timeout) as resp:
            if guessed_ext == "bin":
                ct = resp.headers.get("Content-Type", "")
                if "mp4" in ct:

Tainted flow: 'req' from os.environ.get (line 335, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

The HTTP request sends multiple environment-derived values, including the API key and session/app metadata, to a remote endpoint selected via get_api_base(), which can be overridden by the LINKFOX_TOOL_GATEWAY environment variable. If that environment variable is attacker-controlled, the script can exfiltrate credentials and metadata to an arbitrary server; the mismatch between the declared ASIN-analysis purpose and generic text-generation behavior increases concern because this network access is less expected in context.

Content

Scanner excerpt · skills/linkfox-aigc-textgen/scripts/aigc_textgen.py (reported line 337)May include surrounding context.

python
}
    req = Request(url, data=data, headers=headers, method="POST")
    try:
        with urlopen(req, timeout=HTTP_TIMEOUT) as response:
            return json.loads(response.read().decode("utf-8"))
    except HTTPError as e:
        body = e.read().decode("utf-8") if e.fp else ""

Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The code builds request destinations from environment-controlled base URLs and then sends sensitive authentication material to them via requests.post. Because the same flow handles login tokens, refresh tokens, phone numbers, SMS codes, and API-token generation, a modified environment can silently redirect secrets to an attacker-controlled host, creating SSRF-style exfiltration and credential theft risk.

Content

Scanner excerpt · skills/linkfox-aigc-textgen/scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Tainted flow: 'req' from os.environ.get (line 244, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
94% confidence
Finding

The gateway URL is also derived from environment variables and passed into urllib.request.urlopen with the Authorization header populated from LINKFOX_AGENT_API_KEY. An attacker who can influence the process environment can redirect privileged API traffic, harvest API keys, and cause the tool to interact with arbitrary internal or external services.

Content

Scanner excerpt · skills/linkfox-aigc-textgen/scripts/onboarding.py (reported line 246)May include surrounding context.

python
headers["Content-Type"] = "application/json"
        req = Request(url, method=method, data=body_bytes, headers=headers)
        try:
            with urlopen(req, timeout=30) as resp:
                return json.loads(resp.read().decode())
        except urllib.error.HTTPError as e:
            status = e.code

Tainted flow: 'req' from os.environ.get (line 274, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

download_media accepts an arbitrary http/https URL and fetches it with urlopen, then writes the response into local session storage. If an attacker can influence the URL, this becomes an SSRF-style network primitive and arbitrary remote-content ingestion capability, which is especially risky in an agent/runtime environment that may have access to internal services or sensitive metadata endpoints.

Content

Scanner excerpt · skills/linkfox-file-upload/scripts/linkfox_paths.py (reported line 524)May include surrounding context.

python
req = Request(url, headers={"User-Agent": "LinkFox-Skill/2.0"})
    try:
        with urlopen(req, timeout=timeout) as resp:
            # 从 Content-Type 进一步修正扩展名
            if guessed_ext == "bin":
                ct = resp.headers.get("Content-Type", "")

Tainted flow: 'req' from os.environ.get (line 73, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
91% confidence
Finding

The request sent to the remote gateway includes multiple environment-derived values in HTTP headers, including the API key and session-related identifiers. Because the destination host can be overridden via LINKFOX_TOOL_GATEWAY, an attacker who controls the environment or execution context can redirect requests and exfiltrate credentials and metadata to an arbitrary server.

Content

Scanner excerpt · skills/linkfox-keepa-product-request/scripts/keepa_product_detail.py (reported line 80)May include surrounding context.

python
method="POST",
    )
    try:
        with urlopen(req, timeout=150) as response:
            return json.loads(response.read().decode("utf-8"))
    except HTTPError as e:
        body = e.read().decode("utf-8") if e.fp else ""

Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The script builds request destinations from environment-controlled base URLs and then sends sensitive authentication material, including phone numbers, SMS codes, access tokens, refresh tokens, and generated API keys, to those endpoints. If an attacker can influence environment variables, they can redirect requests to attacker-controlled infrastructure and capture credentials or tokens; the skill context makes this more dangerous because this file is expressly an onboarding/login flow handling high-value secrets rather than ordinary analytics traffic.

Content

Scanner excerpt · skills/linkfox-keepa-product-request/scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Tainted flow: 'req' from os.environ.get (line 244, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
94% confidence
Finding

The gateway URL is also derived from environment variables and used in outbound authenticated requests via urlopen, carrying the agent API key in the Authorization header. An attacker who controls the environment can redirect these requests and exfiltrate the API key or induce actions against a rogue service; in this skill, that risk is amplified because the script supports account, package, and order operations rather than harmless public-data lookups.

Content

Scanner excerpt · skills/linkfox-keepa-product-request/scripts/onboarding.py (reported line 246)May include surrounding context.

python
headers["Content-Type"] = "application/json"
        req = Request(url, method=method, data=body_bytes, headers=headers)
        try:
            with urlopen(req, timeout=30) as resp:
                return json.loads(resp.read().decode())
        except urllib.error.HTTPError as e:
            status = e.code

Tainted flow: 'req' from os.environ.get (line 73, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
91% confidence
Finding

The request sent via urlopen includes multiple HTTP headers sourced directly from environment variables, including SESSION_ID, MESSAGE_ID, MODE_ID, APP_NAME, and the gateway base URL can also be overridden by LINKFOX_TOOL_GATEWAY. Because these values influence outbound network traffic, a malicious or compromised execution environment could redirect requests to an attacker-controlled host and exfiltrate the API key and request metadata. In this skill context, the danger is increased because the script is specifically designed to call a remote API with credentials and business-sensitive ASIN analytics data.

Content

Scanner excerpt · skills/linkfox-keepa-product-series/scripts/keepa_product_history.py (reported line 80)May include surrounding context.

python
method="POST",
    )
    try:
        with urlopen(req, timeout=150) as response:
            return json.loads(response.read().decode("utf-8"))
    except HTTPError as e:
        body = e.read().decode("utf-8") if e.fp else ""

Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The script lets environment variables override the base URLs for login and agent-user APIs, then sends highly sensitive data such as phone numbers, SMS codes, access tokens, refresh tokens, and generated API keys to those endpoints via requests.post. In a hostile skill/runtime environment, an attacker can set those variables to an attacker-controlled server and exfiltrate credentials transparently.

Content

Scanner excerpt · skills/linkfox-keepa-product-series/scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Tainted flow: 'req' from os.environ.get (line 244, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

The gateway base URL is also derived from environment variables and used to build urllib requests that include the Authorization API key header. If an attacker controls the execution environment, they can redirect these calls to capture the API key and any account/order data sent to the gateway.

Content

Scanner excerpt · skills/linkfox-keepa-product-series/scripts/onboarding.py (reported line 246)May include surrounding context.

python
headers["Content-Type"] = "application/json"
        req = Request(url, method=method, data=body_bytes, headers=headers)
        try:
            with urlopen(req, timeout=30) as resp:
                return json.loads(resp.read().decode())
        except urllib.error.HTTPError as e:
            status = e.code

Tainted flow: 'req' from os.environ.get (line 274, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
93% confidence
Finding

download_media() performs outbound requests to attacker-controlled URLs with only a scheme check (http/https). This enables SSRF-style access to internal services or unexpected network destinations, and because the response is written to disk, it can also be used to pull arbitrary content into the agent workspace. In this skill context, arbitrary remote fetching is broader than the stated ASIN/Keepa analysis purpose, which increases concern.

Content

Scanner excerpt · skills/linkfox-plugin-web-data-crawler/scripts/linkfox_paths.py (reported line 504)May include surrounding context.

python
req = Request(url, headers={"User-Agent": "LinkFox-Skill/2.0"})
    try:
        with urlopen(req, timeout=timeout) as resp:
            # 从 Content-Type 进一步修正扩展名
            if guessed_ext == "bin":
                ct = resp.headers.get("Content-Type", "")

Tainted flow: 'req' from os.environ.get (line 124, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · skills/linkfox-plugin-web-data-crawler/scripts/run_crawl.py (reported line 139)May include surrounding context.

python
)
    timeout = int(os.environ.get("LINKFOX_SYNC_TIMEOUT", "300"))
    try:
        with urllib.request.urlopen(req, timeout=timeout) as resp:
            result = json.loads(resp.read().decode("utf-8"))
            # startCrawlTask 返回格式: { taskId, status, data, errorMsg }
            # 适配上层调用方对 code/success 的判断

Tainted flow: 'req' from os.environ.get (line 274, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · skills/linkfox-file-upload/scripts/linkfox_paths.py (reported line 281)May include surrounding context.

python
headers={"Content-Type": "application/json", "Authorization": api_token},
        )
        try:
            with urlopen(req, timeout=30) as resp:
                body = json.loads(resp.read().decode())
            break
        except urllib.error.HTTPError as e:

Tainted flow: 'req' from os.environ.get (line 274, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · skills/linkfox-plugin-web-data-crawler/scripts/linkfox_paths.py (reported line 281)May include surrounding context.

python
headers={"Content-Type": "application/json", "Authorization": api_token},
        )
        try:
            with urlopen(req, timeout=30) as resp:
                body = json.loads(resp.read().decode())
            break
        except urllib.error.HTTPError as e:

Tainted flow: 'req' from os.environ.get (line 274, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · skills/linkfox-report-generator/scripts/linkfox_paths.py (reported line 281)May include surrounding context.

python
headers={"Content-Type": "application/json", "Authorization": api_token},
        )
        try:
            with urlopen(req, timeout=30) as resp:
                body = json.loads(resp.read().decode())
            break
        except urllib.error.HTTPError as e:

Tainted flow: 'req' from os.environ.get (line 274, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
93% confidence
Finding

download_media() performs arbitrary outbound HTTP(S) fetches from a caller-supplied URL and writes the response into the session workspace. Although it rejects non-HTTP schemes, it still enables SSRF-style access to internal services, cloud metadata endpoints, or other network-reachable resources if an attacker can influence the URL.

Content

Scanner excerpt · skills/linkfox-report-generator/scripts/linkfox_paths.py (reported line 524)May include surrounding context.

python
req = Request(url, headers={"User-Agent": "LinkFox-Skill/2.0"})
    try:
        with urlopen(req, timeout=timeout) as resp:
            # 从 Content-Type 进一步修正扩展名
            if guessed_ext == "bin":
                ct = resp.headers.get("Content-Type", "")

Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
92% confidence
Finding

The HTTP helper sends sensitive data, including login credentials, access tokens, refresh tokens, and user metadata, to a URL derived from environment-controlled base URLs. If an attacker can influence environment variables, the CLI can be redirected to an attacker-controlled endpoint and exfiltrate SMS codes, bearer tokens, and generated API keys. The skill context makes this more dangerous because the file performs authentication and key issuance unrelated to the stated ASIN analytics purpose, so there is no strong functional justification for allowing arbitrary endpoint overrides.

Content

Scanner excerpt · skills/linkfox-sif-asin-keywords/scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Tainted flow: 'req' from os.environ.get (line 244, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
91% confidence
Finding

The gateway client builds requests to a base URL sourced from environment variables and attaches the LinkFox API key in the Authorization header. An attacker who can set the environment can redirect billing/account requests to a malicious server and capture the API key and related account metadata. In this skill, that is especially risky because the same script also supports package purchase and order management, magnifying account and billing exposure.

Content

Scanner excerpt · skills/linkfox-sif-asin-keywords/scripts/onboarding.py (reported line 246)May include surrounding context.

python
headers["Content-Type"] = "application/json"
        req = Request(url, method=method, data=body_bytes, headers=headers)
        try:
            with urlopen(req, timeout=30) as resp:
                return json.loads(resp.read().decode())
        except urllib.error.HTTPError as e:
            status = e.code

Tainted flow: 'req' from os.environ.get (line 73, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
93% confidence
Finding

The request sent via urlopen includes multiple headers sourced directly from environment variables, and the destination base URL is also overrideable through LINKFOX_TOOL_GATEWAY. In an agent/runtime setting, environment variables are part of the trust boundary; allowing them to control outbound destination and transmitted identifiers can enable SSRF-like egress, exfiltration of API credentials/metadata, or routing sensitive requests to attacker-controlled infrastructure.

Content

Scanner excerpt · skills/linkfox-sif-asin-keywords/scripts/sif_asin_keywords.py (reported line 80)May include surrounding context.

python
method="POST",
    )
    try:
        with urlopen(req, timeout=150) as response:
            return json.loads(response.read().decode("utf-8"))
    except HTTPError as e:
        body = e.read().decode("utf-8") if e.fp else ""

Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
94% confidence
Finding

The POST destination is derived from environment-controlled base URLs and is used to transmit sensitive data including phone numbers, SMS codes, access tokens, refresh tokens, and generated API keys. If an attacker can influence environment variables, the script can be redirected to an attacker-controlled host, causing credential and token exfiltration under the guise of normal onboarding traffic.

Content

Scanner excerpt · skills/linkfox-sif-asin-summary/scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Tainted flow: 'req' from os.environ.get (line 244, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
91% confidence
Finding

The gateway request target is also environment-derived and receives authenticated requests containing the API key in the Authorization header, plus order and account operations. An attacker who can set the base URL can redirect these requests to a malicious server and capture the API key or manipulate billing-related operations.

Content

Scanner excerpt · skills/linkfox-sif-asin-summary/scripts/onboarding.py (reported line 246)May include surrounding context.

python
headers["Content-Type"] = "application/json"
        req = Request(url, method=method, data=body_bytes, headers=headers)
        try:
            with urlopen(req, timeout=30) as resp:
                return json.loads(resp.read().decode())
        except urllib.error.HTTPError as e:
            status = e.code

Tainted flow: 'req' from os.environ.get (line 73, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
96% confidence
Finding

The request sent via urlopen includes multiple environment-derived values in headers, including an API key and session/message metadata, and the destination host is also overrideable through LINKFOX_TOOL_GATEWAY. This creates a real exfiltration risk: if an attacker can influence environment variables, the script can be redirected to an attacker-controlled endpoint and will transmit credentials and request data there.

Content

Scanner excerpt · skills/linkfox-sif-asin-summary/scripts/sif_asin_summary.py (reported line 80)May include surrounding context.

python
method="POST",
    )
    try:
        with urlopen(req, timeout=150) as response:
            return json.loads(response.read().decode("utf-8"))
    except HTTPError as e:
        body = e.read().decode("utf-8") if e.fp else ""

Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The code builds request destinations from environment-controlled base URLs and then sends sensitive data such as phone numbers, SMS codes, access tokens, refresh tokens, generated API keys, and authorization headers to those endpoints. If an attacker can influence environment variables, they can redirect authentication and token-provisioning traffic to attacker-controlled servers and exfiltrate credentials.

Content

Scanner excerpt · skills/linkfox-sorftime-amazon-product-detail/scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Tainted flow: 'req' from os.environ.get (line 244, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The gateway request path uses an environment-derived base URL together with the API key in the Authorization header, so a modified environment can redirect billing, account, and order traffic to an attacker-controlled endpoint. This enables credential leakage and unauthorized exposure of account and payment workflow metadata.

Content

Scanner excerpt · skills/linkfox-sorftime-amazon-product-detail/scripts/onboarding.py (reported line 246)May include surrounding context.

python
headers["Content-Type"] = "application/json"
        req = Request(url, method=method, data=body_bytes, headers=headers)
        try:
            with urlopen(req, timeout=30) as resp:
                return json.loads(resp.read().decode())
        except urllib.error.HTTPError as e:
            status = e.code

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
skills/linkfox-plugin-web-data-crawler/scripts/run_crawl.py:110