Back to skill

Security audit

睿观-图形商标检测

Security checks for vulnerabilities and agentic risk

Overview

This skill performs the advertised trademark-image check, but it also includes under-scoped public uploads, silent feedback reporting, credential onboarding, and payment/order flows that users should review carefully.

Install only after reviewing the data flows. Use non-confidential images unless you are comfortable with a public 24-hour image URL and LinkFox processing. Avoid running the built-in login, billing, or payment commands unless you intentionally want the agent involved in those flows. Verify LINKFOX_* endpoint environment variables are not overridden, and consider using a limited API key.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:158
Finding

Silent External Disclosure of User Intent and Execution Context Through Feedback Telemetry

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/ruiguan_trademark_graphic_detection.py:37
Finding

Environment-Controlled API Endpoints Can Exfiltrate Credentials and Sensitive Requests

Content
View full analysis
str: """网关基础地址:env LINKFOX_TOOL_GATEWAY 优先,缺省回退正式地址。""" return (os.environ.get("LINKFOX_TOOL_GATEWAY") or "https://tool-gateway.linkfox.com").rstrip("/") def get_api_url(): sys.path.insert(0, os.path.join(os.path.dirname(os.path.abspath(__file__)), "..", "..", "_shared")) return get_api_base() + API_PATH ``` ```python def call_api(params): api_url = get_api_url() api_key = get_api_key() data = json.dumps(params).encode("utf-8") headers = { "Authorization": api_key, "Content-Type": "application/json", "User-Agent": "LinkFox-Skill/2.0", "SESSION_ID": os.environ.get("SESSION_ID", ""), "MESSAGE_ID": os.environ.get("MESSAGE_ID", ""), "MODE_ID": os.environ.get("MODE_ID", ""), "APP_NAME": os.environ.get("APP_NAME", ""), } req = Request( api_url, data=data, headers=headers, method="POST", ) try: with urlopen(req, timeout=150) as response: return json.loads(response.read().decode("utf-8")) ``` From the upload client: ```python _API_BASE = (os.environ.get("LINKFOX_TOOL_GATEWAY") or "https://tool-gateway.linkfox.com").rstrip("/") PRESIGN_URL = f"{_API_BASE}/oss/file/presignedPut" ``` ```python req = Request( PRESIGN_URL, data=data, headers={ "Authorization": api_key, "Content-Type": "application/json", "User-Agent": "LinkFox-Skill/1.0", "SESSION_ID": os.environ.get("SESSION_ID", ""), "MESSAGE_ID": os.environ.get("MESSAGE_ID", ""), "MODE_ID": os.environ.get("MODE_ID", ""), "APP_NAME": os ...[truncated 3355 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/upload_image.py:47
Finding

Unvalidated Presigned Upload URL Can Redirect Local Image Contents

Content
View full analysis
str: """Request a presigned PUT URL from the OSS gateway.""" api_key = get_api_key() data = json.dumps({ "contentType": content_type, "fileExtension": file_extension, }).encode("utf-8") req = Request( PRESIGN_URL, data=data, headers={ "Authorization": api_key, "Content-Type": "application/json", "User-Agent": "LinkFox-Skill/1.0", "SESSION_ID": os.environ.get("SESSION_ID", ""), "MESSAGE_ID": os.environ.get("MESSAGE_ID", ""), "MODE_ID": os.environ.get("MODE_ID", ""), "APP_NAME": os.environ.get("APP_NAME", ""), }, method="POST", ) try: with urlopen(req, timeout=150) as response: result = json.loads(response.read().decode("utf-8")) except HTTPError as e: body = e.read().decode("utf-8") if e.fp else "" print(f"Failed to get presigned URL: HTTP {e.code}: {e.reason}\n{body}", file=sys.stderr) sys.exit(1) except URLError as e: print(f"Connection failed: {e.reason}", file=sys.stderr) sys.exit(1) if result.get("errcode") != 200: print(f"API error: {result.get('errmsg', 'unknown error')}", file=sys.stderr) sys.exit(1) return result["url"] ``` ```python def upload_file(presigned_url: str, file_path: str, content_type: str): """Upload the local file to the presigned OSS URL via HTTP PUT.""" with open(file_path, "rb") as f: file_data = f.read() req = Request( presigned_url, data=file_data, headers={ "Content-Type": content_type, "x-oss-object-acl": "public-read", ...[truncated 1891 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/ruiguan_trademark_graphic_detection.py:250
Finding

Unsanitized Session Identifier Allows Filesystem Path Traversal

Content
View full analysis
str: """优先 env SESSION_ID;缺省按 HHMMSS-<6 hex> 生成(同一进程内稳定)。""" env = os.environ.get("SESSION_ID") if env: return env.strip() if "_auto" not in _SESSION_CACHE: _SESSION_CACHE["_auto"] = ( time.strftime("%H%M%S", time.localtime(ts)) + "-" + secrets.token_hex(3) ) return _SESSION_CACHE["_auto"] def _ensure_session(ts: float) -> tuple[str, str]: """返回 (linkfox_root, session_dir);session_dir 一定存在。""" date_str = time.strftime("%Y-%m-%d", time.localtime(ts)) sid = _session_id(ts) root = _linkfox_root() session_dir = os.path.join(root, date_str, sid) os.makedirs(session_dir, exist_ok=True) _ensure_meta(root, session_dir, date_str, sid, ts) return root, session_dir ``` From the onboarding script: ```python def session_dir() -> str: ts = time.time() sid = (os.environ.get("SESSION_ID") or "").strip() or ( time.strftime("%H%M%S", time.localtime(ts)) + "-" + secrets.token_hex(3)) path = os.path.join(_linkfox_root(), time.strftime("%Y-%m-%d", time.localtime(ts)), sid) os.makedirs(path, exist_ok=True) return path ``` ### Technical Analysis `SESSION_ID` is treated as a trusted directory name. The code does not reject: - Absolute paths. - `..` traversal components. - Forward or backward path separators. - Platform-specific drive or UNC paths. - Empty or special filesystem names. In Python, an absolute final component passed to `os.path.join` can discard preceding path components. Relative traversal components can escape the intended date and `linkfox` directories after path normalization. The trademark script wri ...[truncated 1439 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/onboarding.py:163
Finding

Unpinned Runtime Package Installation Guidance Creates Supply-Chain Risk

Content
View full analysis
dict: try: import qrcode except ImportError: err = "缺少 qrcode 依赖,请运行: pip install qrcode pillow" print(f"{TAG} render_qr: {err}", file=sys.stderr) return {"png_path": None, "ascii_qr": None, "error": err} ``` ```python def _require_requests() -> None: if requests is None: raise RuntimeError("缺少 requests 依赖,请运行: pip install requests") ``` ### Technical Analysis When dependencies are absent, the script instructs the user to install mutable package names from the active pip index. The commands do not provide: - Exact approved versions. - Package hashes. - A lockfile. - A trusted package-index URL. - An isolated virtual environment. - Signature or provenance verification. Python package installation may execute package build or installation code with the invoking user's privileges. The effective source also depends on local pip configuration and environment variables, which may redirect package resolution to an untrusted index. The named packages are legitimate well-known packages; the finding is not that the source contains a known malicious dependency. The risk arises from unconstrained resolution and installation guidance. ### Attack Path 1. The user runs an onboarding operation on a system where `requests`, `qrcode`, or Pillow is missing. 2. The script displays an unpinned `pip install` command. 3. The user runs the command in an environment configured to use a compromised or attacker-controlled index, or resolves a future compromised package release. 4. Pip downloads and installs the selected artifacts. 5. Package build or installation logic executes with the user's privileges. 6. Malicious package code can access files, credentials, and network resou ...[truncated 480 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (33)

Tainted flow: 'url' from os.environ.get (line 235, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The POST destination is derived from environment-controlled base URLs, and the request can carry sensitive data including SMS login details, access tokens, refresh tokens, and API-token provisioning traffic. If an attacker can influence environment variables, they can redirect these authenticated requests to attacker-controlled infrastructure, causing credential exfiltration and account compromise.

Content

Scanner excerpt · scripts/onboarding.py (reported line 196)May include surrounding context.

python
except RuntimeError as e:
        return {"_error": str(e)}
    try:
        r = requests.post(url, json=body or {}, headers=headers, timeout=timeout)
        return r.json()
    except Exception as e:
        body_text = ""

Tainted flow: 'req' from os.environ.get (line 244, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
94% confidence
Finding

The gateway URL is also environment-derived and is used with an Authorization header containing the agent API key. An attacker who can set the environment can redirect these urllib requests to a malicious server and harvest API keys, user/account metadata, and order operations, effectively turning the script into a credential exfiltration client.

Content

Scanner excerpt · scripts/onboarding.py (reported line 246)May include surrounding context.

python
headers["Content-Type"] = "application/json"
        req = Request(url, method=method, data=body_bytes, headers=headers)
        try:
            with urlopen(req, timeout=30) as resp:
                return json.loads(resp.read().decode())
        except urllib.error.HTTPError as e:
            status = e.code

Tainted flow: 'req' from os.environ.get (line 73, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
96% confidence
Finding

The request sent via urlopen includes multiple headers populated directly from environment variables, and the destination base URL is also overrideable via LINKFOX_TOOL_GATEWAY. In an agent/runtime context, environment variables are part of the trust boundary; allowing unvalidated environment-controlled routing and metadata exfiltration can send API keys, session identifiers, and user-derived request data to an attacker-controlled endpoint via SSRF-style redirection or misconfiguration.

Content

Scanner excerpt · scripts/ruiguan_trademark_graphic_detection.py (reported line 80)May include surrounding context.

python
method="POST",
    )
    try:
        with urlopen(req, timeout=150) as response:
            return json.loads(response.read().decode("utf-8"))
    except HTTPError as e:
        body = e.read().decode("utf-8") if e.fp else ""

Tainted flow: 'req' from os.environ.get (line 57, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/upload_image.py (reported line 73)May include surrounding context.

python
)

    try:
        with urlopen(req, timeout=150) as response:
            result = json.loads(response.read().decode("utf-8"))
    except HTTPError as e:
        body = e.read().decode("utf-8") if e.fp else ""

Tainted flow: 'req' from os.environ.get (line 57, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

The code uploads the full image bytes to a presigned URL returned by a prior API call and does not validate the destination host, scheme, or scope of that URL before sending user content. If the presign service or its configuration is compromised, sensitive user images could be exfiltrated to an arbitrary endpoint, which is especially risky because the skill handles product images that may be private or commercially sensitive.

Content

Scanner excerpt · scripts/upload_image.py (reported line 106)May include surrounding context.

python
)

    try:
        with urlopen(req, timeout=120) as response:
            if response.status not in (200, 201):
                print(f"Upload failed with status: {response.status}", file=sys.stderr)
                sys.exit(1)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented purpose promises trademark/logo detection, but the observed implementation path includes only image upload and public URL generation, not actual screening or infringement analysis. This mismatch can mislead users into disclosing sensitive product images under the false impression that analysis is occurring, while the real action is external publication of the asset.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented purpose promises trademark/logo detection, but the observed implementation path includes only image upload and public URL generation, not actual screening or infringement analysis. This mismatch can mislead users into disclosing sensitive product images under the false impression that analysis is occurring, while the real action is external publication of the asset.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The local-image workflow instructs the agent to upload a user’s local file and obtain a public URL, but it does not require a clear warning that the image will become externally accessible. Product images can contain confidential branding, unreleased designs, or other sensitive business information, so silent publication creates a concrete disclosure risk.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 113)May include surrounding context.

md
- **响应401或402状态码**
- **响应提示算力或余额不足**:消息含"算力余额不足/计费不足/余额不足/quota exceeded/insufficient balance/套餐到期/需充值/请充值",或类似含义的内容。

## Display Rules

1. **Present results clearly**: Show detection results in a well-structured table including trademark image, similarity score, trademark name, status, registration office, Nice classification, applicant name, and key dates
2. **Highlight high-risk matches**: When similarity is above 0.8, explicitly warn the user about high infringement risk

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/onboarding.md (reported line 14)May include surrounding context.

md
示 JSON 里的 phone/agreements
   - 收到验证码后:`python scripts/onboarding.py login <phone> <code>`
   - 拿到 `api_key` 后把下面三平台配置转发给用户,提示重启会话生效:
     - Windows PowerShell(永久):`setx LINKFOX_AGENT_API_KEY "<key>"`
     - macOS zsh:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.zshrc && source ~/.zshrc`
     - Linux bash:`echo 'export LINKFOX_AGENT_API_KEY="<key>"' >> ~/.bashrc && source ~/.bashrc`
     - 变量名 `LINKFOX_AGENT_API_KEY`(主推)或 `LINKFOXAGENT_API_KEY`(老规范)任一即可

**billing 场景**:`errcode=402` 或消息含 `算力/余额/quota/insufficient/充值/套餐到期`。
- `python scripts/onboarding.py list-plans` → 有 AskUserQuestion 就弹菜单,否则输出编号清单让用户选
- 校验 `plan_id` ∈ 清单、支付方式 ∈ 该套餐 `available_methods`(通常 `wechat/alipay`)
- `python scripts/onboarding.py order <plan_id> <method>` → 展示优先级 PNG

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The implemented behavior is materially different from the declared skill purpose: instead of trademark/logo detection, the file performs account onboarding, SMS login, API key issuance, plan retrieval, and payment flows. This mismatch is dangerous because users or orchestrators may invoke a seemingly low-risk trademark-analysis skill while it actually handles credentials and billing actions, expanding attack surface and enabling deceptive capability hiding.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Embedding order creation, payment method selection, and QR-code payment initiation inside a trademark-detection skill introduces unjustified financial capabilities. In this context, the mismatch makes the code more dangerous because it could trigger or facilitate purchases under the guise of an image-risk analysis workflow.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script collects phone numbers, sends SMS verification codes, logs users in, and generates or retrieves API credentials, none of which are necessary for graphic trademark screening itself. This is especially risky in this skill context because users may provide sensitive authentication data to a tool whose advertised purpose gives no reason to expect credential handling.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The docstring states output is restricted to the current directory and explicitly forbids /tmp, but the implementation silently falls back to the home directory and system temp directory. This expands the data exposure surface: sensitive trademark-analysis responses may be written to less controlled locations, including shared or ephemeral storage, contrary to operator expectations and potentially bypassing workspace data handling controls.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares no explicit tool scope while its documented behavior relies on environment access, file writes, and network operations. In an agent setting, missing scope boundaries can let the skill invoke more capability than users would reasonably expect, increasing the chance of unintended data access, exfiltration, or persistence.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation criteria are broad enough to trigger on generic trademark-risk conversations, even when the user did not clearly request image-based trademark screening. Overbroad triggering increases the chance that the skill will run in the wrong context and collect or transmit unnecessary data.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill directs full API responses to be persistently written into session-scoped files in the working directory. Persistent natural-language logs can retain sensitive commercial data, identifiers, or analysis results beyond the user’s expectations and expose them to other tools, users, or later tasks in the same environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The API sends user-provided image URLs, product titles, and possible trademark names to an external endpoint, but the documentation does not instruct the agent to warn users or obtain consent for third-party transfer. Because product images and metadata may contain confidential product, branding, or seller information, silent transmission can create privacy, confidentiality, and compliance risks.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 79)May include surrounding context.

}

text

## curl 示例

```bash
curl -X POST https://tool-gateway.linkfox.com/ruiguan/trademarkGraphicDetection \

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation includes a separate feedback API that is unrelated to the trademark-detection operation. In an agent skill context, this creates an additional outbound channel that could transmit user content or operational details to a different service, increasing the risk of unintended data disclosure or misuse if invoked without clear user consent and tight scoping.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file documents account onboarding, SMS-based registration, API key setup, and payment-plan purchase flows that are operationally unrelated to a trademark image detection skill's stated purpose. This scope expansion increases the attack surface by enabling collection of credentials, phone numbers, and payment interactions inside a skill that users would not expect to handle onboarding or billing.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented ability to register accounts via phone verification, log users in, and create payment orders is a high-risk capability that is not justified by the trademark detection use case. In the context of this skill, these instructions could be abused to solicit sensitive data and initiate financial actions under the guise of resolving service issues.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The instructions tell the user to provide a phone number to a script-driven registration flow and handle SMS verification, but provide no privacy notice, consent language, retention policy, or warning about how the number and code will be processed. This creates unnecessary privacy and social-engineering risk, especially because the skill's primary purpose is image trademark analysis, not identity onboarding.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring presents the CLI entirely in Chinese and hard-codes China-specific assumptions such as domestic phone numbers and area code +86, with no indication that users can choose another language or locale. This is a natural-language policy concern because the skill appears to require a specific language/locale rather than offering an opt-in or documenting a justified regional-only scope.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The session and QR utilities create writable directories and persist PNG QR codes to disk for checkout flows. Local file output for payment artifacts is not an obvious requirement of a skill whose stated purpose is trademark/logo comparison and infringement-risk analysis.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.