Back to skill

Security audit

多网盘统一下载

Security checks for vulnerabilities and agentic risk

Overview

This is a plausible cloud-drive downloader, but its web and Feishu control features can start downloads or change tasks without authentication if exposed beyond localhost.

Review before installing. Keep pan serve and the Feishu bridge bound to localhost or behind an authenticated tunnel/reverse proxy, do not expose them directly on a LAN or the public Internet, and avoid enabling remote web control unless you can add access control and quotas. Treat the Chrome extension and clipboard monitor as link-forwarding automation that can trigger downloads from copied or selected text.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/pan.py:3633
Finding

Unauthenticated Download and Task-Control API Allows Remote Operations

Content
View full analysis

Vulnerability Details

File Location: scripts/pan.py, lines 3108-3190 and 3633-3717
Vulnerability Type: Missing authentication and authorization on state-changing HTTP endpoints
Risk Level: High

Vulnerable Code

python
def _apply_task_action(reports_dir, task_id, action):
    """Apply pause/resume/delete/retry to a task control record."""
    path, rec = _locate_task_control(reports_dir, task_id)
    if not path or not rec:
        return False, "Task %s not found" % task_id

    recs = read_task_records(path)
    now = datetime.now().strftime("%Y-%m-%dT%H:%M:%S%z")
    if action == "pause":
        if rec.get("state") != "running":
            return False, "Only running tasks can be paused"
        rec["state"] = "paused"
    elif action == "resume":
        if rec.get("state") != "paused":
            return False, "Only paused tasks can be resumed"
        rec["state"] = "running"
    elif action == "delete":
        if rec.get("state") == "running":
            rec["state"] = "cancelled"
            rec["updated"] = now
            rec["finished"] = rec.get("finished") or now
            _atomic_write_json(path, {"schema": 1, "tasks": recs})
            return True, "Cancellation and deletion marker sent"
        recs.pop(task_id, None)
        _atomic_write_json(path, {"schema": 1, "tasks": recs})
        return True, "Task record deleted"
    elif action == "retry":
        if rec.get("state") not in ("done", "failed", "cancelled"):
            return False, "Only completed tasks can be retried"
        pid, err = _spawn_retry_task(rec)
        if err:
            return False, err
python
def _spawn_download_task(url, pwd="", to="", engine="", tier="", path=""):
    """Start pan get --live in the background."""
    if not url or not url.strip():
        return "", "url is empty"
    argv = [sys.executable, str(Path(__file__).resolve()),

...[truncated 5441 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require authentication for all API endpoints, using an unguessable bearer token, mutually authenticated TLS, or an authenticated reverse proxy.
  2. Refuse non-loopback binding unless authentication is explicitly configured and validated.
  3. Apply authorization per task so callers can only view or modify tasks they created.
  4. Remove task mutations from GET routes and require authenticated POST requests with CSRF protection.
  5. Restrict to destinations to canonical paths beneath one or more configured download roots. Resolve symbolic links and reject paths that escape those roots.
  6. Apply allowlists to selectable engines, tiers, and remote paths.
  7. Add request-body size limits, rate limits, concurrent-job limits, and storage quotas.
  8. Avoid exposing sensitive report fields and local filesystem paths to unauthenticated clients.
  9. Bind remote deployments to 127.0.0.1 by default and require access through an authenticated SSH tunnel or secured reverse proxy.

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/feishu_bot.py:64
Finding

Unsigned Feishu Callback Events Can Trigger Unauthorized Downloads

Content
View full analysis

Vulnerability Details

File Location: scripts/feishu_bot.py, lines 64-97, 111-126, and 133-144
Vulnerability Type: Missing webhook signature and sender verification
Risk Level: High

Vulnerable Code

python
def handle_event(body: dict, target: str):
    body = body or {}
    challenge = body.get("challenge")
    if challenge:
        return True, {"challenge": challenge}, [
            "Feishu URL verification passed"
        ]

    event = body.get("event") or {}
    msg = event.get("message") or {}
    content = msg.get("content") or "{}"
    text = ""
    try:
        content_obj = (
            json.loads(content)
            if isinstance(content, str)
            else (content or {})
        )
        text = (
            content_obj.get("text")
            or content_obj.get("content")
            or ""
        )
    except (ValueError, TypeError):
        text = str(content)

    if not text:
        text = str(
            event.get("text") or body.get("text") or ""
        )

    urls = extract_urls(text)
    if not urls:
        return True, None, [
            "Message received but no downloadable URL found"
        ]

    msgs = []
    for url in urls:
        ok, info = forward_download(
            url, extract_pwd(text), target
        )
        msgs.append(
            ("Download started: %s\n%s" %
             (url, json.dumps(info, ensure_ascii=False)))
            if ok else
            ("Download failed: %s" %
             info.get("error", "Download start failed"))
        )
    return True, None, msgs
python
class FeishuHandler(BaseHTTPRequestHandler):
    target = DEFAULT_TARGET

    def do_POST(self):
        length = int(
            self.headers.get("Content-Length", 0) or 0
        )
        raw = self.rfile.read(length) if length else b""
        try:
            body = json.loads(
...[truncated 3272 chars]
Remediation
View remediation

Remediation Suggestions

  1. Validate Feishu callback signatures and verification tokens before parsing or processing event data.
  2. If encrypted callbacks are enabled, authenticate and decrypt the callback envelope using the configured Encrypt Key and reject invalid envelopes.
  3. Verify the application ID, tenant identity, event type, and permitted sender or chat before forwarding a download.
  4. Validate timestamps and store event IDs temporarily to prevent replay attacks.
  5. Reject unexpected callback paths and HTTP methods rather than accepting POST requests globally.
  6. Enforce strict request-body size limits, URL-count limits, rate limits, and concurrent-download quotas.
  7. Place the callback behind TLS and an authenticated ingress or API gateway.
  8. Authenticate requests from the Feishu bridge to pan serve with a dedicated, least-privileged service token.
  9. Keep the downloader bound to loopback and do not expose its control API directly to the callback network.
  10. Consider requiring explicit approval before a callback-originated download is started.
Vulnerability Patterns
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (211)

Tainted flow: 'value' from sys.stdin.read (line 3936, user input) → subprocess.run (code execution)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

External input (network, user) flows to a code execution sink. This enables remote code execution or command injection.

Content

Scanner excerpt · scripts/pan.py (reported line 814)May include surrounding context.

python
def _macos_keychain_store(name, value):
    if not (SECURITY_BIN and Path(SECURITY_BIN).exists()):
        raise RuntimeError("macOS security 命令不可用,拒绝保存明文;请在正常终端执行")
    proc = subprocess.run(
        [SECURITY_BIN, "add-generic-password", "-U", "-a", name, "-s", KEYCHAIN_SERVICE, "-w"],
        input=value + "\n" + value + "\n", text=True, capture_output=True,
    )

Tainted flow: 'value' from sys.stdin.read (line 3936, user input) → subprocess.run (code execution)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

External input (network, user) flows to a code execution sink. This enables remote code execution or command injection.

Content

Scanner excerpt · scripts/pan.py (reported line 943)May include surrounding context.

python
def _secret_tool_store(name, value):
    proc = subprocess.run(
        ["secret-tool", "store", "--label", APP + " " + name, "service", APP, "account", name],
        input=value, text=True, capture_output=True,
    )

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill description understates a broad administrative feature set including credential storage operations, dependency installation, SSH/SCP deployment, web UI serving, task control, webhook notifications, and MCP integration. This mismatch matters because users and orchestrating agents may grant downloader-level trust to what is effectively a remote-management and automation tool with substantial local and network-side effects.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill description understates a broad administrative feature set including credential storage operations, dependency installation, SSH/SCP deployment, web UI serving, task control, webhook notifications, and MCP integration. This mismatch matters because users and orchestrating agents may grant downloader-level trust to what is effectively a remote-management and automation tool with substantial local and network-side effects.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description understates a broad administrative feature set including credential storage operations, dependency installation, SSH/SCP deployment, web UI serving, task control, webhook notifications, and MCP integration. This mismatch matters because users and orchestrating agents may grant downloader-level trust to what is effectively a remote-management and automation tool with substantial local and network-side effects.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill description understates a broad administrative feature set including credential storage operations, dependency installation, SSH/SCP deployment, web UI serving, task control, webhook notifications, and MCP integration. This mismatch matters because users and orchestrating agents may grant downloader-level trust to what is effectively a remote-management and automation tool with substantial local and network-side effects.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

md
典型用法:任何 agent 拿到用户提供的网盘地址后调用 `scripts/pan.py get "<链接>"`;需要登录时只给出本机授权步骤,账号密码由用户在本机系统凭据库保存,不进入聊天、不进配置文件、不写日志。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

md
典型用法:任何 agent 拿到用户提供的网盘地址后调用 `scripts/pan.py get "<链接>"`;需要登录时只给出本机授权步骤,账号密码由用户在本机系统凭据库保存,不进入聊天、不进配置文件、不写日志。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
典型用法:任何 agent 拿到用户提供的网盘地址后调用 `scripts/pan.py get "<链接>"`;需要登录时只给出本机授权步骤,账号密码由用户在本机系统凭据库保存,不进入聊天、不进配置文件、不写日志。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

md
典型用法:任何 agent 拿到用户提供的网盘地址后调用 `scripts/pan.py get "<链接>"`;需要登录时只给出本机授权步骤,账号密码由用户在本机系统凭据库保存,不进入聊天、不进配置文件、不写日志。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

md
典型用法:任何 agent 拿到用户提供的网盘地址后调用 `scripts/pan.py get "<链接>"`;需要登录时只给出本机授权步骤,账号密码由用户在本机系统凭据库保存,不进入聊天、不进配置文件、不写日志。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

md
典型用法:任何 agent 拿到用户提供的网盘地址后调用 `scripts/pan.py get "<链接>"`;需要登录时只给出本机授权步骤,账号密码由用户在本机系统凭据库保存,不进入聊天、不进配置文件、不写日志。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

md
典型用法:任何 agent 拿到用户提供的网盘地址后调用 `scripts/pan.py get "<链接>"`;需要登录时只给出本机授权步骤,账号密码由用户在本机系统凭据库保存,不进入聊天、不进配置文件、不写日志。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

md
典型用法:任何 agent 拿到用户提供的网盘地址后调用 `scripts/pan.py get "<链接>"`;需要登录时只给出本机授权步骤,账号密码由用户在本机系统凭据库保存,不进入聊天、不进配置文件、不写日志。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

md
典型用法:任何 agent 拿到用户提供的网盘地址后调用 `scripts/pan.py get "<链接>"`;需要登录时只给出本机授权步骤,账号密码由用户在本机系统凭据库保存,不进入聊天、不进配置文件、不写日志。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

md
典型用法:任何 agent 拿到用户提供的网盘地址后调用 `scripts/pan.py get "<链接>"`;需要登录时只给出本机授权步骤,账号密码由用户在本机系统凭据库保存,不进入聊天、不进配置文件、不写日志。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

md
典型用法:任何 agent 拿到用户提供的网盘地址后调用 `scripts/pan.py get "<链接>"`;需要登录时只给出本机授权步骤,账号密码由用户在本机系统凭据库保存,不进入聊天、不进配置文件、不写日志。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
典型用法:任何 agent 拿到用户提供的网盘地址后调用 `scripts/pan.py get "<链接>"`;需要登录时只给出本机授权步骤,账号密码由用户在本机系统凭据库保存,不进入聊天、不进配置文件、不写日志。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

md
典型用法:任何 agent 拿到用户提供的网盘地址后调用 `scripts/pan.py get "<链接>"`;需要登录时只给出本机授权步骤,账号密码由用户在本机系统凭据库保存,不进入聊天、不进配置文件、不写日志。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

md
典型用法:任何 agent 拿到用户提供的网盘地址后调用 `scripts/pan.py get "<链接>"`;需要登录时只给出本机授权步骤,账号密码由用户在本机系统凭据库保存,不进入聊天、不进配置文件、不写日志。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

md
典型用法:任何 agent 拿到用户提供的网盘地址后调用 `scripts/pan.py get "<链接>"`;需要登录时只给出本机授权步骤,账号密码由用户在本机系统凭据库保存,不进入聊天、不进配置文件、不写日志。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

md
典型用法:任何 agent 拿到用户提供的网盘地址后调用 `scripts/pan.py get "<链接>"`;需要登录时只给出本机授权步骤,账号密码由用户在本机系统凭据库保存,不进入聊天、不进配置文件、不写日志。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

md
典型用法:任何 agent 拿到用户提供的网盘地址后调用 `scripts/pan.py get "<链接>"`;需要登录时只给出本机授权步骤,账号密码由用户在本机系统凭据库保存,不进入聊天、不进配置文件、不写日志。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 81)May include surrounding context.

md
典型用法:任何 agent 拿到用户提供的网盘地址后调用 `scripts/pan.py get "<链接>"`;需要登录时只给出本机授权步骤,账号密码由用户在本机系统凭据库保存,不进入聊天、不进配置文件、不写日志。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 82)May include surrounding context.

md
典型用法:任何 agent 拿到用户提供的网盘地址后调用 `scripts/pan.py get "<链接>"`;需要登录时只给出本机授权步骤,账号密码由用户在本机系统凭据库保存,不进入聊天、不进配置文件、不写日志。

Static analysis

Detected: suspicious.dynamic_code_execution, suspicious.install_untrusted_source

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/self_test.py:26

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
extensions/chrome/manifest.json:7