T09 · Insecure Skill Coding Practices
- Location
scripts/report_cli.py:32- Finding
API Credential and Sensitive Query Data Transmitted over Plaintext HTTP
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
TrendScope appears to generate the promised public-opinion reports, but it sends API keys and report queries over unencrypted HTTP and creates unsafe HTML reports.
Review before installing. Do not use this skill with sensitive searches or production API keys unless the API endpoint is changed to verified HTTPS and generated reports safely escape all untrusted data. If used anyway, treat saved reports as sensitive files and be aware that opening HTML reports contacts a third-party CDN.
scripts/report_cli.py:32API Credential and Sensitive Query Data Transmitted over Plaintext HTTP
scripts/report_cli.py:659Stored HTML and JavaScript Injection in Generated Reports
查询关键词: {query} | 生成时间: {now}
scripts/report_cli.py:722Generated Reports Load Executable JavaScript from an External CDN without Integrity Verification
The script sends an API key loaded from environment/.env in an HTTP request header to a hard-coded plain-HTTP endpoint. Because the transport is unencrypted, any network observer or intermediary can recover the credential and query contents, enabling credential theft and unauthorized use of the reporting service.
try:
print("\n🔄 正在调用API...")
response = requests.post(
f"{API_BASE_URL}{REPORT_ENDPOINT}",
json=payload,
headers={"Content-Type": "application/json; charset=UTF-8", "x-api-key": DEFAULT_API_KEY},
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
在宿主环境设置 FEEDAX_REPORT_API_KEY,或使用项目内 .env(勿在对话中粘贴密钥):
cp .env.example .env
# 编辑 .env,设置 FEEDAX_REPORT_API_KEY=你的密钥
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
import requests
from dotenv import load_dotenv
# 加载 .env 文件(从脚本所在目录向上两级找到项目根目录)
SCRIPT_DIR = Path(__file__).parent
PROJECT_ROOT = SCRIPT_DIR.parent
load_dotenv(dotenv_path=PROJECT_ROOT / ".env", override=True)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
import requests
from dotenv import load_dotenv
# 加载 .env 文件(从脚本所在目录向上两级找到项目根目录)
SCRIPT_DIR = Path(__file__).parent
PROJECT_ROOT = SCRIPT_DIR.parent
load_dotenv(dotenv_path=PROJECT_ROOT / ".env", override=True)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 加载 .env 文件(从脚本所在目录向上两级找到项目根目录)
SCRIPT_DIR = Path(__file__).parent
PROJECT_ROOT = SCRIPT_DIR.parent
load_dotenv(dotenv_path=PROJECT_ROOT / ".env", override=True)
# 固定 API 根地址
API_BASE_URL = "http://221.6.15.90:18011"
The install trigger phrase is broad natural language ('帮我安装并学习这个技能'), which increases the chance an agent will invoke installation behavior from ordinary conversation rather than explicit user intent. In an agent ecosystem, overly generic activation language can cause unintended execution of repository installation or onboarding flows, especially when paired with a remote Git URL.
Without declared permissions the skill's intent is opaque and cannot be validated.
The document sets lang="zh-CN", which hard-codes a specific language/locale for the rendered report. Under the policy, locale restrictions should either offer user choice or be clearly justified as region-specific; this file does not include such an explanation or opt-in.
The skill transmits user queries and filters to an external service. External transmission is expected for this CLI, but it remains security-relevant because the destination is a fixed third-party IP over HTTP, so sensitive search terms and analysis parameters may be exposed in transit or sent to an endpoint users did not explicitly approve.
try:
print("\n🔄 正在调用API...")
response = requests.post(
f"{API_BASE_URL}{REPORT_ENDPOINT}",
json=payload,
headers={"Content-Type": "application/json; charset=UTF-8", "x-api-key": DEFAULT_API_KEY},
The tool automatically writes JSON, Markdown, and HTML reports containing returned article data, metadata, and request parameters to local disk without an explicit warning or consent step. In this skill context, the reports may include sensitive search topics, article URLs, author names, and summaries, creating unintended local data retention and exposure to other local users, backups, or sync services.
The trigger phrases are very broad and overlap with ordinary business terms like '报告', '分析报告', '市场分析', and '趋势分析'. This can cause unintended skill activation, leading the agent to process user inputs with this skill when the user did not intend to invoke it, potentially sending sensitive business queries or personal data to an external API.
The README states that reports are written to a Desktop directory but does not clearly warn users before execution that local files will be created automatically. This can lead to unexpected data persistence, privacy exposure, or clutter on shared systems, especially because report contents may contain sensitive query topics or analyzed content.
This JSON dataset is entirely labeled in Chinese, which can impose a specific language/locale on downstream consumers without any visible opt-in or alternative. Under the stated policy, forcing a specific language without user choice is a natural-language policy concern even in data/config files.
The template loads executable JavaScript from a third-party CDN at runtime, which introduces a supply-chain and integrity risk: if the CDN, package, or network path is compromised, malicious code will execute in every generated report. In the context of a report template, this is unnecessary external trust and expands the attack surface beyond static content generation.
The manifest description and top-level instructions present the skill entirely as a Chinese-language experience for generating reports, with no indication that users may choose another language or locale. This is a natural-language policy concern when a skill implicitly enforces a single language without opt-in or justification.
L025-L036 将未配置条件和用户指引都限定为 FEEDAX_REPORT_API_KEY,且 manifest 的 requires.env 也只声明该变量;但 L543 又说明 CLI 会尝试读取旧名 FEEDAX_SEARCH_API_KEY。虽然这不一定是安全问题,但属于文档与实现意图描述不一致,可能导致运维配置预期混乱。
L062-L064 说明返回摘要并将完整报告保存到桌面目录;L365-L366 仅明确列出 JSON 和 Markdown 文件,而 L520-L533 又声明会生成可视化 HTML 报告。该技能文件内部的输出格式说明存在主动不一致,容易让调用者误判实际产物类型。
No suspicious patterns detected.