T09 · Insecure Skill Coding Practices
- Location
scripts/report_cli.py:29- Finding
API Credential and Sensitive Query Data Transmitted over Plaintext HTTP
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly matches its stated report-generation purpose, but it sends API keys and report queries over plaintext HTTP and creates unsafe HTML reports, so users should review it before installing.
Install only if you trust the Feedax service and accept that API keys, search terms, and filters are currently sent over unencrypted HTTP. Avoid sensitive queries, prefer json-only output when possible, be cautious opening generated HTML reports, and ask the publisher to switch to HTTPS, escape HTML output, validate links, bundle or integrity-protect chart JavaScript, and narrow auto-trigger terms.
scripts/report_cli.py:29API Credential and Sensitive Query Data Transmitted over Plaintext HTTP
scripts/report_cli.py:640Stored Script Injection in Generated HTML Reports
Search query: {query} | Generated at: {now}
scripts/report_cli.py:722Generated Reports Execute Third-Party CDN JavaScript without Integrity Verification
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
try:
print("\n🔄 正在调用API...")
response = requests.post(
f"{API_BASE_URL}{REPORT_ENDPOINT}",
json=payload,
headers={"Content-Type": "application/json; charset=UTF-8", "x-api-key": DEFAULT_API_KEY},
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
在宿主环境设置 FEEDAX_REPORT_API_KEY,或使用项目内 .env(勿在对话中粘贴密钥):
cp .env.example .env
# 编辑 .env,设置 FEEDAX_REPORT_API_KEY=你的密钥
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
import requests
from dotenv import load_dotenv
# 加载 .env 文件(从脚本所在目录向上两级找到项目根目录)
SCRIPT_DIR = Path(__file__).parent
PROJECT_ROOT = SCRIPT_DIR.parent
load_dotenv(dotenv_path=PROJECT_ROOT / ".env", override=True)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
import requests
from dotenv import load_dotenv
# 加载 .env 文件(从脚本所在目录向上两级找到项目根目录)
SCRIPT_DIR = Path(__file__).parent
PROJECT_ROOT = SCRIPT_DIR.parent
load_dotenv(dotenv_path=PROJECT_ROOT / ".env", override=True)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 加载 .env 文件(从脚本所在目录向上两级找到项目根目录)
SCRIPT_DIR = Path(__file__).parent
PROJECT_ROOT = SCRIPT_DIR.parent
load_dotenv(dotenv_path=PROJECT_ROOT / ".env", override=True)
# 固定 API 根地址
API_BASE_URL = "http://221.6.15.90:18011"
Referenced artifact was not completely inspected
- `assets/area_codes.json` - 国标区域编码数据
All user-facing instructions and descriptions in the file are presented only in Chinese, and the document does not indicate that the language is optional or region-specific. Under SQP-3, forcing a specific language without user opt-in is a natural-language policy concern.
Without declared permissions the skill's intent is opaque and cannot be validated.
The template hard-codes lang="zh-CN", which imposes a specific language/locale on all rendered output. Under the policy rule, locale constraints should either offer user opt-in/choice or be explicitly documented as justified for a region-specific tool; that justification is not present in this file.
The manifest describes a skill that automatically generates professional public-opinion analysis reports according to user needs across brand, market, competitor, and trend scenarios. This file is instead a prefilled HTML report for a specific domain and case set ('江苏省医疗卫生舆情分析报告') with fixed dates, metrics, keywords, risk conclusions, and article entries, indicating a narrowly hard-coded output rather than a general-purpose report generator.
The tool's docstring, help text, status messages, and generated report content are all hard-coded in Chinese, and the HTML output explicitly sets lang="zh-CN". There is no indication that users can select another language or that the skill is intentionally limited to a Chinese-only regional context.
The manifest frames this skill as a舆情趋势洞察/report-generation capability. While calling an API is expected for that purpose, reading secrets from a project .env file and environment variables introduces a separate credential-discovery/access capability that is not described as part of the skill's scope.
The CLI sends user queries, filters, and an API key to a hard-coded remote endpoint over plain HTTP. Because there is no transport encryption, anyone on the network path could observe or tamper with sensitive query content and steal the API key, which is especially concerning for a tool handling potentially sensitive monitoring topics.
The manifest describes automatic generation of professional public-opinion analysis reports, but does not disclose that the implementation persistently saves JSON, Markdown, and HTML outputs to a desktop directory. Persisting artifacts to disk is a broader behavior than transient report generation and can affect user data handling expectations.
This file performs external transmission of user-provided query data and report filters to a remote server, and in this implementation the destination is a fixed plaintext HTTP endpoint. The skill context makes this more dangerous because report queries may reveal sensitive investigations, brands, incidents, or monitoring interests, and the lack of secure transport enables interception or manipulation.
try:
print("\n🔄 正在调用API...")
response = requests.post(
f"{API_BASE_URL}{REPORT_ENDPOINT}",
json=payload,
headers={"Content-Type": "application/json; charset=UTF-8", "x-api-key": DEFAULT_API_KEY},
The tool persists report outputs containing returned article content and request parameters to local disk by default, without an explicit warning or consent step. In the context of a sentiment/intelligence reporting skill, those files may contain sensitive keywords, monitoring targets, and collected content that can later be exposed through local compromise, backups, or shared workstations.
The trigger list is very broad and overlaps with common business terms such as '报告', '分析报告', '市场分析', and '趋势分析'. That increases the chance the skill activates in unrelated contexts and causes unintended external API queries and local report generation, potentially sending user-provided content to a third party and writing files without clear user intent.
The skill writes full reports to local storage, but the description and activation context do not prominently warn users about persistent file output. In a skill that handles potentially sensitive search queries and aggregated results, undisclosed local storage increases privacy and data handling risk, especially on shared machines or managed agent hosts.
This markdown file states that JSON, Markdown, and HTML reports are saved by default to ~/Desktop/舆情分析报告/, which affects the user's local filesystem. While the output location is documented, there is no explicit caution or warning that running the skill will create files on disk, which is the kind of user-impacting behavior SQP-2 asks markdown files to disclose clearly.
This JSON asset represents all region names exclusively in Chinese, which imposes a specific language/locale across the dataset. Under the stated policy, forcing a language without user opt-in can be a natural-language locale policy violation when no alternative or documented justification is present in the file.
The inline comment report_info = API调用参数 suggests this field is limited to request parameters. In practice, the code mutates that structure by adding report_time and total, so the documentation actively misdescribes the stored content.
The manifest description and the entire skill instructions are presented only in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-only audience for compliance reasons. Under the stated policy, forcing a specific language without opt-in can be a natural-language policy violation.
L027-L036 将 API Key 配置严格描述为 FEEDAX_REPORT_API_KEY,且 manifest 的 requires/env 也只声明该变量;但 L543 又声称 CLI 还会读取旧名 FEEDAX_SEARCH_API_KEY。虽然这是兼容逻辑,但文档前后对实际读取的环境变量集合描述不一致,属于意图与实现说明分歧。
L362-L366 的“输出结果”明确列出仅保存 JSON 和 Markdown 报告文件,而 L520-L533 又说明会生成 HTML 格式可视化报告。这属于文档内部对实际输出行为的直接矛盾,可能误导调用方对产物类型和联网需求的判断。
No suspicious patterns detected.