Back to skill

Security audit

Grok Api

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed Grok API client that sends prompts and an API key to a LeonAI proxy, with no hidden install, persistence, or unrelated local access found.

Install only if you intend to route Grok requests through the LeonAI proxy. Do not send secrets, regulated data, or private content unless you trust that proxy and its data handling. Use explicit Grok commands to avoid accidental external calls, and review the NSFW option before enabling or copying the image-generation example.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (11)

Tainted flow: 'req' from os.environ.get (line 23, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · grok_chat.py (reported line 19)May include surrounding context.

python
def _post(path, body):
    data = json.dumps(body).encode()
    req = urllib.request.Request(f"{BASE_URL}{path}", data=data, headers=HEADERS)
    with urllib.request.urlopen(req, timeout=300) as resp:
        return json.loads(resp.read())

def _get(path):

Tainted flow: 'req' from os.environ.get (line 23, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · grok_chat.py (reported line 24)May include surrounding context.

python
def _get(path):
    req = urllib.request.Request(f"{BASE_URL}{path}", headers=HEADERS)
    with urllib.request.urlopen(req, timeout=30) as resp:
        return json.loads(resp.read())

def chat(prompt, model="grok-4.1-mini", system=None, reasoning=None, temperature=0.8):

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 13)May include surrounding context.

md
- 用户提到 Grok 模型名(grok-3, grok-4, grok-4.1 等)

## 环境变量要求
- `GROK_API_KEY` — LeonAI 代理的 API Key(存入 personal-secrets.json)
- `GROK_BASE_URL` — 默认 `https://apileon.leonai.top/grok/v1`

## 可用模型

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are broad enough to overlap with normal conversation, which can cause the skill to activate when the user did not clearly intend to use this external Grok integration. In this skill, accidental activation is more risky because it can send prompts to a third-party proxy service and may incur cost or expose sensitive content unintentionally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation instructs users to send prompts and credentials through a LeonAI proxy endpoint but does not clearly warn that conversation content and API usage are transmitted to a non-xAI intermediary. In this context, the missing disclosure increases privacy and trust risk because users may assume direct provider communication and may share sensitive data without informed consent.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The skill sends user messages and media-generation prompts to an external endpoint, which is an actual data egress path. In this case it is more sensitive than ordinary API use because the endpoint is a proxy service, so user content and metadata may be exposed to an additional party beyond the expected model provider.

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

1. 文本对话

bash
curl -s -X POST "$GROK_BASE_URL/chat/completions" \
  -H "Authorization: Bearer $GROK_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly demonstrates NSFW generation with enable_nsfw: true but provides no user-facing warning, policy boundary, age restriction, or abuse-prevention guidance. That omission makes misuse more likely and can expose operators to policy, legal, or reputational harm, especially in an agent environment where the examples may be copied directly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script sends user prompts and a bearer token to a third-party endpoint without any explicit user-facing disclosure beyond the source code. In a skill or agent context, users may not realize their inputs and credentials are transmitted off-box, increasing privacy and secret-handling risk, especially because the default endpoint is a non-official-looking proxy domain rather than a clearly trusted vendor host.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

文档的描述、触发场景和使用说明全部以中文给出,且未表明这是面向特定中文区域场景的限定,也未提供其他语言选项。按照语言/locale 政策,强制单一语言而无用户选择可能构成自然语言策略问题。

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

No manifest is available, so there is no declared skill purpose or scope to justify sensitive environment access. The code explicitly reads GROK_API_KEY from the environment to authenticate outbound API calls, which is a capability beyond a minimally scoped unknown-purpose skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The script reads GROK_API_KEY from the environment and injects it into the Authorization header, but the user-facing description does not explain that an API credential is required and will be used for remote authentication. Access to sensitive credentials in code files should include some visible disclosure unless already clearly documented.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.