Back to skill

Security audit

远行商人库存查询

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says: it fetches game merchant inventory from one documented API, but users should handle the API key carefully.

Install only if you are comfortable sending your Roco merchant API key to the documented wegame.shallow.ink endpoint. Prefer setting ROCOM_API_KEY in a controlled environment over passing --api-key on the command line, and rotate the key if it was exposed in shell history, logs, or shared terminal output.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/fetch_inventory.py:135
Finding

API Key Exposure Through Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: scripts/fetch_inventory.py:135
Related Documentation: SKILL.md:29
Vulnerability Type: API key disclosure through process arguments and shell history
Risk Level: Medium

Vulnerable Code

python
parser.add_argument("--api-key", default=os.environ.get("ROCOM_API_KEY") or DEFAULT_API_KEY)

The documented usage explicitly encourages this insecure input method:

bash
python3 skills/rocom-merchant-inventory/scripts/fetch_inventory.py --api-key 你的key --format json --pretty

Technical Analysis

The script permits an API key to be supplied directly through the --api-key command-line option. Command-line arguments are not an appropriate secret transport mechanism because they may be exposed through:

  • Shell history files.
  • Process inspection utilities and process metadata.
  • Endpoint monitoring and audit systems.
  • Terminal session logging.
  • CI/CD job logs or wrapper scripts that record executed commands.

The script also supports the ROCOM_API_KEY environment variable, which avoids placing the key directly in command history, but the unsafe command-line mechanism remains enabled and is explicitly demonstrated in the documentation.

The subsequent transmission at scripts/fetch_inventory.py:92-93 is not independently considered malicious:

python
def fetch(api_key: str):
    resp = requests.get(API_URL, headers={"X-API-Key": api_key}, timeout=30)

The key is sent over HTTPS, in the documented X-API-Key header, to the fixed API endpoint declared by the skill. Authentication is necessary for the declared inventory-retrieval functionality, and no evidence of transmission to unrelated destinations was found.

Attack Path

  1. A user follows the documented example and invokes the script with --api-key.
  2. The plaintext API key becomes part of the command line.
  3. The command is retained in shell history, captured by process monitoring, recorded in job logs, or observed thr ...[truncated 932 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the --api-key argument so secrets cannot be supplied through process arguments.
  2. Accept the credential through ROCOM_API_KEY or a protected credential store.
  3. If interactive use is required, use getpass.getpass() so the key is not echoed or stored in shell history.
  4. Remove the command-line key example from SKILL.md and document only safer credential-loading methods.
  5. Advise users to restrict access to any configuration file containing the key and to avoid logging environment contents.
  6. Rotate any key that may previously have been entered through command-line arguments.
  7. Where supported by the API provider, use narrowly scoped, short-lived, and revocable credentials.

A hardened interface could reject command-line secret input and require the environment variable:

python
api_key = os.environ.get("ROCOM_API_KEY")
if not api_key:
    print(
        json.dumps(
            {
                "ok": False,
                "error": "ROCOM_API_KEY is required.",
            }
        ),
        file=sys.stderr,
    )
    sys.exit(2)
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill documentation indicates it uses environment variables and makes outbound network requests, but it does not declare any explicit tool scope such as permissions or allowed-tools. This creates a trust and containment gap: an agent or runtime may execute the skill with broader capabilities than intended, including access to sensitive environment data and unrestricted network access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file documents that the skill uses a credential (ROCOM_API_KEY or --api-key) but does not include any warning or guidance about protecting the key, avoiding shell history leakage, or the privacy implications of transmitting it to the remote API. Under the markdown-specific missing-warning criteria, credential use that could affect privacy or system integrity should be disclosed to users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The text states that rounds are shown according to Beijing time, which imposes a specific locale/timezone behavior. Because no user opt-in, alternative timezone handling, or justification is provided in the file, this is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script contains multiple hard-coded Chinese user-facing strings such as status labels, countdown text, item availability messages, and error output, while providing no option for users to select another language. This is a natural-language locale policy concern because the skill enforces a specific language rather than offering opt-in or choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.