Back to skill

Security audit

pangolinfo-amazon-product-explorer

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Amazon product research skill, but it needs review because it tells the agent to directly handle a Pangolinfo API key.

Install only if you are comfortable giving this skill access to Pangolinfo-authenticated tools. Prefer configuring credentials through a protected MCP or secret-management path, avoid putting API keys in URLs or prompts, and rotate any key that has been pasted into a transcript, URL, ticket, or shared config.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:343
Finding

API Credential Exposure Through Agent-Visible Environment Access and URL Query Parameters

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:343-359 and SKILL.md:568-571
Vulnerability Type: API credential exposure and insecure secret transport
Risk Level: Medium

Vulnerable Skill Instructions

The following is an English translation of the relevant instructions from SKILL.md:

markdown
### API Key (two separate mechanisms; do not mix them)

- Skill side: The AI reads the key from the environment variable
  `PANGOLINFO_API_KEY`. This is the skill's default key source. The AI
  reads it directly and should not repeatedly ask the user.

- MCP server side: The key is supplied through MCP configuration:
  `--api-key=<key>`, the environment variable `PANGOLINFO_API_KEY`,
  `~/.pangolinfo/config.json`, hosted URL `?api_key=<key>`, or the
  HTTP header `Authorization: Bearer <key>`.

The credential guidance is repeated in the defensive checklist:

markdown
Skill-side credentials are read from `PANGOLINFO_API_KEY`. MCP-side
credentials may be passed through CLI/configuration, a URL query parameter
`?api_key=<key>`, or `Authorization: Bearer <key>`.

Technical Analysis

The skill explicitly authorizes the AI agent itself to read PANGOLINFO_API_KEY. This unnecessarily places a reusable API credential within the agent's accessible environment and potentially its model-visible context. An agent should normally invoke an MCP tool without receiving or processing the underlying authentication secret.

The instructions also permit authentication through the URL query parameter ?api_key=<key>. Query-string credentials are unsafe because complete URLs are commonly retained by:

  • Reverse-proxy and web-server access logs
  • Observability, tracing, and error-reporting systems
  • Browser or client history
  • Shell history and process invocation records
  • Screenshots, copied configuration URLs, and support tickets
  • Referrer propagation where the client or redirect policy permits it

Although the d ...[truncated 1679 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove agent-side secret access

    • Delete the instruction directing the AI to read PANGOLINFO_API_KEY.
    • Keep the credential inside the MCP server or credential broker.
    • Expose only authenticated tools to the agent, never the underlying token.
  2. Disallow query-string authentication

    • Remove ?api_key=<key> from the documented configuration methods.
    • Require an Authorization: Bearer <key> header supplied by the MCP client or secret manager outside model-visible context.
    • Reject query-parameter credentials server-side where compatibility permits.
  3. Apply secret redaction

    • Redact JWTs and authorization headers from agent transcripts, tool errors, telemetry, traces, and access logs.
    • Add detection for JWT-like three-segment values and the api_key parameter.
    • Ensure authentication errors never echo the submitted credential.
  4. Use least-privilege credentials

    • Issue scoped keys limited to the operations and quotas required by this skill.
    • Prefer short-lived credentials where supported.
    • Maintain straightforward revocation and rotation procedures.
  5. Harden configuration guidance

    • Recommend an operating-system secret store or MCP-specific protected configuration.
    • Restrict configuration-file permissions to the owning user.
    • Warn users not to paste credentials into prompts, hosted URLs, tickets, screenshots, or source-controlled files.
  6. Rotate potentially exposed credentials

    • Revoke and replace any key previously placed in a URL, transcript, or shared configuration.
    • Review service usage and infrastructure logs for unauthorized activity.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The activation examples for the Fast tier include broad phrases like "X 方向能做什么" and "我想做 Y 类目,先研究一下," which are not tightly constrained to a specific command or invocation context. Although the file gives some 'NOT for' exclusions earlier, these trigger examples are still general enough that ordinary exploratory conversation could unintentionally match the skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly instructs the agent to read PANGOLINFO_API_KEY from the environment. Accessing secrets is a sensitive capability and is not strictly part of product-analysis logic; if an agent broadly follows skill instructions, this normalizes secret access inside untrusted skill content and can enable secret exposure or misuse in downstream prompts, logs, or tool arguments. The embedded guidance to 'directly read' the key from env increases the blast radius if the skill is ever modified or if adjacent prompt-injection attempts try to exfiltrate credentials.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.