Back to skill

Security audit

求职技能顾问

Security checks for vulnerabilities and agentic risk

Overview

The skill is a simple career-advice guide, but it publishes a payment/API key directly in its documentation.

Review this before installing. The career-advice behavior itself is narrow, but the published SkillPay key should be treated as compromised and removed or replaced with secure per-user credential handling before distribution.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:19
Finding

Hardcoded SkillPay API Key Exposed in Skill Documentation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:19
Vulnerability Type: Hardcoded API credential
Risk Level: High

Vulnerable Code:

markdown
- **API Key**: `sk_3bf4e74479614724623768f5269c68251b09adf555a891eda68dbdfeac108f01`

Technical Analysis

A secret-shaped SkillPay API key is embedded directly in documentation distributed with the skill. Any party able to download, inspect, clone, or otherwise access the skill can recover the credential without authentication or specialized tooling.

Secrets must not be stored in source files or documentation because repository access controls, package distribution, caches, forks, logs, and version history can expose them beyond their intended environment. No source code in the audited project transmits this key, and the audit did not verify whether the credential remains active. Nevertheless, its explicit publication must be treated as credential compromise.

Attack Path

  1. An attacker obtains or downloads the skill package.
  2. The attacker opens SKILL.md and copies the API key from line 19.
  3. The attacker identifies the associated SkillPay service from the adjacent documentation.
  4. If the key is active, the attacker submits authenticated requests directly to the service using the exposed credential.
  5. Those requests may consume the associated account's quota or balance and may continue until the credential is revoked, expires, or is otherwise restricted.

Impact Assessment

If valid, the exposed credential may permit unauthorized use of the API privileges assigned to the key. Potential impact includes fraudulent paid calls, quota or balance consumption, service abuse attributed to the legitimate account, and loss of control over activity performed under that credential.

The obtainable privileges are limited to those granted to the API key by SkillPay. The audited project provides no evidence that the key grants local system access, admini ...[truncated 72 chars]

Remediation
View remediation

Remediation Suggestions

  1. Revoke the exposed API key immediately and issue a replacement only if the integration still requires one.
  2. Remove the credential from SKILL.md and from all published package versions, repository history, forks, build artifacts, caches, and documentation mirrors under the maintainer's control.
  3. Replace the literal value with a non-secret placeholder such as SKILLPAY_API_KEY.
  4. Require operators to provide credentials through a protected environment variable or dedicated secret-management system at runtime.
  5. Ensure credentials are never printed in logs, generated responses, error messages, examples, or diagnostic output.
  6. Restrict replacement credentials to the minimum required scopes, set spending or quota limits, and configure expiration and rotation where supported.
  7. Review provider-side usage records for requests made with the exposed key and investigate unexpected charges or activity.
  8. Add automated secret scanning to commit hooks and CI pipelines to prevent future credential publication.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill documentation includes a plaintext, live-looking API/payment secret that is unrelated to the normal operation of a career-advice skill from the user's perspective. Exposing secrets in public documentation can enable unauthorized use, fraud, account takeover of the associated payment/API service, and downstream abuse billed to the owner.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Publishing a plaintext API key without warning, scoping details, or secure handling guidance invites accidental reuse and malicious harvesting. Because the key appears directly embedded in markdown, any reader or automated scraper can capture it and attempt unauthorized transactions or API calls.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill content, instructions, examples, and disclaimer are all presented in Chinese only, which can amount to forcing a specific language without user opt-in. The file does not indicate that language selection is optional or that the skill supports other locales.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.