Back to skill

Security audit

讯飞票据识别

Security checks for vulnerabilities and agentic risk

Overview

The skill performs the advertised invoice OCR workflow, but its instructions can expose API secrets and do not clearly warn users about uploading sensitive documents to a third-party OCR service.

Review this skill before installing. Use it only for documents you are authorized to send to iFlytek, avoid medical or financial records unless that third-party processing is acceptable, and do not run the troubleshooting commands that print XFEI_API_KEY or XFEI_API_SECRET. If those secrets were displayed in a shared or logged terminal, rotate them.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:149
Finding

API credentials exposed by unsafe troubleshooting instructions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 149–156
Vulnerability Type: Cleartext credential disclosure and insecure secret storage guidance
Risk Level: Medium

Vulnerable Code Snippet

bash
# macOS / Linux:
echo "XFEI_APP_ID: $XFEI_APP_ID | XFEI_API_KEY: $XFEI_API_KEY | XFEI_API_SECRET: $XFEI_API_SECRET"

# Windows cmd:
echo XFEI_APP_ID: %XFEI_APP_ID% ^|^| XFEI_API_KEY: %XFEI_API_KEY% ^|^| XFEI_API_SECRET: %XFEI_API_SECRET%

The documentation subsequently recommends persisting an environment variable in a shell startup file:

bash
echo 'export XFEI_APP_ID=your_value' >> ~/.zshrc

Technical Analysis

The troubleshooting commands expand and print the complete iFlytek API key and API secret in cleartext. Secret values displayed in a terminal may be captured by terminal scrollback, CI logs, shell-session recording, screen sharing, screenshots, support transcripts, or local monitoring software.

The nearby persistence example also establishes an unsafe pattern of storing credentials in plaintext shell startup files. Although the documented command specifically stores the application ID, users may reasonably apply the same method to the API key and secret.

This exposure is unnecessary for diagnosing whether required environment variables exist. A presence-only test provides the same diagnostic result without revealing their values.

The application implementation itself does not print these credentials. It reads them from the environment and uses them for the documented HMAC authentication flow. The vulnerability is therefore confined to the troubleshooting and credential-management instructions.

Attack Path

  1. A user experiences an authentication error and follows the troubleshooting instructions.
  2. The user runs the provided command, causing the API key and API secret to appear in cleartext.
  3. Terminal logging, a screen-sharing participant, a screenshot, a support transcript, a CI system, or another local ob ...[truncated 1476 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove all commands that print the values of XFEI_API_KEY or XFEI_API_SECRET.
  2. Replace them with presence-only checks. For example:
bash
for name in XFEI_APP_ID XFEI_API_KEY XFEI_API_SECRET; do
  if [ -n "$(printenv "$name")" ]; then
    echo "$name: set"
  else
    echo "$name: missing"
  fi
done
  1. Provide an equivalent presence-only PowerShell check:
powershell
"XFEI_APP_ID", "XFEI_API_KEY", "XFEI_API_SECRET" | ForEach-Object {
    if (Test-Path "Env:$_") {
        "$_: set"
    } else {
        "$_: missing"
    }
}
  1. Explicitly warn users not to paste credentials into support messages, issue reports, screenshots, logs, or shared terminals.
  2. Recommend an operating-system credential manager, secret-management service, or permission-restricted environment file excluded from version control.
  3. If an environment file must be used, require restrictive filesystem permissions and provide an appropriate ignore rule. Do not recommend storing API secrets in shell startup files.
  4. Advise users who have already run the cleartext diagnostic command in a logged or shared environment to rotate the API key and secret and remove exposed values from retained logs where feasible.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill declares no explicit tool scope even though its documented behavior requires reading environment variables and making outbound network requests. Missing permission metadata weakens least-privilege controls and can cause users or hosting platforms to underestimate what the skill can access and transmit.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation says invoice images are processed via the iFlytek API but does not clearly warn that potentially sensitive financial documents and extracted data are sent to a third party. Users may unknowingly transmit invoices, receipts, medical bills, and bank receipts containing personal or financial information without informed consent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The troubleshooting section tells users to print XFEI_APP_ID, XFEI_API_KEY, and XFEI_API_SECRET directly to the terminal. This exposes secrets in plaintext to screen observers, terminal logs, session recordings, and copy/paste workflows, which is unnecessary for invoice recognition and materially increases credential-compromise risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The troubleshooting instructions encourage exposing credential values without any warning about shoulder-surfing, terminal capture, screen sharing, or saved logs. Because these variables include the API secret, disclosure can enable unauthorized API use and abuse of the associated account.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

Printing all authentication environment variables directly reveals secrets in plain text, including the API secret needed for request signing. If captured by logs, recordings, remote support sessions, or nearby observers, those credentials can be reused to impersonate the user and access paid or sensitive OCR services.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 81)May include surrounding context.

md
from urllib.parse import urlencode, urlparse
from wsgiref.handlers import format_date_time

API_URL = "https://api.xf-yun.com/v1/private/sc45f0684"


def build_auth_url(request_url: str, api_key: str, api_secret: str, method: str = "POST") -> str:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/invoice.py (reported line 34)May include surrounding context.

python
from urllib.parse import urlencode, urlparse
from wsgiref.handlers import format_date_time

API_URL = "https://api.xf-yun.com/v1/private/sc45f0684"


def build_auth_url(request_url: str, api_key: str, api_secret: str, method: str = "POST") -> str:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code base64-encodes the user-supplied invoice image and sends it to a third-party OCR endpoint, which can expose sensitive financial and personal data contained in invoices, receipts, or medical bills. While this is core functionality rather than malicious behavior, there is no explicit user-facing consent or warning at transmission time, so users may not understand that document contents leave the local environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

A substantial troubleshooting section switches to Chinese-only guidance, which can impose a language requirement on users without opt-in. The policy allows locale constraints when clearly documented and justified, but this file does not explicitly state that support content is Chinese-only or offer an alternative language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill description and formatted output include Chinese-only labels such as '票据类型', and the CLI description also embeds Chinese text, but the script does not provide a language/locale option or explain that it is intentionally Chinese-specific. This can violate language/locale policy when users are not given an opt-in or alternative.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.