Back to skill

Security audit

中国AI API统一网关

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a disclosed AI API gateway guide, but its included gateway code can expose users' provider accounts through an unauthenticated public-facing service.

Review this before installing or running it. The guide can be useful for comparing China-based AI APIs, but do not expose the included gateway on a network without adding authentication, local-only binding, rate limits, request size limits, and quota controls. Store provider keys in environment variables or a secret manager, avoid committing real keys to YAML, and assume any prompt or code sent through the examples may be transmitted to third-party AI providers.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/gateway.py:50
Finding

Unauthenticated Public Gateway Permits Unauthorized Use of Provider Accounts

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/config.yaml:1
Finding

Provider Credentials Are Designed to Be Stored in Plaintext Configuration

Content
View full analysis
dict: base_url = provider["base_url"].rstrip("/") api_key = provider.get("api_key", "") timeout = CONFIG.get("routing", {}).get("timeout", 30) url = f"{base_url}/chat/completions" headers = {"Content-Type": "application/json", "Authorization": f"Bearer {api_key}"} ``` ### Technical Analysis The distributed configuration contains placeholders rather than live secrets, so no credential is exposed in the audited artifact itself. However, the operational design expects `api_key` to be read directly from YAML and placed into an upstream authorization header. A user follo ...[truncated 1990 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (43)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill documents code and configuration that read environment variables and make outbound network requests, but it declares no corresponding tool scope or permissions. This creates a capability/visibility mismatch: an orchestrator or reviewer may not realize the skill can access secrets and transmit data to external providers.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger keywords include broad everyday phrases such as switching models or API usage that may match benign conversations outside the intended context. Overbroad activation can cause unintended invocation of a skill that recommends third-party services and external API usage, increasing the chance of surprise data disclosure or irrelevant actions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The activation matrix uses ambiguous examples like 'OpenAI compatible' or 'API gateway' without requiring intent qualifiers such as domestic-provider aggregation or provider switching. This can cause the skill to trigger on general developer questions and steer users toward external services unexpectedly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill provides setup and call examples that send prompts and credentials to third-party APIs, but it does not clearly warn users that their inputs will leave the local environment. In a gateway context, this is more sensitive because the skill encourages multi-provider routing and fallback, which can multiply external disclosures across vendors.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This example performs an outbound API request containing user prompts and a bearer credential. The behavior is expected for an API-gateway skill, but it is still security-relevant because users may copy it without understanding that sensitive data will be transmitted to an external provider.

Content

Scanner excerpt · SKILL.md (reported line 164)May include surrounding context.

bash
# 小米MiMo
curl https://api.xiaomimimo.com/v1/chat/completions \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer $MIMO_API_KEY" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This example performs an outbound API request containing user prompts and a bearer credential. The behavior is expected for an API-gateway skill, but it is still security-relevant because users may copy it without understanding that sensitive data will be transmitted to an external provider.

Content

Scanner excerpt · SKILL.md (reported line 164)May include surrounding context.

bash
# 小米MiMo
curl https://api.xiaomimimo.com/v1/chat/completions \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer $MIMO_API_KEY" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

This curl example sends prompts and an authorization token to DeepSeek over the network. In context, the risk is not malicious code execution but unannounced third-party data exposure and possible credential mishandling by users who paste real secrets into examples.

Content

Scanner excerpt · SKILL.md (reported line 175)May include surrounding context.

md
}'

# DeepSeek
curl https://api.deepseek.com/v1/chat/completions \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer $DEEPSEEK_API_KEY" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The Python SDK example configures an external base URL and API key for remote inference. This is normal functionality, but in a skill document it should be treated as a disclosure point because copied code may send arbitrary prompt contents outside the user's trust boundary.

Content

Scanner excerpt · SKILL.md (reported line 200)May include surrounding context.

md
# 小米MiMo
client = OpenAI(
    base_url="https://api.xiaomimimo.com/v1",
    api_key="sk-xxxxx"
)

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

This example directs traffic and credentials to an external DeepSeek endpoint. The skill context makes it more sensitive because it is framed as a drop-in replacement gateway, which can encourage broad reuse without careful review of data-handling implications.

Content

Scanner excerpt · SKILL.md (reported line 206)May include surrounding context.

md
# DeepSeek
client = OpenAI(
    base_url="https://api.deepseek.com/v1",
    api_key="sk-xxxxx"
)

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The streaming example still transmits prompt content and credentials to a third party; streaming changes response handling but not the core disclosure risk. Users may incorrectly assume streaming is local or safer when it still crosses the network boundary.

Content

Scanner excerpt · SKILL.md (reported line 234)May include surrounding context.

md
from openai import OpenAI

client = OpenAI(
    base_url="https://api.xiaomimimo.com/v1",
    api_key="sk-xxxxx"
)

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The gateway configuration example stores provider endpoints and references API keys for multiple third-party services. In a routing/fallback design, a single prompt may be sent to alternate providers, increasing the blast radius of accidental disclosure compared with a single-provider example.

Content

Scanner excerpt · SKILL.md (reported line 257)May include surrounding context.

md
# gateway.yaml
providers:
  - name: mimo
    base_url: https://api.xiaomimimo.com/v1
    api_key: ${MIMO_API_KEY}
    models: [mimo-v2.5]
    priority: 1

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This second provider entry is part of a multi-provider gateway that can forward requests externally to DeepSeek. The security concern is cumulative: additional providers increase the number of external trust boundaries and potential retention/exposure surfaces.

Content

Scanner excerpt · SKILL.md (reported line 263)May include surrounding context.

md
priority: 1
    
  - name: deepseek
    base_url: https://api.deepseek.com/v1
    api_key: ${DEEPSEEK_API_KEY}
    models: [deepseek-chat]
    priority: 2

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The sample gateway code reads API keys from the environment and uses them to send messages to external providers. That is standard practice, but without explicit warnings it normalizes forwarding arbitrary user input and can mislead users about where their data goes.

Content

Scanner excerpt · SKILL.md (reported line 283)May include surrounding context.

md
PROVIDERS = {
    "mimo": {
        "base_url": "https://api.xiaomimimo.com/v1",
        "api_key": os.getenv("MIMO_API_KEY"),
        "models": ["mimo-v2.5"]
    },

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This provider configuration extends the same gateway forwarding logic to another remote endpoint. In context, the danger is higher than a simple one-off example because retry/fallback logic may cause repeated submissions of the same sensitive input to multiple vendors.

Content

Scanner excerpt · SKILL.md (reported line 288)May include surrounding context.

md
"models": ["mimo-v2.5"]
    },
    "deepseek": {
        "base_url": "https://api.deepseek.com/v1",
        "api_key": os.getenv("DEEPSEEK_API_KEY"),
        "models": ["deepseek-chat"]
    }

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The unsupported-scope section states that private deployment is not supported, but a later example recommends and demonstrates self-hosted gateway deployment. Inconsistent scope boundaries increase the chance that users follow risky infrastructure steps without the safety checks that would normally accompany supported deployment guidance.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This section recommends a concrete external API endpoint to users seeking a free AI service. The risk is lower than executable code, but it still encourages direct transmission of user data to a third-party provider without adjacent privacy caveats.

Content

Scanner excerpt · SKILL.md (reported line 360)May include surrounding context.

md
【推荐方案】

🥇 小米MiMo(首选)
• API:https://api.xiaomimimo.com/v1/chat/completions
• 模型:mimo-v2.5
• 额度:当前免费无限
• 中文:⭐⭐⭐⭐⭐

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This recommendation names an external DeepSeek endpoint in a way that may prompt immediate use. While informational, it contributes to third-party data-sharing risk if readers are not warned that their prompts will leave their environment.

Content

Scanner excerpt · SKILL.md (reported line 367)May include surrounding context.

md
• 适合:高频调用、中文对话

🥈 DeepSeek(备选)
• API:https://api.deepseek.com/v1/chat/completions
• 模型:deepseek-chat
• 额度:注册送500万tokens
• 推理:⭐⭐⭐⭐⭐

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

This recommendation promotes DeepSeek-Coder via a remote API endpoint. In a code-generation context, users may paste proprietary code or secrets, making external transmission particularly sensitive even though the example itself is informational.

Content

Scanner excerpt · SKILL.md (reported line 386)May include surrounding context.

md
【推荐方案】

🥇 DeepSeek-Coder(代码最强)
• API:https://api.deepseek.com/v1/chat/completions
• 模型:deepseek-coder
• 额度:500万tokens免费
• 代码:⭐⭐⭐⭐⭐

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The code example configures an external DeepSeek client with an API key and is likely to be copied verbatim. For code-assistant use cases, the surrounding context increases risk because users may send proprietary code, secrets, or internal architecture details to a third party unintentionally.

Content

Scanner excerpt · SKILL.md (reported line 395)May include surrounding context.

md
from openai import OpenAI

client = OpenAI(
    base_url="https://api.deepseek.com/v1",
    api_key="sk-xxxxx"
)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill says private/self-hosted deployment consulting is out of scope, yet later provides self-hosted gateway deployment instructions. This contradiction can bypass user expectations and reviewer assumptions, causing the skill to facilitate operational actions it claims not to support.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

The deployment example uses a container image reference without a pinned tag or digest, so users may pull an unexpected or later-mutated image. That weakens supply-chain integrity and can expose users to malicious or compromised upstream images without any change to the documentation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file appears to force a single language/locale for all users through its title, parameter descriptions, examples, and guidance. The policy allows locale constraints only when users are given a choice or when the restriction is explicitly documented and justified, neither of which is present here.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/details.md (reported line 38)May include surrounding context.

bash
# 基础对话(curl)
curl http://localhost:18080/v1/chat/completions \
  -H "Content-Type: application/json" \
  -d '{
    "model": "auto",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The example code sends user content directly to external model APIs but does not warn that prompts, attachments, and metadata may be transmitted to third-party providers and subject to their retention policies. In a gateway/integration skill, this omission can mislead users into sending sensitive business or personal data without informed consent or sanitization.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
85% confidence
Finding

This code example configures a client to send user messages to an external provider, but without any explicit warning about third-party data transmission, retention, or sensitivity handling. In context, the skill encourages easy drop-in replacement, which makes accidental disclosure of confidential prompts more likely.

Content

Scanner excerpt · references/platforms.md (reported line 43)May include surrounding context.

md
from openai import OpenAI

client = OpenAI(
    base_url="https://api.xiaomimimo.com/v1",
    api_key="sk-xxxxx"  # 你的API Key
)

Static analysis

No suspicious patterns detected.