Back to skill

Security audit

baidu-scholar-search

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent academic search helper, but it needs review because it sends queries to a third-party API using an environment API key and builds the JSON request unsafely.

Review before installing. Use it only if you are comfortable sending search keywords to SkillBoss/HeyBossAI and providing a SKILLBOSS_API_KEY in the runtime environment. Avoid sensitive or unpublished research queries unless you trust that service's handling of them, and prefer a version that JSON-escapes the query before sending requests.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
baidu_scholar_search.sh:13
Finding

Unescaped Search Input Permits JSON Request-Body Injection

Content
View full analysis

Vulnerability Details

File Location: baidu_scholar_search.sh, lines 13–26
Vulnerability Type: JSON injection caused by unsafe string interpolation
Risk Level: Medium

Vulnerable Code

bash
WD="$1"
if [ -z "$WD" ]; then
    echo '{"error": "Missing wd parameter"}'
    exit 1
fi

pageNum="${2:-0}"
enable_abstract="${3:-false}"

curl -s -X POST \
  -H "Authorization: Bearer $SKILLBOSS_API_KEY" \
  -H "Content-Type: application/json" \
  -d "{\"type\": \"search\", \"inputs\": {\"query\": \"$WD\"}, \"prefer\": \"balanced\"}" \
  "https://api.heybossai.com/v1/pilot"

The same vulnerable implementation is reproduced in SKILL.md, lines 57–72.

Technical Analysis

The script inserts the user-controlled WD argument directly into a manually assembled JSON string. Shell quoting prevents word splitting and direct shell-command substitution after parameter expansion, so this is not a demonstrated shell-command injection vulnerability. However, shell quoting does not JSON-escape quotation marks, backslashes, or control characters contained in WD.

An attacker can therefore supply JSON syntax that terminates the intended query string and introduces additional properties or structures. Alternatively, malformed input can invalidate the entire request. The resulting body is sent to the remote API using the legitimate SKILLBOSS_API_KEY.

The exact server-side effect depends on the API parser, schema validation, and supported properties. Modification of fields not shown in the audited client cannot be asserted, but the client demonstrably fails to preserve the input solely as a JSON string value.

Attack Path

  1. An attacker or untrusted caller invokes the script with a search term containing quotation marks and JSON syntax.
  2. The script assigns this content to WD without JSON encoding or validation.
  3. The -d argument interpolates the content verbatim into the JSON document.
  4. The crafted content terminates or modifies the intend ...[truncated 874 chars]
Remediation
View remediation

Remediation Suggestions

Construct the request body with a JSON serializer rather than manual string concatenation. For example, if jq is declared and installed as a dependency:

bash
payload=$(jq -n --arg query "$WD" \
  '{type: "search", inputs: {query: $query}, prefer: "balanced"}')

curl --fail-with-body -sS -X POST \
  -H "Authorization: Bearer $SKILLBOSS_API_KEY" \
  -H "Content-Type: application/json" \
  --data-binary "$payload" \
  "https://api.heybossai.com/v1/pilot"

This ensures that quotes, backslashes, control characters, Unicode content, and line breaks are encoded as JSON string data rather than interpreted as JSON structure.

Additional hardening should include:

  1. Declare jq as a required binary if this implementation is adopted.
  2. Apply a reasonable maximum length to WD to limit oversized requests and quota abuse.
  3. Use curl --fail-with-body -sS so transport and HTTP failures are observable.
  4. Validate and implement pageNum and enable_abstract, or remove them from the interface to avoid misleading callers.
  5. Update the duplicated implementation in SKILL.md so documentation does not encourage reuse of the vulnerable pattern.
  6. Add tests containing quotes, backslashes, newlines, and JSON-like input to verify that each value remains confined to inputs.query.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill executes shell code and performs outbound network requests, but the manifest does not declare any tool scope such as allowed-tools or permissions. This weakens policy enforcement and review because consumers cannot clearly see that shell execution and network access are required before running the skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation and examples show that user search queries and a bearer API credential are sent to a third-party remote service, but there is no explicit user-facing warning about external data sharing. In an academic search context, queries may contain sensitive research topics, unpublished ideas, or personal data, so silent transmission creates privacy and compliance risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

This duplicate finding identifies the external domain in the example curl command, which clearly shows user queries being sent off-platform. In this skill context the behavior is functional, but without explicit warnings and data-handling constraints it creates privacy and data-sharing risk.

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

Example Usage

bash
curl -s -X POST 'https://api.heybossai.com/v1/pilot' \
-H 'Authorization: Bearer $SKILLBOSS_API_KEY' \
-H 'Content-Type: application/json' \
-d '{"type": "search", "inputs": {"query": "人工智能"}, "prefer": "balanced"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

This duplicate finding identifies the external domain in the example curl command, which clearly shows user queries being sent off-platform. In this skill context the behavior is functional, but without explicit warnings and data-handling constraints it creates privacy and data-sharing risk.

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

Example Usage

bash
curl -s -X POST 'https://api.heybossai.com/v1/pilot' \
-H 'Authorization: Bearer $SKILLBOSS_API_KEY' \
-H 'Content-Type: application/json' \
-d '{"type": "search", "inputs": {"query": "人工智能"}, "prefer": "balanced"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

The execution script sends the runtime user parameter WD directly to a remote API using curl and authorizes the request with an environment-stored bearer token. This is expected behavior for the search feature, but it is still a true external transmission risk because potentially sensitive inputs are automatically exfiltrated to a third party during normal use.

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

-H "Authorization: Bearer $SKILLBOSS_API_KEY"
-H "Content-Type: application/json"
-d "{"type": "search", "inputs": {"query": "$WD"}, "prefer": "balanced"}"
"https://api.heybossai.com/v1/pilot"

Response path: .result.results

text

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · baidu_scholar_search.sh (reported line 23)May include surrounding context.

sh
pageNum="${2:-0}"
enable_abstract="${3:-false}"

curl -s -X POST \
  -H "Authorization: Bearer $SKILLBOSS_API_KEY" \
  -H "Content-Type: application/json" \
  -d "{\"type\": \"search\", \"inputs\": {\"query\": \"$WD\"}, \"prefer\": \"balanced\"}" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

md
-H "Authorization: Bearer $SKILLBOSS_API_KEY" \
  -H "Content-Type: application/json" \
  -d "{\"type\": \"search\", \"inputs\": {\"query\": \"$WD\"}, \"prefer\": \"balanced\"}" \
  "https://api.heybossai.com/v1/pilot"
# Response path: .result.results

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · baidu_scholar_search.sh (reported line 27)May include surrounding context.

sh
-H "Authorization: Bearer $SKILLBOSS_API_KEY" \
  -H "Content-Type: application/json" \
  -d "{\"type\": \"search\", \"inputs\": {\"query\": \"$WD\"}, \"prefer\": \"balanced\"}" \
  "https://api.heybossai.com/v1/pilot"
# Response path: .result.results

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The manifest frames this skill as an academic literature search tool, but the implementation depends on reading SKILLBOSS_API_KEY from the environment. Accessing credentials is not described in the manifest and is a broader capability than the user-facing purpose of searching literature, even though it is used to authenticate the backend request.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.