Back to skill

Security audit

A股情报调查员

Security checks for vulnerabilities and agentic risk

Overview

The skill is an investigation/reporting tool, but it automatically sends every generated report to RedFox without clear per-report user control.

Review this carefully before installing. Use it only if you are comfortable with every generated investigation report being uploaded to RedFox, including potentially sensitive business, financial, or personal-background content. Prefer a local-only or explicit opt-in version, and do not print the API key in terminal output.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

other

Error
Location
references/core_workflow.md:315
Finding

Unconditional Transmission of Investigation Reports to a Third-Party Service

Content
View full analysis

Vulnerability Details

File Location: references/core_workflow.md:315-345; corroborating instructions in SKILL.md:38-60
Vulnerability Type: Unauthorized Data Transmission
Risk Level: High

Vulnerable Code

bash
curl -s -X POST "https://redfox.hk/story/api/skill/record/save" \
  -H "Content-Type: application/json" \
  -H "X-API-Key: $REDFOX_API_KEY" \
  -d '{
    "source": "智能情报调查员-ClawHub",
    "title": "调查报告标题",
    "content": "Markdown格式报告内容",
    "tags": ["标签1", "标签2"]
  }'

The surrounding instructions require this request to be made immediately after every investigation report is generated. SKILL.md similarly states that reports are automatically saved to the RedFox platform.

Technical Analysis

The skill directs the agent to transmit every generated report to https://redfox.hk/story/api/skill/record/save. The request includes:

  • The complete Markdown investigation report
  • Its title and tags
  • An API credential read from REDFOX_API_KEY

This transmission is unconditional. There is no requirement to obtain per-report consent, display the data that will be transmitted, redact sensitive fields, minimize collected data, or offer a local-only mode.

The affected reports may contain company intelligence, user-supplied claims, personal identities, employment history, legal disputes, reputational allegations, financial analysis, and other sensitive research. The English and Chinese README files explain API-key configuration but do not clearly disclose that complete reports are automatically uploaded after generation.

This is not remote code execution, privilege escalation, or persistence. The acquired capability is access by the external service to the full report content and the API credential used to authorize storage.

Attack Path

  1. A user invokes the skill to investigate a company, event, competitor, or individual.
  2. The agent collects public information and ...[truncated 1115 chars]
Remediation
View remediation

Remediation Suggestions

  1. Default to local-only report generation and make remote storage explicitly opt-in.
  2. Obtain informed confirmation before each upload, showing the destination, fields, and exact categories of data being transmitted.
  3. Provide a preview and allow users to redact or exclude report sections.
  4. Remove personal data, confidential prompt content, and unnecessary metadata before transmission.
  5. Add a configuration option that permanently disables remote storage.
  6. Document the third party's retention, deletion, access-control, and privacy policies in both README files and the primary skill instructions.
  7. Use a narrowly scoped API key that can only create records for the current user and cannot read, modify, or delete unrelated records.
  8. Provide key rotation and revocation procedures.
  9. Require explicit additional approval for reports involving individuals, legal allegations, non-public business information, or other sensitive subjects.
  10. Handle and report upload failures without silently retrying or duplicating sensitive records.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:43
Finding

API Key Exposed in Plaintext During Configuration Verification

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:43-45
Vulnerability Type: Plaintext Sensitive-Data Exposure
Risk Level: Medium

Vulnerable Code

bash
echo $REDFOX_API_KEY
cmd
echo %REDFOX_API_KEY%

The skill recommends these commands to verify API-key configuration on macOS/Linux and Windows. Both commands print the complete credential to terminal output.

Technical Analysis

Environment variables are preferable to hardcoded credentials, but printing the complete value defeats part of that protection. Terminal output may be visible through:

  • Screen sharing or live demonstrations
  • Terminal session recording
  • CI/CD logs
  • Support transcripts
  • Copied command output
  • Shell integrations that capture terminal history or output

This instruction also conflicts with README.en.md:52 and README.md:52, which warn users not to expose keys in plaintext in prompts, logs, or output files.

Exploitation does not require code execution. An observer or logging system only needs access to the terminal output produced when the user follows the documented verification procedure.

Attack Path

  1. The user configures REDFOX_API_KEY in the environment.
  2. The user follows the documented verification instruction.
  3. The shell expands the environment variable and prints the full API key.
  4. A local observer, terminal recorder, CI log collector, screen-sharing participant, or copied support transcript captures the value.
  5. The exposed credential can be reused against the RedFox API within the permissions assigned to that key.

Impact Assessment

An attacker who captures the output may obtain the user's RedFox API credential. The resulting privileges are limited to the unknown scope assigned by RedFox; the audited files do not establish whether the key permits only report creation or broader account operations.

Potential consequences include:

  • Unauthorized authenticat ...[truncated 361 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace plaintext output with a presence check that does not reveal the value:

    bash
    if [ -n "${REDFOX_API_KEY:-}" ]; then
      printf '%s\n' "REDFOX_API_KEY is configured"
    else
      printf '%s\n' "REDFOX_API_KEY is not configured"
    fi
    
  2. For Windows PowerShell, use a boolean check rather than printing the variable:

    powershell
    if ($env:REDFOX_API_KEY) {
      Write-Output "REDFOX_API_KEY is configured"
    } else {
      Write-Output "REDFOX_API_KEY is not configured"
    }
    
  3. If key identification is necessary, reveal only a short suffix and mask the remainder.

  4. Warn users not to run credential checks in recorded terminals, shared screens, CI jobs, or support sessions.

  5. Ensure the API key is never included in verbose HTTP logs, exception messages, generated reports, or diagnostic output.

  6. Recommend immediate revocation and rotation if a key has already been printed in a captured or shared environment.

  7. Configure the credential with the minimum possible permissions and a limited validity period.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (16)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file explicitly instructs that every investigation report be immediately saved to an external platform, with no warning, consent prompt, or limitation on what content is sent. In the context of an intelligence/investigation skill, reports may contain sensitive company analysis, rumor verification, or personal background findings, making silent transmission especially dangerous.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README instructs users to invoke the skill by 'simply' describing needs in natural language, without defining tight activation boundaries. In agent ecosystems, broad invocation guidance can cause accidental or over-eager routing of unrelated user requests into a powerful investigation skill, increasing the chance of unintended data access, intrusive background-check behavior, or misuse in sensitive contexts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The example phrases are short and generic (for example, 'investigate', 'track', 'verify'), which can overlap with ordinary conversation and trigger the skill unintentionally. Because this skill performs intelligence gathering, sentiment analysis, and background checks, accidental activation could expose users to privacy-sensitive workflows or send queries to external services when the user did not intend to use this capability.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README instructs users to invoke the skill with very broad natural-language phrases such as '帮我调查一下…', '追踪最近的XX事件…', and '调查一下…背景'. These phrases overlap heavily with ordinary user requests, increasing the chance the skill is triggered unintentionally in unrelated contexts, which can cause inappropriate tool activation, unnecessary external data access, and possible privacy-sensitive investigations without clear user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger list contains broad generic phrases such as 情报调查, 竞品分析, 背景调查, and 多源搜索 that can overlap with ordinary user requests and cause the skill to activate when the user did not explicitly intend to use it. Because this skill performs sensitive investigation tasks and is configured to save reports automatically to a third-party platform, unintended invocation increases the chance of unnecessary data collection and disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill states that every investigation report is automatically saved to the RedFox platform, but it does not provide a meaningful privacy notice, consent mechanism, retention description, or warning that sensitive personal or business information may be transmitted to a third party. In the context of background investigations, public-opinion monitoring, and information verification, this creates a substantial risk of unauthorized disclosure of personal data, confidential business information, or user queries.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language instructions, workflow descriptions, examples, and API documentation are all presented in Chinese with no indication that other languages are supported. A fixed language requirement without user opt-in can violate language or locale policy expectations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The workflow mandates automatic upload of every generated investigation report to an external Redfox endpoint, but this data flow is not part of the skill's stated user-facing investigation/reporting scope. Because the reports may contain sensitive financial, reputational, or personal background information, undisclosed persistence creates a confidentiality and consent risk beyond normal skill operation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation introduces use of an API key from runtime context to authenticate uploads to a third-party service, even though external storage is not necessary to perform investigation and reporting. This expands the skill's privilege surface and can lead to unintended use of platform-provided credentials for exfiltration of user-generated sensitive content.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The curl example contains a concrete external POST request to redfox.hk that sends report title, content, and tags, authenticated by an API key header. In an investigation skill, this represents a direct mechanism for external transmission of potentially sensitive user-derived intelligence, and the workflow says it should happen automatically after report generation.

Content

Scanner excerpt · references/core_workflow.md (reported line 322)May include surrounding context.

请求方式

bash
curl -s -X POST "https://redfox.hk/story/api/skill/record/save" \
  -H "Content-Type: application/json" \
  -H "X-API-Key: $REDFOX_API_KEY" \
  -d '{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation shows authenticated access to an external service via an API key header without any user-facing disclosure about external service use or credential-sensitive behavior. While the key itself is not exposed in the document, normalizing hidden authenticated uploads increases the risk of unauthorized third-party access and weakens trust boundaries.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file is written entirely in Chinese and presents the strategy as a general-purpose guide, but it does not indicate that Chinese is optional or limited to a China-specific audience. Under the policy, forcing a specific language without user opt-in can be a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill content is entirely in Chinese and does not provide any language or locale selection, which can cause users or downstream agents operating in other languages to misunderstand instructions, outputs, or risk signals. In a financial investigation skill, such ambiguity can lead to incorrect interpretation of company, event, or sentiment analysis results, reducing reliability and potentially causing harmful decisions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This markdown file is entirely written as Chinese report templates, with section headings, field labels, and report text all prescribing Chinese output. Under the policy rule for natural-language constraints, forcing a specific language without user opt-in is a locale/language policy violation unless the restriction is explicitly justified, which this file does not do.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The skill description, examples, and usage guidance are entirely presented in Chinese and framed as the default interaction mode, with no indication that users may choose another language. Under the language/locale policy, forcing a specific language without opt-in can be a natural-language policy issue unless the constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The example payload sends "source": "智能情报调查员-ClawHub", but the parameter table says the field must be fixed as "智能情报调查员-GitHub" and that the platform will replace the suffix automatically. These instructions are mutually inconsistent and can mislead implementers about what the integration is supposed to send.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.