Back to skill

Security audit

品牌GEO分析Plus版

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent brand-monitoring tool, but it has a real credential-safety flaw and under-disclosed external data handling that users should review before installing.

Install only if you are comfortable sending brand, topic, competitor, and AI-search questions to RedFox-backed services. Avoid using confidential launches, unreleased campaigns, regulated personal data, or sensitive investigations until the hub TLS verification issue is fixed and local report/temp-file retention is clarified.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/hub_fetch.py:181
Finding

Authenticated API Request Disables TLS Certificate Validation

Content
View full analysis

Vulnerability Details

File Location: scripts/hub_fetch.py, lines 181-186
Vulnerability Type: Improper TLS certificate and hostname validation
Risk Level: High

Complete Code Snippet

python
ctx = ssl.create_default_context()
ctx.check_hostname = False
ctx.verify_mode = ssl.CERT_NONE
with urllib.request.urlopen(req, timeout=30, context=ctx) as resp:
    if resp.status != 200:
        return {

The request constructed immediately before this code includes the user's RedFox API key:

python
req = urllib.request.Request(
    api_url,
    data=body,
    headers={
        "Content-Type": "application/json",
        "X-API-KEY": api_key
    },
    method="POST"
)

Technical Analysis

The hub module sends an authenticated HTTPS request to the fixed RedFox endpoint. Although it creates an SSL context, it explicitly disables both hostname verification and certificate validation:

  • ctx.check_hostname = False allows a certificate issued for an unrelated hostname.
  • ctx.verify_mode = ssl.CERT_NONE accepts untrusted, self-signed, expired, or attacker-provided certificates.

Consequently, TLS encryption does not authenticate the remote server. An active network attacker can impersonate redfox.hk and receive the request body and X-API-KEY header. This differs from normal API authentication because the secret is no longer guaranteed to reach the intended service.

The same attacker can return forged hotspot records. Those records are parsed by process_hotspot_data() and then emitted as compact, JSON, or Markdown output for use by the Agent.

Attack Path

  1. A user invokes the hub workflow, causing fetch_hotspot_data() to send an authenticated request.
  2. An attacker with an active network position intercepts or redirects the connection, such as through a hostile network, compromised proxy, or DNS/network-routing manipulation.
  3. The attacker presents an arbitrary TLS certificate.
  4. Because certificate and hostname verific ...[truncated 880 chars]
Remediation
View remediation

Remediation Suggestions

Remove the insecure custom SSL settings and rely on Python's default certificate and hostname verification:

python
with urllib.request.urlopen(req, timeout=30) as resp:
    ...

If an explicit context is needed, retain secure defaults:

python
ctx = ssl.create_default_context()
with urllib.request.urlopen(req, timeout=30, context=ctx) as resp:
    ...

Additional hardening steps:

  1. Never set verify_mode to ssl.CERT_NONE for authenticated production requests.
  2. Never disable check_hostname when connecting to a named HTTPS endpoint.
  3. If a private certificate authority is required, load only the required CA bundle with cafile or ctx.load_verify_locations() while retaining ssl.CERT_REQUIRED.
  4. Add a regression test confirming that self-signed certificates and hostname mismatches cause the request to fail.
  5. Rotate any API key that may previously have been used over an untrusted network with this vulnerable code.
  6. Avoid including raw authentication headers or key values in exceptions, diagnostics, or logs.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (38)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents a comprehensive three-module brand perception suite spanning heat tracking, 30-day cross-platform discussion research, and AI-search/GEO visibility analysis. The supplied code only covers a hotspot-fetching script for several platforms via one API endpoint. It does not perform Xiaohongshu/Douyin/公众号 30-day deep discussion analysis, does not query AI systems like 豆包/Kimi/DeepSeek, and does not provide broader brand perception synthesis beyond hot-topic retrieval and formatting. While the implemented functionality is consistent with one subset of the declared tool ('hub'), the overall description materially overstates what this code chunk actually does, so this is a mismatch.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · scripts/cn30_search.py (reported line 729)May include surrounding context.

python
</div>'
            )

        xhs_notice = (
            '<div style="background:#fff3cd;border:1px solid #ffc107;border-radius:8px;padding:10px 14px;margin-bottom:14px;color:#664d03;font-size:13px;line-height:1.6">'
            '⚠️ 受小红书风控规则限制,部分作品链接可能无法正常跳转,您可复制对应作品标题前往小红书搜索查看,感谢理解🙇‍♀️🙇‍♀️'
            '</div>'
        ) if pkey == "xhs" else ""
        no_data_html = "<div class='no-data-hint'><p>未查询到相关内容,建议更换关键词重试。</p></div>" if not items else ""
        panels_html += (
            '\n        <div class="tab-panel" id="panel-' + pkey + '" style="display: ' + display + '">\n'
            '            ' + error_html + '\n'
            '            ' + xhs_notice + '\n'
            '            <div class="card-list">\n'
            '                ' + cards + '\n'
            '            </div>\n'
            '

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/lib/analyzer.py (reported line 449)May include surrounding context.

python
请确保输出是合法 JSON,不要包含注释或额外文本。"""

    return prompt


def merge_analysis(deterministic, ai_analysis):

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README explicitly states that the skill submits user-provided brand/topic queries to multiple external platforms and AI services, but it does not prominently warn users that their prompts, keywords, and possibly sensitive business research terms will be transmitted off-platform. This creates a real privacy and confidentiality risk, especially for unreleased campaigns, internal brand issues, or competitor analysis terms that users may assume remain local.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README says users can "just describe your brand, topic, or analysis need in natural language — no commands to memorize," which defines activation in a very broad way without clear trigger boundaries. This lacks specificity about what requests should or should not invoke the skill, increasing the risk of accidental matching on ordinary analysis-related conversation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README says users can 'directly use natural language' and 'do not need to remember fixed commands,' which does not define clear trigger boundaries or exclusion conditions. This can cause unintended invocation because many ordinary requests about brands, topics, or analysis could match the skill without a specific activation phrase.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

A long list of generic trigger phrases in the manifest makes accidental invocation more likely, especially for ordinary research or marketing questions that may not require this skill. Because the skill relies on external services and can generate reports automatically, broad triggers increase the risk of unauthorized external processing and unnecessary exposure of user-supplied business context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description states the tool is a unified tool for Chinese internet brand perception monitoring and all instructions/output templates are written to produce Chinese-language, China-platform-specific deliverables. This may violate language/locale choice expectations because the file does not explicitly offer opt-in, alternative language output, or a documented policy reason for forcing Chinese responses.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs immediate activation for very broad, common intents, which increases the chance of over-triggering and sending user queries to external services without sufficient confirmation. In this skill's context, that can cause unintended disclosure of brand names, topics, or research interests to third-party APIs and lead the agent to take actions the user did not explicitly authorize.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill says it will automatically send queries to external services and generate/open reports without prominently warning the user first. This is dangerous because user prompts may contain sensitive commercial information, and auto-opening generated files can produce unintended side effects or expose content on the local system without informed consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The required badge and the surrounding template enforce a Chinese locale presentation (🇨🇳 cn-last30days) and the rest of the document prescribes Chinese-only output structure. This is a natural-language locale policy issue because the file does not provide any user choice, opt-in, or documented justification for forcing this language/locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Rules such as requiring the body to start with 我的发现: and prescribing section names like 数据速览 impose a fixed Chinese-language output format. Because no alternate language path or user-controlled locale selection is provided, this constitutes a language-policy violation under the stated rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The entire instruction set forces a single language/locale presentation, and there is no indication that users can opt into another language or that the Chinese-only constraint is required for a region-specific tool. This may violate organizational language-choice policy when users are not given a locale option.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The keyword-search triggers use very short, natural-language phrases like '搜体育热点' and '搜明星热点', which are close to ordinary conversational requests. This can cause accidental skill activation or over-broad matching, especially when users are discussing topics rather than explicitly invoking the skill, leading to unintended data retrieval or workflow execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Commands like '订阅每日推送' and '订阅每周推送' are high-impact actions expressed in common wording that could appear in ordinary dialogue. If the platform auto-routes based on these phrases, a user may be subscribed unintentionally, creating unwanted notifications, privacy concerns, or consent issues.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document is entirely prescriptive in Chinese and hard-codes Chinese output labels and reply commands such as “回复「查看百度完整榜单」” and subscription phrases. This imposes a single language/locale for interaction without any opt-in or documented region-specific justification, which fits the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

User-provided search keywords are transmitted to a third-party API service, and the returned content is then processed and exported, but the code provides no explicit consent prompt or prominent warning before data leaves the local environment. In an agent skill context, users may reasonably assume a local analysis workflow, so silent transmission can expose sensitive brand, campaign, or investigation terms to an external provider.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This Python file contains natural-language instructions, descriptions, and output guidance entirely in Chinese, including the script description, usage, and next-step instructions. Because the file does not offer any user opt-in or explain that the skill is intentionally region-specific, it appears to impose a specific language/locale by default.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language instructions, argument descriptions, and output messages exclusively in Chinese. Under the policy, forcing a specific language without offering user choice or documenting a justified locale restriction is a violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language documentation and CLI/help text exclusively in Chinese, including the module docstring and environment-variable instructions. Because the skill does not offer users a language/locale choice, it can violate a language-policy requirement against forcing a specific language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The argparse descriptions, option help strings, and runtime error/status messages are all presented in Chinese only. This imposes a fixed locale on all users and is a natural-language policy issue unless the tool explicitly limits itself to a Chinese-only audience or allows opt-in language selection.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code sends user-supplied source, platform, keyword, and time-range data to an external HTTPS API and includes an API key from the environment in the request headers. Although the code has internal comments, there is no user-facing print/log message, confirmation, or explicit disclosure at runtime that data will be transmitted to a remote service.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script persists the full fetched results to a local temporary JSON file and then exposes the file path in output, which creates an unadvertised data-retention and local disclosure channel beyond simple fetching/formatting. In a multi-user host, shared workspace, or agent environment, that file may be readable by other processes or later steps, especially because the implementation uses insecure temporary-file creation later in the flow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script writes fetched results to a temporary JSON file without notice, creating unexpected local persistence of potentially sensitive search terms, brand-monitoring results, and URLs. In agent, CI, or shared-machine contexts this increases exposure because other tools or users may access the file, and the code does not ensure secure creation or cleanup.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.insecure_tls_verification

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
scripts/hub_fetch.py:184