Back to skill

Security audit

懂车帝用户搜索和作品订阅

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent, but it disables HTTPS certificate checks while sending an API key and can create recurring daily automation tasks, so it should be reviewed before use.

Install only if you are comfortable giving this skill a RedFox API key and allowing it to create recurring daily automation tasks. The TLS certificate bypass should be fixed before using the key on untrusted networks, and subscription creation should clearly confirm the recurring task and explain how to cancel it.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/search_user.py:51
Finding

TLS Certificate Verification Disabled for Authenticated API Requests

Content
View full analysis

Vulnerability Details

File Location: scripts/search_user.py:51-55, scripts/work_list.py:49-53
Vulnerability Type: Improper TLS certificate validation
Risk Level: High

Complete Code Snippet

The same vulnerable TLS configuration appears in both scripts:

python
def _ssl_context():
    """Create an SSL context compatible with multiple environments."""
    try:
        ctx = ssl.create_default_context()
        ctx.check_hostname = False
        ctx.verify_mode = ssl.CERT_NONE
    except Exception:
        ctx = None
    return ctx

The resulting context is passed to authenticated HTTPS requests:

python
req = urllib.request.Request(
    API_URL,
    data=payload,
    headers={
        "Content-Type": "application/json",
        "X-API-Key": api_key,
        "User-Agent": "QoderWork/1.0",
    },
    method="POST",
)

ctx = _ssl_context()
kwargs = {"timeout": 30}  # 60 seconds in work_list.py
if ctx:
    kwargs["context"] = ctx
with urllib.request.urlopen(req, **kwargs) as resp:
    result = json.loads(resp.read().decode("utf-8"))

Technical Analysis

Both scripts create a standard TLS context but then explicitly disable hostname checking and certificate verification. Consequently, the HTTPS connection encrypts traffic without authenticating the remote endpoint.

The requests include the user's REDFOX_API_KEY in the X-API-Key header. Because any certificate is accepted, a network-positioned attacker can impersonate redfox.hk, terminate the TLS connection, and receive the API credential and request payload.

The scripts also trust and parse the unauthenticated response as API data. This allows an interceptor to modify user records, work metadata, and externally displayed URLs. The issue is reachable whenever either script performs its normal API operation.

Attack Path

  1. A user invokes user search or work-list retrieval.
  2. The script loads REDFOX_API_KEY from the environment or local configuration.
  3. An attac ...[truncated 1055 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove both statements that disable hostname and certificate validation:
    python
    ctx.check_hostname = False
    ctx.verify_mode = ssl.CERT_NONE
    
  • Use the default verified context without modification:
    python
    def _ssl_context():
        return ssl.create_default_context()
    
  • Fail closed if a secure SSL context cannot be created rather than falling back to behavior that may weaken transport security.
  • Ensure the runtime has an up-to-date trusted CA bundle instead of bypassing validation for compatibility.
  • Apply the correction consistently in both search_user.py and work_list.py.
  • Add tests confirming that certificates signed by an untrusted authority and certificates with a mismatched hostname are rejected.
  • Rotate the API key if the vulnerable scripts have been used over an untrusted network.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (19)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述的是一个“用户搜索 + 作品订阅”综合工具,但提供的代码块功能范围明显更窄。该脚本唯一的核心行为是向 https://redfox.hk/story/api/dongchedi/searchUser 发送请求,按关键词搜索懂车帝用户,并格式化返回基础用户信息。代码中没有任何获取某个用户作品列表的 API 调用,也没有作品字段处理逻辑,更没有订阅、定时任务、消息推送或持久化订阅关系的实现。因此,描述显著夸大了代码实际能力,属于描述与行为不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明描述的是一个综合性的“懂车帝用户搜索和作品订阅工具”,覆盖搜索作者账号、展示作者信息、查看作品、订阅并自动推送更新等多项能力。但提供的代码文件 work_list.py 只接受 userId 作为输入,向 https://redfox.hk/story/api/dongchedi/workList 发起请求,获取作品列表并格式化输出;附加功能仅是本地按日期过滤。代码中没有任何搜索用户接口调用、没有处理粉丝数/简介字段、没有订阅持久化逻辑、没有定时任务或推送逻辑。因此,实际行为只是声明中的一个子功能,且与整体描述相比存在明显能力缺失,属于描述与代码行为不一致。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill advertises daily 9:00 subscription pushes but does not present a strong, explicit warning that this creates ongoing automated notifications until unsubscribed. Users may subscribe without understanding persistence, frequency, or how to stop delivery, which weakens informed consent and can lead to unwanted monitoring or repeated outbound messages.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README says users can 'just describe in natural language' what they want, which creates very loose trigger boundaries for when the skill should activate or what actions it may infer. In a multi-skill or agentic environment, overly broad invocation can cause unintended execution paths, ambiguous state transitions, or accidental access to search/subscription actions when the user did not clearly consent.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · README.en.md (reported line 77)May include surrounding context.

md
After selecting a user (e.g., replying "1"), their work list is displayed:

| #   | Publish Time     | Work Title                                                                                        | Type  | Reads | Likes | Comments | Collects |
| --- | ---------------- | ------------------------------------------------------------------------------------------------- | ----- | ----- | ----- | -------- | -------- |
| 1   | 2026-09-28 16:03 | [又想合资又想电动又想舒适智能——别克至境E7再推新](https://www.dcdapp.com/motor/m/feed/detail?link_source=share&group_id=7690492951143268888) | Video | 1145  | 37    | 7        | 0        |

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill advertises automatic daily subscription pushes but does not clearly warn users about ongoing notifications, persistence of the subscription state, or what user/account data is retained to deliver those pushes. This can lead to privacy surprises, unwanted notifications, and consent issues, especially because the feature creates a continuing action beyond the current session.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README says users can 'directly use natural language' and '无需记忆固定命令', which does not define clear trigger boundaries or exclusions. This makes activation conditions ambiguous and increases the chance the skill is invoked by broad everyday phrasing rather than a constrained set of commands.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The usage instructions and example utterances assume Chinese-language input and do not mention whether other languages are supported or that Chinese is a required locale. Under the policy, forcing a specific language without opt-in or justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · README.md (reported line 77)May include surrounding context.

md
选中用户(如回复「1」)后,将展示该用户的作品列表:

| #   | 发布时间            | 作品标题                                                                                          | 类型 | 阅读 | 点赞 | 评论 | 收藏 |
| --- | ------------------ | ------------------------------------------------------------------------------------------------- | ---- | ---- | ---- | ---- | ---- |
| 1   | 2026-09-28 16:03   | [又想合资又想电动又想舒适智能——别克至境E7再推新](https://www.dcdapp.com/motor/m/feed/detail?link_source=share&group_id=7690492951143268888) | 视频 | 1145 | 37   | 7    | 0    |

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs users to place an API key in shell environment variables or a local config file without warning that the credential is sensitive, long-lived, and should be protected from logs, screenshots, shell history, and repository check-in. This increases the chance of accidental credential leakage, which could allow unauthorized use of the associated API and any accessible data or billable resources.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script explicitly disables TLS hostname checking and certificate verification before sending requests that include the Redfox API key in the X-API-Key header. This enables man-in-the-middle interception or response tampering by any attacker able to influence the network path, which is especially risky for a skill that contacts a third-party API over the internet.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The helper explicitly disables TLS certificate validation by setting check_hostname=False and verify_mode=ssl.CERT_NONE, which allows man-in-the-middle interception or tampering of API traffic. Because this script sends an API key in the X-API-Key header and trusts the returned JSON, an attacker on the network path could steal credentials or modify work-list data without detection.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The outbound request is made with certificate verification disabled and there is no warning, opt-in, or constrained fallback behavior. In this skill context, the script communicates with a third-party API and includes a sensitive API key, so silent TLS bypass materially increases the chance of credential exposure and response tampering.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and CLI description say this is a '懂车帝用户搜索和作品订阅' script/tool, implying both search and subscription support. In the actual code, the only implemented operation is sending a search request to the searchUser API and printing formatted user-search results; there is no code to subscribe users or manage subscription state.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The stated skill purpose includes pulling a selected user's work list with titles, stats, and links. This file never calls any work-list API and only returns user profile fields such as nickname, followers, bio, avatar, and profile URL.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

Natural-language strings in the module docstring, CLI description, help text, and runtime error messages are all presented in Chinese only. This forces a specific language for all users without any documented opt-in or locale selection, which matches the language-policy violation criteria.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The manifest describes a user-facing Dongchedi search/subscription tool, but does not mention dependence on third-party Redfox credentials or local secret loading. While credential use may be operationally necessary, reading secrets from environment variables and ~/.qoder/apis/redfox.json is an additional capability outside the stated functional scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The module docstring, CLI description, help text, and user-facing messages are written in Chinese, with no option for another language. Under the stated policy, forcing a specific language without offering user choice can be a locale/language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.insecure_tls_verification

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
scripts/search_user.py:54

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
scripts/work_list.py:54