Back to skill

Security audit

公众号搜索爬虫

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but its local report server can expose API-backed search access more broadly than users would expect.

Review this skill before installing. Use it only with a revocable RedFox API key, avoid sensitive internal search terms, prefer CSV-only or no-open mode when possible, and stop the local server promptly after viewing the report. The publisher should add proxy authentication/origin checks, safer HTML escaping, explicit activation wording, and pinned dependencies.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
assets/search.py:382
Finding

Generated HTML Reports Permit Script and Markup Injection

Content
View full analysis
``` `assets/report_template.html:538-542`: ```javascript const INITIAL_DATA = {{INITIAL_DATA}}; // ─── 状态 ──────────────────────────────────────────────────────────────────── let currentKeyword = '{{KEYWORD}}'; let currentOffset = 0; ``` `assets/report_template.html:640-652`: ```javascript const card = document.createElement('a'); card.className = 'article-card'; card.href = url; card.target = '_blank'; card.rel = 'noopener noreferrer'; card.innerHTML = `
${avatarHTML}
${escapeHTML(title)}
${escapeHTML(author)} ``` `assets/report_template.html:770-774`: ```javascript fallbackArticles.slice(0, 5).map(function(a) { return '' + escapeHTML(a.title || '无标题') + ' — ' + (a.author || '') + ''; }).join(''); ``` ### Technical Analysis The report generator performs direct string substitution into several different parsing contexts: - An HTML attribute - A Java ...[truncated 3195 chars]
Remediation
View remediation
``` Populate its `textContent` through a trusted template engine or escape at least `<`, `>`, `&`, U+2028, and U+2029 before embedding serialized JSON. 3. Avoid inserting the keyword into inline JavaScript. Read it from a safely populated DOM element or encode it with a JavaScript-string encoder. 4. Encode values according to their exact context: - HTML attribute encoding for `value` - JavaScript-string encoding for script literals - HTML text encoding for visible content - URL validation for links and images 5. Replace `innerHTML` construction with `document.createElement()`, `textContent`, and `setAttribute()` using validated values. 6. Permit only `https:` and, if necessary, `http:` URLs. Reject `javascript:`, `data:`, `file:`, and unknown schemes. 7. Validate remote cover-image URLs separately and restrict them to expected HTTPS hosts if practical. 8. Add a restrictive Content Security Policy that blocks inline scripts, object embedding, and unexpected network destinations. 9. Add regression tests using quotes, angle brackets, ``, event-handler markup, and dangerous URL schemes. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
assets/search.py:768
Finding

Unauthenticated Local Proxy Allows Cross-Origin Use of the API Credential

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:99
Finding

Requests Dependency Is Installed Without Version or Integrity Pinning

Content
View full analysis
Remediation
View remediation
``` 2. Include hashes generated from trusted artifacts and install with: ```bash pip install --require-hashes -r requirements.txt ``` 3. Pin and review transitive dependencies as well. 4. Use the official Python Package Index or an explicitly trusted internal mirror. 5. Periodically update pinned versions after vulnerability scanning and compatibility testing. 6. Recommend installation inside a dedicated virtual environment rather than the user's global Python environment. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (15)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/report_template.html (reported line 8)May include surrounding context.

html
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>公众号搜索 · {{KEYWORD}} | {{DATE}}</title>

<!-- Fonts: Space Grotesk (body) + Inter (fallback) -->
<link rel="preconnect" href="https://fonts.googleapis.com">
<link rel="preconnect" href="https://fonts.gstatic.com" crossorigin>
<link href="https://fonts.googleapis.com/css2?family=Space+Grotesk:wght@300;400;500;600;700&display=swap" rel="stylesheet">

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The invocation guidance 'Just say the keyword you want to search' is overly broad and can cause the skill to activate on ordinary user messages that merely mention a topic or keyword-like phrase. In an agent environment, this increases the chance of unintended crawling, external API usage, report generation, and data export without the user clearly intending to invoke this specific skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README says users can invoke the skill by simply speaking natural language keywords, without any explicit trigger phrase, scope boundary, or confirmation step. In an agent environment, this makes accidental activation more likely during ordinary conversation, which could launch web scraping/export actions and send user queries to external services without clear intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The example phrases are common, conversational requests like '搜一下 AI 相关的公众号文章', which overlap with normal chat behavior and do not indicate that a tool with external access will be used. In contexts where the agent auto-selects skills, this increases the chance of unintended scraping, data export, and third-party API usage.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill invokes Python code that uses environment variables, network access, shell execution semantics, and reads/writes local files, but the manifest does not declare any tool scope or permissions. This weakens informed consent and sandbox policy enforcement, making it easier for the skill to access sensitive resources or perform side effects without clear disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill sends user-provided search terms and API-key-authenticated requests to an external service, but the description does not prominently warn about this data flow. In a search/crawling context, queries may contain proprietary research topics or sensitive monitoring targets, so undisclosed transmission creates privacy and confidentiality risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

技能描述与模块文档都强调通过用户输入的关键词搜索公众号文章并展示结果,但这里在零结果时会自动把关键词缩短,甚至改用固定词“AI”进行兜底搜索。随后主流程还会把这些非原关键词结果作为推荐内容展示给用户,这与按指定关键词搜索的语义存在明显偏离。

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script starts a local HTTP server that exposes an /api/search endpoint and proxies requests using the stored API key. Although bound to 127.0.0.1, any local process or a malicious webpage via permissive CORS can send requests to this service and abuse the user's API-backed search capability, potentially consuming quota and leaking queried content through the browser context.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The local proxy forwards user-supplied search terms to an external third-party API together with the user's API key. External transmission is expected for a search crawler, but the added proxy interface broadens the trust boundary: untrusted local/browser-originated requests can trigger outbound calls using the resident credential, causing unauthorized API usage and privacy exposure of submitted queries.

Content

Scanner excerpt · assets/search.py (reported line 795)May include surrounding context.

python
def _do_proxy_request(self, payload):
        try:
            resp = requests.post(API_URL, json=payload,
                headers={"Content-Type": "application/json", "X-API-KEY": self.api_key}, timeout=15)
            self._send_json(resp.json())
        except Exception as e:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · assets/search.py (reported line 965)May include surrounding context.

python
if not args.no_open:
            step("打开浏览器...")
            try:
                subprocess.run(["open", url], check=True)
            except Exception:
                print(f"  请手动打开: {url}")

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The example queries are written as broad, everyday natural-language requests, which can train routing systems or users to treat normal conversational requests as valid activation triggers for the skill. This can lead to accidental invocation, unnecessary external requests, and unintended CSV/HTML output generation, though the impact is limited because the skill's function is search-oriented rather than directly privileged.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill behavior includes automatic creation of CSV/HTML files, starting a local HTTP service, and potentially auto-opening a browser, but this is not surfaced as a prominent warning in the skill description. Hidden side effects reduce user awareness and can lead to unexpected local exposure of report data or execution of actions the user did not anticipate.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The HTML document declares lang="zh-CN", and the visible UI text throughout the template is fixed in Chinese. For a general-purpose search/report template, this imposes a specific language/locale without any user opt-in or documented region-specific justification in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The user-facing description, usage guidance, prompts, and output are entirely in Chinese, which effectively imposes a single language/locale on users. The file does not indicate that other languages are supported or that Chinese is an opt-in or justified regional constraint.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

技能说明聚焦于公众号文章搜索与报告生成,没有提及会从环境变量或 ~/.qoder/apis/redfox.json 中读取凭据。虽然这在实现上可用于访问搜索 API,但从开发者意图审计角度看,这属于额外的凭据获取能力,应被明确声明。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.