Back to skill

Security audit

Bing Webmaster Ronnie

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Bing Webmaster helper, but users should protect the API key and run write actions only for sites they control.

Install only if you are comfortable giving the skill a Bing Webmaster API key for the relevant verified sites. Prefer the environment variable over --api-key, avoid logging full request URLs, rotate any key that may have been used on a command line, and confirm URL submissions before using batch or scheduled workflows.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/fetch_data.py:66
Finding

API Key Exposure Through Command-Line Arguments in Data Retrieval Script

Content
View full analysis
--method [--api-key ] ``` ```python elif args[i] == "--api-key": api_key = args[i+1] ``` ### Technical Analysis The script advertises and accepts the Bing Webmaster API key as a command-line argument. Command-line secrets may be exposed through shell history, process listings, process-monitoring utilities, diagnostic collectors, audit logs, or automation logs. Although the script also supports the `BING_WEBMASTER_API_KEY` environment variable, retaining the command-line option creates an unnecessary secondary credential channel. It exceeds the minimum credential-handling privileges needed for the declared functionality because the integration can operate using the environment variable alone. ### Attack Path 1. A user invokes the script using `--api-key SECRET`. 2. The complete command is stored in shell history or exposed in the process command line while the script runs. 3. Another local user, monitoring process, support bundle, or log collector reads the command. 4. The exposed key is replayed against the Bing Webmaster API. 5. The attacker obtains whatever access the compromised key grants. Successful exploitation requires local process visibility, access to command history, or access to logs that capture command-line arguments. ### Impact Assessment An attacker could use the API key to retrieve Bing Webmaster information available to the associated account, including search queries, traffic statistics, crawl information, and URL-submission quota. The precise scope is limited to the permissions and verified sites associated with the compromised key. This flaw does not independently provide operating-system privilege escalation. ]]>
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/submit_urls.py:38
Finding

API Key Exposure Through Command-Line Arguments in URL Submission Script

Content
View full analysis
--urls [--api-key ] python3 submit_urls.py --site-url --file [--api-key ] ``` ```python elif args[i] == "--api-key": api_key = args[i+1] ``` ### Technical Analysis The URL-submission script accepts sensitive credentials through a command-line argument. The key can consequently appear in shell history, process tables, endpoint telemetry, debugging output, or job-runner logs. This exposure is avoidable because the script already reads `BING_WEBMASTER_API_KEY`. Supporting a command-line secret is therefore not necessary for the Skill's declared URL-submission functionality. ### Attack Path 1. A user or scheduled job starts the script with `--api-key SECRET`. 2. The command line is retained in history, job logs, process telemetry, or process-listing output. 3. A local user or party with access to those records recovers the key. 4. The attacker submits unauthorized URLs or invokes other Bing Webmaster operations permitted by the key. Successful exploitation requires access to local process information, command history, or relevant operational logs. ### Impact Assessment The compromised credential may allow unauthorized URL submissions for verified sites and access to other account data exposed by the same Bing Webmaster key. Abuse can consume submission quota, trigger unwanted crawl requests, and disclose site analytics. The maximum impact remains bounded by the key's server-side permissions. ]]>
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/fetch_data.py:42
Finding

API Key Embedded in Data Retrieval Request URLs

Content
View full analysis
`. 2. A proxy, gateway, tracing system, destination access log, or diagnostic component records the complete request URL. 3. A person or compromised service with access to that record extracts the API key. 4. The key is replayed directly against Bing Webmaster endpoints. 5. The attacker retrieves data or performs other actions allowed by the key. Exploitation depends on an intermediary or logging system retaining the query string and an attacker obtaining access to that retained data. ### Impact Assessment Disclosure can expose search queries, clicks, impressions, ranking information, crawl statistics, and submission quota for sites authorized by the key. If the same credential permits write operations, it may also suppo ...[truncated 126 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/submit_urls.py:84
Finding

API Key Embedded in URL Submission Request URLs

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The code substantially matches part of the description: it fetches Bing search traffic, keyword/query data, crawl statistics, and generates an SEO-style report. However, a key declared capability—submitting single or batch URLs for indexing—is absent. The only submission-related function present is quota retrieval via GetUrlSubmissionQuota, which checks allowance but does not submit URLs. Also, the description claims retrieval of indexing statuses, but the implemented crawl_stats path only calls GetCrawlStats and reports page crawl/error counts, not page-level indexing status. The mention of operating via GSC-verified site / without verification-file upload is also not reflected in the code. Because these are material declared capabilities rather than minor omissions, this is a description/behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a multi-purpose Bing Webmaster Tools helper covering both URL submission and multiple read/reporting capabilities. However, the supplied code only implements URL submission via the SubmitUrl/SubmitUrlbatch endpoints. There is no code to call traffic, keyword, indexing, or crawl-health endpoints, no parsing/reporting of such data, and no broader SEO audit logic. The submission capability is accurately represented, but the overall description materially overstates what this code chunk actually does.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares no explicit tool scope while the documentation indicates use of environment variables, local files, and external network access. Missing scope declarations weaken least-privilege controls and can lead to unintended access or invocation behavior, especially in agent environments where permissions are enforced from the manifest.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description states the skill can retrieve both crawl health and page indexing statuses. In the documented file, the only fetch methods shown are rank_traffic, query_stats, crawl_stats, quota, and all, and the described combined report includes crawl health but not indexing status data. That creates a semantic mismatch between the advertised capability and the documented behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill description omits a clear warning that URLs, search performance data, and crawl information are transmitted to Bing's external service. In a security-sensitive agent environment, lack of disclosure can cause users to share proprietary client data without informed consent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The statement that the skill will automatically activate once the environment variable is set suggests a broad activation trigger. In an agent system, broad auto-activation can cause the skill to run in contexts the user did not clearly intend, potentially sending URLs and site telemetry to an external API.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
78% confidence
Finding

The documentation normalizes URL submission without verification-file checks by assuming the configured account is already authorized. This encourages autonomous action against external web properties based only on ambient API-key access, which can lead to unintended modifications or submissions if the wrong site URL is provided or the skill is invoked broadly.

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

md
All scripts are in the skill's base directory `<base_dir>/scripts/`.

### 1. Instant URL Submission (No Verification File Needed)

Submit new or updated page URLs to Bing for fast crawling and indexing. This bypasses the need to upload any `.txt` or `.html` verification files since the domain is already validated in your Bing/GSC account.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The help text and implementation expose crawl_stats via GetCrawlStats, which provides aggregate crawl statistics and errors. There is no code calling any endpoint for page indexing status or per-page index inspection, so the implemented behavior is narrower than the manifest description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The API key is embedded in the query string, which can be exposed through logs, proxies, browser/history equivalents, error reports, or intermediary monitoring systems. In a skill that accesses webmaster data for client sites, leakage of this credential could permit unauthorized API access to search performance and site-management data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest explicitly says the skill can submit single or batch URLs to Bing for indexing, but the implemented methods are limited to rank_traffic, query_stats, crawl_stats, quota, and all. The only submission-related API used is GetUrlSubmissionQuota, which is read-only and does not perform URL submission.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script embeds the Bing Webmaster API key directly in the request URL query string. Query-string secrets are commonly exposed through shell history, process listings, proxy logs, browser/debug tooling, error messages, and upstream server logs, which can lead to credential leakage and unauthorized API use.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The description broadly suggests use for zymetalforming.com or any other B2B client sites, but the setup text says the skill works using your Bing Webmaster API key and examples rely on domains already validated in the user's Bing/GSC account. This is a narrower operational scope than the manifest implies.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest frames this as a Bing Webmaster Tools API helper for URL submission and SEO data retrieval. The SKILL.md additionally promotes pushing reports to Slack/DingTalk webhooks via scheduled automation, which expands into outbound notification/integration capability beyond the core Bing API helper purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.