Back to skill

Security audit

HotBee 全网热榜

Security checks for vulnerabilities and agentic risk

Overview

The skill is narrowly aimed at HotBee ranking lookups, but it tells users to run unreviewed GitHub-hosted code with local API-key access.

Install only if you are comfortable running the referenced third-party GitHub package locally. Prefer a commit-pinned or registry-published version, expose HOTBEE_API_KEY only for approved live calls, and assume the key may appear in URL logs unless the client and service redact it.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
references/api.md:34
Finding

Remote Code Execution Through a Mutable GitHub-Hosted npm Dependency

Content
View full analysis

Vulnerability Details

File Location: references/api.md:34-36; equivalent commands also appear at SKILL.md:27 and references/api.md:22-30
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Complete Code Snippet:

bash
npx -y github:shanye1402-hash/hotbee-social-data-skills#v1.1.0 call hot-rankings --dry-run --platform baidu --platform douyin

Technical Analysis

The documented command instructs the agent to use npx -y to download and execute a package directly from a third-party GitHub repository. The dependency is identified by the mutable Git tag v1.1.0, rather than an immutable audited commit hash or a package protected by lockfile integrity metadata.

The -y option automatically accepts package installation without an interactive confirmation. In addition, the documented --dry-run argument is passed to the downloaded application; it does not prevent npm from downloading the dependency or executing applicable package lifecycle behavior before the application handles that argument.

The downloaded implementation is not included in this project, so its source, dependency tree, installation hooks, and runtime behavior could not be audited. If the repository, maintainer account, dependency chain, or Git tag is compromised, the externally hosted payload can change after this Skill has been reviewed.

Attack Path

  1. An attacker compromises the referenced GitHub repository, a maintainer account, or an upstream dependency.
  2. The attacker moves or replaces the v1.1.0 tag, or otherwise causes the referenced package to resolve to malicious content.
  3. A user or agent follows the Skill documentation and executes the npx -y command.
  4. npm retrieves the attacker-controlled package and may execute its installation lifecycle scripts.
  5. The malicious package executes with the permissions of the agent process.
  6. The payload can access files, environment variable ...[truncated 1012 chars]
Remediation
View remediation

Remediation Suggestions

  1. Vendor the required implementation into the reviewed project and audit its source code and dependency tree before execution.
  2. If GitHub retrieval is unavoidable, pin the dependency to a specific audited commit SHA rather than a mutable tag.
  3. Verify downloaded content against a separately maintained cryptographic digest or signature.
  4. Avoid npx -y for untrusted remote sources. Require explicit user approval before installation and execution.
  5. Disable npm lifecycle scripts where compatible, for example by using --ignore-scripts, and separately verify that the package does not depend on them.
  6. Run the dependency in a restricted sandbox with minimal filesystem access, a constrained network policy, and no unrelated credentials.
  7. Expose HOTBEE_API_KEY only to the specific process and only for the duration of an approved live request.
  8. Maintain a lockfile or equivalent dependency manifest with integrity metadata for all transitive dependencies.
  9. Clarify in the documentation that application-level --dry-run does not make remote package installation safe.

T09 · Insecure Skill Coding Practices

Warning
Location
references/api.md:5
Finding

API Credential Transmitted in a GET Query Parameter

Content
View full analysis

Vulnerability Details

File Location: references/api.md:5-9; the same contract is also documented at SKILL.md:15-23
Vulnerability Type: Sensitive credential exposure through URL logging
Risk Level: Medium

Complete Code Snippet:

markdown
All confirmed hot-ranking endpoints use:

- Method: `GET`
- Required query: `key`
- Default key source: `HOTBEE_API_KEY`

Technical Analysis

The API contract requires HOTBEE_API_KEY to be supplied as the key query parameter of a GET request. Consequently, the credential becomes part of the request URL.

Although HTTPS protects the request in transit from ordinary network observers, it does not prevent URL exposure at endpoints that process or record the request. Full URLs and query strings are commonly retained by HTTP clients, reverse proxies, API gateways, observability platforms, server access logs, error reports, and debugging tools. Query parameters may also be exposed in diagnostic output if request failures are logged without redaction.

This design conflicts with the instruction in SKILL.md not to echo or persist the key because infrastructure outside the Skill may persist the complete URL automatically.

Attack Path

  1. The agent reads HOTBEE_API_KEY from its local environment.
  2. It constructs a live GET request containing the credential in the URL, such as ?key=REDACTED.
  3. A client, proxy, gateway, monitoring service, or destination server records the complete request URL.
  4. A user or attacker with access to those logs, traces, diagnostics, or error records retrieves the API key.
  5. The exposed key is reused to make unauthorized HotBee API requests until it is revoked, rotated, or exhausted.

Impact Assessment

Exposure grants the attacker the API capabilities assigned to the compromised key. Based on the documented behavior, this can include access to paid hot-ranking endpoints and consumption of the account's quota or p ...[truncated 425 chars]

Remediation
View remediation

Remediation Suggestions

  1. Change the API contract to transmit credentials in an HTTP authorization header, preferably Authorization: Bearer, rather than in the URL.
  2. If the upstream API cannot be changed, configure every client, proxy, gateway, monitoring system, and server to redact the key parameter before logging.
  3. Ensure errors and debug output never include the complete request URL.
  4. Use short-lived, narrowly scoped API credentials with strict quota and billing limits.
  5. Rotate the key periodically and immediately after any suspected logging or disclosure.
  6. Restrict the key by source network, permitted endpoint, or account policy where the provider supports such controls.
  7. Add automated tests that confirm secrets are removed from logs, traces, exceptions, and dry-run output.
  8. Preserve the existing requirement not to echo or persist HOTBEE_API_KEY, and explicitly document the residual risk of the upstream query-parameter contract.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The skill instructs users to execute code directly from a GitHub repository via npx -y github:...#v1.1.0, which does not provide the same immutability and supply-chain assurance as using a pinned package version with verified integrity. If the referenced repo, tag, or dependency chain is tampered with, users may run attacker-controlled code locally, potentially exposing environment secrets such as HOTBEE_API_KEY or allowing arbitrary command execution.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The natural-language instruction says to select interfaces based on '中文平台词', which imposes a Chinese-language/platform constraint in the skill behavior. The file does not indicate that users can opt into another language or locale, nor does it justify this as a region-specific compliance requirement.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.