Back to skill

Security audit

UAPI 步骤2 (方法一): 获取加密数据 接口

Security checks for vulnerabilities and agentic risk

Overview

This is a documented helper for one Clipzy/UAPI read endpoint, with no executable code or persistence, though its activation wording is broader than ideal.

Install only if you intend to use the Clipzy/UAPI encrypted data retrieval endpoint. Prefer invoking it explicitly by name or endpoint because the published trigger terms are broad enough that an agent might select it for unrelated requests involving the word get; review any request before sending ids or API keys to UAPI.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill advertises extremely broad trigger terms such as "get" and "clipzy" in its metadata description, which creates a high risk of unintended invocation during normal user conversations. In an agent environment, accidental routing to the wrong skill can cause inappropriate API calls, context leakage to an external service, or execution of actions the user did not specifically intend.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Ambiguous English triggers like "api get" are too generic and can match many unrelated requests involving APIs or GET operations. This increases the chance the agent selects this skill outside its intended Clipzy/UAPI context, potentially sending user-provided data to an unintended endpoint or causing confusing, incorrect workflow execution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The file's natural-language instructions and interface description are entirely in Chinese, and there is no indication that users can choose another language or that the skill is intentionally limited to a Chinese-speaking context. This can conflict with organizational language/locale policies that require user choice or explicit justification for locale constraints.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This quick-start guidance is primarily written in Chinese, but it also includes English keywords and example phrases as activation guidance. Because the skill does not state whether language handling is user-selectable or intentionally bilingual, it may imply a language/locale behavior without explicit opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.