Back to skill

Security audit

Api Push Product Platform

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its stated purpose, but it pushes potentially sensitive API documentation to a hardcoded external HTTP endpoint and documents optional automation that could send data during git workflows.

Review the destination before installing or using this skill. Do not send confidential, production, credential-bearing, or customer-sensitive API definitions through the documented HTTP endpoint; require HTTPS, explicit approval before each push, and a trusted authenticated destination. Avoid copying the pre-push hook unless your team deliberately wants automatic submissions during git operations.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/push_api_to_product_platform.py:22
Finding

API Definitions Transmitted over Unencrypted HTTP

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill clearly performs network transmission and references local files/scripts, yet it declares no explicit tool scope or permissions boundary. In an agent environment, this can allow unintended file access and outbound requests without transparent user consent or platform-level restriction, increasing the risk of data exfiltration or misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill documents an external HTTP endpoint and instructs users to send API definition content, but it does not prominently warn that potentially sensitive internal interface metadata will be transmitted off-system. This is more dangerous in context because backend Java API definitions often contain internal paths, parameters, schemas, and business logic details that may be confidential, and the endpoint uses plain HTTP rather than HTTPS.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language trigger '直接告诉我需求,我引导你完成推送' is broad enough that routine conversation about APIs or product requirements could activate a workflow that prepares or sends data externally. Overbroad invocation raises the chance of accidental execution, especially when the skill's core action is network transmission of potentially sensitive interface definitions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file title and all instructions are written exclusively in Chinese, and the document presents the standard as universally applicable without offering any language or locale choice. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is clearly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document directs users to POST internal API definition data to a remote endpoint over plain HTTP, which exposes potentially sensitive API metadata to interception and tampering in transit. Because the skill also frames this as a normal workflow without any warning, users may unknowingly exfiltrate internal architecture details outside the repository and organization boundary.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The pre-push hook automates outbound submission whenever matching files change, creating silent data transmission during a common developer workflow. This increases the likelihood of accidental disclosure of internal API specifications and can surprise users by coupling source-control actions to network exfiltration without clear consent or review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script transmits API definition content to a remote endpoint automatically, but in normal mode it does not clearly warn the user that potentially sensitive internal API metadata will be sent off-host. Because API definitions often contain internal paths, parameters, auth expectations, and business logic details, silent or non-obvious transmission increases the risk of unintended data disclosure, especially when users invoke the tool with only a file path or inline JSON.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file presents all user-facing instructions and labels exclusively in Chinese. Under the language/locale policy rule, forcing a specific language without offering user choice or documenting a justified locale constraint can be a policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

All natural-language docstrings, CLI descriptions, help text, and runtime messages are presented only in Chinese. That creates a locale/language constraint without any opt-in or alternative, which matches the policy category for forced language usage.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.