Back to skill

Security audit

Java Api Extractor

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly performs Java API extraction, but it also creates extra local copies by default and can run an unreviewed neighboring upload script, so users should review it before installing.

Install only if you are comfortable with a tool that scans Java source trees for internal API structure. Use local-only extraction first, pass --no-backup if you do not want duplicate retained files, and do not use --push or --prdid unless you have verified the neighboring push script and approved the destination and contents being uploaded.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T07 · Tool Hijacking and Spoofing

Warning
Location
scripts/extract_java_api.py:356
Finding

Execution of an Unverified External Sibling Script

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/extract_java_api.py:333
Finding

Unexpected Default Backup of Extracted API Metadata in Python Implementation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/extract_java_api.js:363
Finding

Unexpected Default Backup of Extracted API Metadata in Node.js Implementation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (35)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill appears to do more than local JSON extraction: it may read a fixed template file, write to a default backup directory, and support pushing data to an external product platform through additional scripts. This is dangerous because the actual data flow includes local persistence and possible outbound transmission that are not clearly reflected in the declared purpose, increasing the chance of unreviewed disclosure of internal API metadata.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill appears to do more than local JSON extraction: it may read a fixed template file, write to a default backup directory, and support pushing data to an external product platform through additional scripts. This is dangerous because the actual data flow includes local persistence and possible outbound transmission that are not clearly reflected in the declared purpose, increasing the chance of unreviewed disclosure of internal API metadata.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
py scripts/extract_java_api.py --project "D:\working\coding\msa-icmp-dev-manage" --output api-definitions.json

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

md
py scripts/extract_java_api.py --project "D:\working\coding\msa-icmp-dev-manage" --output api-definitions.json

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

md
py scripts/extract_java_api.py --project "D:\working\coding\msa-icmp-dev-manage" --output api-definitions.json

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

md
py scripts/extract_java_api.py --project "D:\working\coding\msa-icmp-dev-manage" --output api-definitions.json

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

md
py scripts/extract_java_api.py --project "D:\working\coding\msa-icmp-dev-manage" --output api-definitions.json

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 152)May include surrounding context.

md
py scripts/extract_java_api.py --project "D:\working\coding\msa-icmp-dev-manage" --output api-definitions.json

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 84)May include surrounding context.

md
node scripts/extract_java_api.js --project "D:\working\coding\msa-icmp-dev-manage" --package "com.example.user.controller" --output user-api.json

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

md
node scripts/extract_java_api.js --project "D:\working\coding\msa-icmp-dev-manage" --package "com.example.user.controller" --output user-api.json

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 153)May include surrounding context.

md
node scripts/extract_java_api.js --project "D:\working\coding\msa-icmp-dev-manage" --package "com.example.user.controller" --output user-api.json

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/usage-examples.md (reported line 21)May include surrounding context.

md
✓ 提取接口:GET /api/users
  ✓ 提取接口:POST /api/users
  ✓ 提取接口:PUT /api/users/{id}
  ✓ 提取接口:DELETE /api/users/{id}
  ...

✅ 共提取 45 个接口定义

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill is described as extracting Java API definitions to JSON, but it also supports pushing the extracted results to an external product platform. This mismatch is security-relevant because users may run a supposedly local analysis tool without realizing it can exfiltrate potentially sensitive internal API metadata to another system.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The subprocess-based push path expands a local parsing utility into a data-transfer tool without that capability being justified by the stated purpose. In this skill context, the extracted data consists of internal controller routes and schemas, which can expose sensitive service structure if sent to an external platform.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises operational behaviors that imply shell execution, file reads, and file writes, but it declares no explicit tool scope or permissions. This weakens least-privilege controls and can let an agent invoke broader capabilities than a user would expect when only 'API extraction' is described.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill offers a direct 'push' path to an external product platform but does not warn users that extracted API definitions may leave the local environment. Because controller definitions can reveal internal endpoints, parameters, and architecture details, silent or poorly disclosed upload capability raises data leakage and compliance risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The Python usage examples include '--push' without any adjacent warning that it triggers external data transmission. Example commands are often copied verbatim, so omission of a warning materially increases the risk that users upload internal API metadata unintentionally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The Node.js examples repeat the same issue by presenting '--push' as a normal workflow step without disclosure of external transmission. Repetition across multiple examples normalizes uploading and increases the chance of accidental disclosure by users who assume the operation is still local extraction only.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The standard requires the name field to be an "接口中文名称", which imposes a Chinese-language output format. Because this markdown does not offer user opt-in or explain that the standard is intentionally China/Chinese-specific, it creates a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest describes this skill as extracting Java Controller interface definitions into JSON data, which implies a local analysis/output role. This reference file additionally points to a separate 'push' script for sending API data to a product platform, introducing behavior beyond extraction and suggesting a broader operational scope than the manifest claims.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The usage documentation expands the skill from local Java API extraction into pushing extracted API definitions to an external product platform. That materially changes the trust boundary and data-flow of the skill: internal endpoint definitions, paths, schemas, and product identifiers may be transmitted off-host without the narrow extraction-only scope stated in the metadata.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation describes a '--push' mode that sends extracted API definitions externally, but it does not provide a user-facing warning about outbound transmission. API definitions often reveal internal routes, object models, and product metadata, so silent transmission can create confidentiality and governance issues.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The natural-language invocation guidance is broad enough that an agent could interpret vague user requests as authorization to inspect a project and potentially perform follow-on actions like packaging or transmission. In an agent setting, underspecified triggers increase the risk of unintended access to source trees or execution of adjacent capabilities beyond simple extraction.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language examples invite users to request extraction and direct pushing to a product department data platform, despite the skill being described only as extracting controller definitions to JSON. Broadening the implied capability through casual prompts increases the chance that an agent sends sensitive API documentation externally based on an ambiguous request.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The workflow examples automate pushing API definitions in Git hooks, CI/CD, and build integration, turning a local analysis utility into an automated data-exfiltration path. Because this can run on every push or compile, sensitive internal API structure may be exported continuously and without interactive review.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.