Back to skill

Security audit

115 Publish

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its 115 cloud-drive purpose, but it needs review because it saves reusable account cookies and can change cloud files without the confirmations its documentation promises.

Install only if you are comfortable giving this skill access to your 115 account and cloud-file structure. Review the cookie storage behavior, avoid the alternate web-auth flow until TLS validation is fixed, and use smart organization only after manually confirming the files and destination because the current implementation can move files immediately.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
lib/auth-web.js:15
Finding

TLS Certificate Verification Is Disabled During Web Authentication

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
lib/client/http-client.js:147
Finding

115 Session Cookies Can Be Sent to Arbitrary Absolute URLs

Content
View full analysis
this.request(req.endpoint, req.options).catch(err => ({ error: err.message }))) ); results.push(...batchResults); if (i + batchSize < requests.length) { await this.sleep(500); } } return results; } ``` ### Technical Analysis The request method treats every string beginning with `http` as an already complete URL. It does not verify th ...[truncated 1961 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
lib/storage/cookie-store.js:43
Finding

Cookie Encryption Key Is Derived from Predictable Machine Metadata

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
index.js:260
Finding

Bulk Cloud-File Reorganization Executes Without a Preview or Explicit Confirmation

Content
View full analysis
f.is_dir).forEach(dir => { dirMap[dir.file_name] = dir.file_id; }); } for (const [category, categoryFiles] of Object.entries(classified)) { const targetCid = dirMap[category]; for (const file of categoryFiles) { if (file.is_dir) { results.skipped++; continue; } try { if (!dryRun) { await this.operations.moveFiles(file.file_id, targetCid); } results.mov ...[truncated 1893 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (72)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code persists active authentication cookies to storage with no visible safeguards such as encryption, scope restriction, secure lifecycle controls, or user consent handling. Stored session cookies can be replayed to hijack the user's 115 account, and this skill's purpose—automated QR login and cookie harvesting—makes the risk more acute than in ordinary web automation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The HTTPS client is explicitly configured with rejectUnauthorized: false, which disables TLS certificate validation for requests in the web login flow. This allows man-in-the-middle attackers to intercept or alter QR-login responses and potentially steal session cookies or inject attacker-controlled authentication data.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The clearRecycleBin method directly calls /files/clear_recycle and returns success, but there is no confirmation prompt, user-facing notice, or warning comment describing the destructive nature of emptying the recycle bin. This is a safety-critical operation that can permanently affect user data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The offline download feature accepts magnet/HTTP inputs and initiates remote network activity, but the documentation does not clearly warn users about privacy implications, third-party fetching, or account/network traces created by such tasks. In a cloud-drive context, that omission increases the chance users trigger behavior without understanding that it causes persistent external retrieval operations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrase '下载 xxx' is broad enough to match ordinary conversational requests or unrelated download intents, which can cause the skill to invoke offline download behavior unexpectedly. In this skill, that behavior creates network-side tasks and may consume account resources, so accidental activation has real side effects beyond a harmless misunderstanding.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The smart organization feature can automatically classify and move files, which changes file structure and may disrupt user organization or workflows, yet the description does not clearly warn about those side effects. In this skill, file-management actions operate on cloud storage state, so insufficient warning can lead to unintended bulk modifications that are difficult to review or reverse.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The phrase '整理文件' is vague and maps to an operation that can reorganize user data, potentially moving many files at once. Because this skill manages cloud storage contents, an imprecise trigger raises the risk of unintended bulk modification to folder structure and user workflows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill performs a state-changing cloud storage operation (autoOrganizeByType) immediately when the message contains words like '自动' or '智能', without presenting a preview, warning, or explicit confirmation. Because this action moves user files in remote storage, ambiguous natural-language input or accidental triggering could cause unintended reorganization and operational disruption.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The code reads authenticated browser cookies after QR login and converts them into reusable credential fields, then later saves them via the cookie store. Although comments describe the mechanics, there is no user-facing prompt, log message, or warning that sensitive authentication material will be collected and stored.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

On successful login, the code saves authentication cookies via this.cookieStore.save(status.cookie), which is a sensitive write of credential material. While the file has internal comments about login flow, it does not provide any user-facing prompt, warning, or disclosure that session cookies will be stored.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module persists long-lived login cookies locally for up to 90 days, but the code provides no built-in disclosure, consent, or safeguards around storing authentication material. In a chat/agent context, silently retaining reusable session tokens increases the risk of account compromise if local storage is exposed, misconfigured, or accessed by other components.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code attaches a Cookie header containing UID/CID/SE values to outbound axios requests, which is a network operation transmitting sensitive authentication data. While the code has technical comments about request handling, it does not include any user-facing warning, confirmation, or disclosure that credentials will be sent over the network.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The module stores potentially sensitive fields such as userInput, assistantOutput, details, and context in memory and later exposes records through getHistory() and export() with no redaction, consent check, or sensitivity warning. In an agent context, history often contains secrets, prompts, tokens, personal data, or tool outputs, so exporting or displaying it wholesale can cause unintended data disclosure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module returns user-visible strings such as 暂无历史记录, 历史记录, and 历史统计 only in Chinese, and relative time formatting is also fixed to Chinese phrases. This forces a specific language/locale without any opt-in or configuration path, which matches the policy category for language or locale violations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This JavaScript file includes natural-language recovery guidance such as 回复"登录 115"重新扫码 and 使用 /115 登录 命令 that assumes Chinese as the required interaction language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The code exposes a batchDelete method that performs irreversible remote deletion against '/rb/delete' for arbitrary file IDs without any built-in confirmation, safeguard, dry-run mode, or policy check in this module. In an agent or automation context, this raises the risk of accidental or prompt-induced mass deletion because a single mistaken call can remove many files at once.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The deleteFiles method issues a deletion request to /files/delete for one or more file IDs, but the code provides no confirmation prompt, warning log, or cautionary comment beyond the basic function description. Because deletion affects user data and may be safety-critical, this lacks visible disclosure within the file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This method reads a local file and sends its contents to a remote upload endpoint, which is a safety-relevant network transmission of user data. While the code has developer comments describing upload behavior, it provides no confirmation prompt, user-facing log/print, or explicit warning to the user before transmitting the file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The large-file path reads local file data in chunks and posts base64-encoded content to upload endpoints, which is a direct transmission of user file contents. The function contains internal comments for developers, but no confirmation, print/log message, or other user-facing notice that local data is being uploaded.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The download routine writes remote content directly to an arbitrary caller-supplied savePath without validating or constraining the destination. If untrusted input can influence savePath, this can overwrite sensitive local files or place attacker-controlled content in dangerous locations, making the file-writing behavior security-relevant beyond mere lack of disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill implements both single-task deletion and bulk cleanup of completed tasks through remote API calls, which are destructive operations affecting user-managed download tasks. Although methods are commented, there is no confirmation prompt, visible logging/print, or explicit warning to the user before deletion occurs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This module makes multiple API calls to enumerate file metadata, storage usage, recycle-bin contents, large files, duplicates, and temporary files, but the file itself contains no user-consent, disclosure, or permission-gating mechanism before inspecting potentially sensitive file information. Even if intended for cleanup assistance, this creates a privacy risk because a caller can trigger broad metadata collection and formatted reporting of filenames, locations, and identifiers without any visible notice or explicit opt-in at this layer.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill returns user-facing status messages, suggestions, and formatted reports exclusively in Chinese. This enforces a specific language/locale without offering the user a choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The autoOrganizeByType method creates folders and moves files, which changes user data layout and can be disruptive if triggered unexpectedly. Although a dryRun option exists, there is no confirmation prompt, user-facing log/output, or explicit warning comment/docstring that this operation will reorganize files in place.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The autoOrganizeByTime method automatically creates folders and moves files into them, which is a safety-relevant file modification operation. The code does not show any prompt, print/log statement, or explicit warning in the surrounding comments indicating that user files will be reorganized when dryRun is false.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal, suspicious.insecure_tls_verification

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
lib/storage/cookie-store.js:58

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
lib/auth-web.js:25