Back to skill

Security audit

Api Design

Security checks for vulnerabilities and agentic risk

Overview

This is a Markdown-only API design reference skill; the main caution is that some documentation examples use unpinned external CLI and Docker tooling if a user chooses to run them.

Reasonable to install if you want API design and OpenAPI reference material. Before running commands copied from the documentation, pin npm package versions, Docker image digests, GitHub Action commits, and remote rulesets; prefer project-local dependencies over global installs. Treat all tokens, passwords, URLs, and user data in the examples as placeholders.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
references/documentation/doc-generation-guide.md:178
Finding

Mutable and Unpinned Third-Party Tooling Creates Supply-Chain Execution Risk

Content
View full analysis
Remediation
View remediation
lint openapi.yaml npx --yes @redocly/cli@ build-docs openapi.yaml ``` - Prefer project-local development dependencies recorded in `package.json` and a committed lockfile. - Use `npm ci` in automation to enforce lockfile resolution. - Verify package provenance and integrity before adoption. 2. **Avoid global package installation** - Replace `npm install -g @redocly/cli` with a pinned project-local dependency. - Run the local binary through a package script or an explicitly pinned `npx` invocation. 3. **Vendor or immutably pin the Spectral ruleset** - Store a reviewed copy in the project, for example: ```bash spectral lint openapi.yaml --ruleset ./config/spectral.yaml ``` - If remote retrieval is unavoidable, reference a specific immutable commit rather than `master`, verify its checksum, and restrict outbound access in CI. 4. **Pin the Docker image by digest** - Use a reviewed immutable image reference: ```bash docker run --rm -p 127.0.0.1:8080:80 \ -e SWAGGER_JSON=/spec/openapi.yaml \ -v "$(pwd)/openapi.yaml:/spec/openapi.yaml:ro" \ swaggerapi/swagger-ui@sha256: ``` - Mount the OpenAPI file read-only and bind the preview port to localhost where remote access is unnecessary. 5. **Pin GitHub Actions to full commit SHAs** - Replace `actions/checkout@v2` with a supported release pinned to a reviewed full commit SHA. - Configure minimal workflow permissions, such as read-only repository contents unless deployment explicitly requires more access. 6. **Harden CI execution** - Do not expose unrelated secrets to documentation jobs. - Restrict job permissions and outbound network access. - Separate build and deploymen ...[truncated 169 chars]
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (35)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/common/design-principles.md (reported line 14)May include surrounding context.

md
| `POST /createUser` | `POST /users` |
| `GET /getUserById/123` | `GET /users/123` |
| `POST /updateUser` | `PATCH /users/123` |
| `DELETE /deleteUser/123` | `DELETE /users/123` |

### 2. 使用正确的 HTTP 方法

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/common/design-principles.md (reported line 14)May include surrounding context.

md
| `POST /createUser` | `POST /users` |
| `GET /getUserById/123` | `GET /users/123` |
| `POST /updateUser` | `PATCH /users/123` |
| `DELETE /deleteUser/123` | `DELETE /users/123` |

### 2. 使用正确的 HTTP 方法

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/common/error-response-format.md (reported line 143)May include surrounding context.

md
{
  "error": {
    "code": "AUTH_002",
    "message": "Access token has expired. Please refresh your token."
  }
}

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/design/endpoint-design.md (reported line 14)May include surrounding context.

POST /users # 创建用户 GET /users/123 # 获取用户 PATCH /users/123 # 更新用户 DELETE /users/123 # 删除用户

text

#### 动作端点(特定场景)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/design/resource-modeling.md (reported line 113)May include surrounding context.

POST /users # 创建用户 GET /users/123 # 获取用户 PATCH /users/123 # 更新用户 DELETE /users/123 # 删除用户

text

#### 动作端点(特定场景)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/design/endpoint-design.md (reported line 194)May include surrounding context.

批量删除

bash
DELETE /users/batch

Body:
{

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

The trigger is recorded only in Chinese, which can imply a language-specific activation condition or usage expectation. The file does not indicate that users may choose another language or that the locale restriction is intentional and justified, so this appears to violate the language/locale policy criterion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file presents its headings and explanatory content in Chinese, while the policy category requires flagging language or locale constraints that force a specific language without user opt-in. The file does not indicate that Chinese is optional, selectable, or justified as a region-specific requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file is primarily written in Chinese, which imposes a specific language on readers. The policy allows locale constraints only when the skill offers user choice or clearly documents a justified region-specific need, neither of which appears here.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/design/security-best-practices.md (reported line 247)May include surrounding context.

http
# ❌ 不安全
http://api.example.com/users

# ✅ 安全
https://api.example.com/users

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

The Docker example uses swaggerapi/swagger-ui without a tag or digest, so users will pull whatever image is current at execution time. This weakens reproducibility and introduces supply-chain risk if the image is replaced, retagged, or compromised upstream.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/documentation/doc-generation-guide.md (reported line 80)May include surrounding context.

3. 代码示例

cURL 示例

bash
# 获取用户列表

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The documentation tells users to run npx @stoplight/spectral without pinning a version. This causes execution of the latest package version at runtime, which creates supply-chain risk if a malicious or compromised release is published or if behavior changes unexpectedly.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The GitHub Actions example runs npx @redocly/cli build-docs openapi.yaml without an explicit version. In CI this can pull and execute an unexpected upstream release, making builds non-reproducible and exposing consumers to package supply-chain compromise.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/design/security-best-practices.md (reported line 250)May include surrounding context.

md
url: https://opensource.org/licenses/MIT

servers:
  - url: https://api.example.com/v1
    description: Production server
  - url: https://staging-api.example.com/v1
    description: Staging server

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/design/security-best-practices.md (reported line 258)May include surrounding context.

md
url: https://opensource.org/licenses/MIT

servers:
  - url: https://api.example.com/v1
    description: Production server
  - url: https://staging-api.example.com/v1
    description: Staging server

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/documentation/doc-generation-guide.md (reported line 47)May include surrounding context.

md
url: https://opensource.org/licenses/MIT

servers:
  - url: https://api.example.com/v1
    description: Production server
  - url: https://staging-api.example.com/v1
    description: Staging server

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/documentation/doc-generation-guide.md (reported line 84)May include surrounding context.

md
url: https://opensource.org/licenses/MIT

servers:
  - url: https://api.example.com/v1
    description: Production server
  - url: https://staging-api.example.com/v1
    description: Staging server

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/documentation/doc-generation-guide.md (reported line 89)May include surrounding context.

md
url: https://opensource.org/licenses/MIT

servers:
  - url: https://api.example.com/v1
    description: Production server
  - url: https://staging-api.example.com/v1
    description: Staging server

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/documentation/doc-generation-guide.md (reported line 103)May include surrounding context.

md
url: https://opensource.org/licenses/MIT

servers:
  - url: https://api.example.com/v1
    description: Production server
  - url: https://staging-api.example.com/v1
    description: Staging server

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/documentation/doc-generation-guide.md (reported line 125)May include surrounding context.

md
url: https://opensource.org/licenses/MIT

servers:
  - url: https://api.example.com/v1
    description: Production server
  - url: https://staging-api.example.com/v1
    description: Staging server

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/templates/openapi3-template.md (reported line 23)May include surrounding context.

md
url: https://opensource.org/licenses/MIT

servers:
  - url: https://api.example.com/v1
    description: Production server
  - url: https://staging-api.example.com/v1
    description: Staging server

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The template recommends running an npm package with npx without pinning an exact version, which allows whatever the latest published package is at execution time to run on the user's machine. If the package is compromised, a malicious version is released, or a dependency chain is poisoned, users following the template could execute untrusted code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This example invokes npx @stoplight/spectral without an explicit version, causing users to fetch and execute the current package version at runtime. That creates a supply-chain risk because the template normalizes execution of mutable third-party code with no version control or review point.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

Line L08 describes the skill purpose in Chinese, but the file does not state that the skill is Chinese-only, region-specific, or that users can choose their preferred language. This can conflict with language/locale policy expectations when a skill implicitly forces one language without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/common/design-principles.md:149

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/design/security-best-practices.md:18