Back to skill

Security audit

Doubao Assistant

Security checks for vulnerabilities and agentic risk

Overview

This documentation-only skill is not overtly malicious, but it needs review because it normalizes sending private prompts and knowledge-base content to an unverified external API while advertising broad exec and tool-calling capabilities.

Install only if you are prepared to review and tighten the integration before production use. Replace the placeholder API URL with a verified approved Doubao endpoint, avoid sending secrets or regulated data in prompts or RAG documents, require explicit approval for write or command actions, and enforce tool allowlists plus argument validation outside the model response.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:59
Finding

Potential disclosure of user conversations and private knowledge-base content to an unverified endpoint

Content
View full analysis
`[Document ${i+1}] ${doc.content}`) .join('\n\n'); const systemPrompt = `You are an enterprise knowledge assistant. Reference documents: ${context}`; const messages = [ { role: 'system', content: systemPrompt }, { role: 'user', content: question } ]; body: JSON.stringify({ model: 'doubao-pro', messages }) ``` The production configuration example defines the same placeholder destination: ```yaml doubao: session_id: ${DOUBAO_SESSIONID} base_url: https://api.example.com/v1 ``` ### Technical Analysis Sending prompts to an external model is necessary for the declared LLM integration functionality. However, the provided implementation sends complete user messages—and, in the RAG workflow, private enterprise document excerpts—to `api.example.com`. This is a placeholder domain and is not identified or validated as an official Doubao API endpoint. The instructions do not demonstrate: - An allowlist of approved API hostnames. - Rejection of placeholder or untrusted production endpoints. - Explicit user disclosure and consent before transmitting private content. - Secret and personally identifiable information redaction. - Context minimization before transmission. - A policy limiting which knowledge-base documents may leave the local environment. ...[truncated 1867 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:138
Finding

Model-directed tool calls are dispatched without demonstrated authorization enforcement

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description uses very broad activation language such as 'use when needing AI model calls, intelligent dialogue, Agent orchestration, LLM applications,' which can cause the agent to invoke this skill for many unrelated requests. Because the skill also advertises exec, file handling, API calls, and knowledge-base access, overbroad routing increases the chance of unnecessary privileged actions or data exposure.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
75% confidence
Finding

The sample code sends user message content to an external endpoint via fetch, which constitutes outbound data transmission. In this skill's context, that is expected functionality, but it is still security-relevant because prompts and potentially sensitive content are transmitted off-host without adjacent privacy guidance in the example.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

javascript
// 流式响应处理框架
async function chatStream(message, onChunk) {
  const resp = await fetch('https://api.example.com/v1/chat/completions', {
    method: 'POST',
    headers: { 'Content-Type': 'application/json' },
    body: JSON.stringify({

External Transmission

Medium
Category
Data Exfiltration
Confidence
75% confidence
Finding

The sample code sends user message content to an external endpoint via fetch, which constitutes outbound data transmission. In this skill's context, that is expected functionality, but it is still security-relevant because prompts and potentially sensitive content are transmitted off-host without adjacent privacy guidance in the example.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

javascript
// 流式响应处理框架
async function chatStream(message, onChunk) {
  const resp = await fetch('https://api.example.com/v1/chat/completions', {
    method: 'POST',
    headers: { 'Content-Type': 'application/json' },
    body: JSON.stringify({

External Transmission

Medium
Category
Data Exfiltration
Confidence
79% confidence
Finding

This request sends the full message history and tool definitions to an external service, potentially including prior conversation context, sensitive prompts, and structured tool metadata. Because the skill also supports function calling and enterprise workflows, a larger volume of operational or proprietary data may be exposed than users realize.

Content

Scanner excerpt · SKILL.md (reported line 154)May include surrounding context.

md
});
    }
    // 再次请求获取最终回复
    const finalResp = await fetch('https://api.example.com/v1/chat/completions', {
      method: 'POST',
      headers: { 'Content-Type': 'application/json' },
      body: JSON.stringify({ model: 'doubao-pro', messages, tools })

External Transmission

Medium
Category
Data Exfiltration
Confidence
79% confidence
Finding

This request sends the full message history and tool definitions to an external service, potentially including prior conversation context, sensitive prompts, and structured tool metadata. Because the skill also supports function calling and enterprise workflows, a larger volume of operational or proprietary data may be exposed than users realize.

Content

Scanner excerpt · SKILL.md (reported line 154)May include surrounding context.

md
});
    }
    // 再次请求获取最终回复
    const finalResp = await fetch('https://api.example.com/v1/chat/completions', {
      method: 'POST',
      headers: { 'Content-Type': 'application/json' },
      body: JSON.stringify({ model: 'doubao-pro', messages, tools })

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 379)May include surrounding context.

yaml
doubao:
  session_id: ${DOUBAO_SESSIONID}
  base_url: https://api.example.com/v1
  default_model: doubao-pro
  timeout_ms: 60000
  max_retries: 3

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill advertises file processing capabilities including write-oriented behavior without a clear, prominent warning that using the skill may modify local data. In an agent environment, this can lead users or the orchestrator to trigger file-changing actions without informed consent, risking unintended overwrites or corruption.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill promotes external API integration and information retrieval but does not clearly warn that user inputs, conversation content, or knowledge-base data may be transmitted to third-party services. This omission can cause accidental disclosure of sensitive enterprise or personal information when the skill is used in production workflows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly advertises command execution as a feature but does not present a strong warning about system-impacting behavior. Since the declared tools include exec, broad use of this skill could result in shell commands being run with local side effects, dependency installation, process execution, or environment access beyond user expectations.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.prompt_injection_instructions

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
SKILL.md:189