Back to skill

Security audit

baidu-scholar-search

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent academic search skill that sends user search terms to a documented SkillBoss API, with one real input-encoding flaw users should understand.

Install only if you are comfortable sending search queries to SkillBoss using your SKILLBOSS_API_KEY. Avoid highly sensitive or confidential research terms, and prefer a fixed version that JSON-encodes the query safely before sending it.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
baidu_scholar_search.sh:13
Finding

Unescaped User Input Allows JSON Request-Body Injection

Content
View full analysis

Vulnerability Details

File Location: baidu_scholar_search.sh, lines 13–25
Vulnerability Type: JSON injection through unsafe string interpolation
Risk Level: Medium

bash
WD="$1"
if [ -z "$WD" ]; then
    echo '{"error": "Missing wd parameter"}'
    exit 1
fi

pageNum="${2:-0}"
enable_abstract="${3:-false}"

curl -s -X POST \
  -H "Authorization: Bearer $SKILLBOSS_API_KEY" \
  -H "Content-Type: application/json" \
  -d "{\"type\": \"search\", \"inputs\": {\"query\": \"$WD\"}, \"prefer\": \"balanced\"}" \
  "https://api.skillboss.co/v1/pilot"

Technical Analysis

The script places the attacker-controlled WD argument directly inside a manually constructed JSON string. It does not encode JSON metacharacters such as quotation marks, backslashes, or control characters.

An input containing JSON syntax can therefore terminate the intended query string and add properties to the request. For example, an argument shaped like:

text
x","additional_property":"attacker-controlled

causes the inputs object sent to the remote API to contain an injected property:

json
{
  "type": "search",
  "inputs": {
    "query": "x",
    "additional_property": "attacker-controlled"
  },
  "prefer": "balanced"
}

More complex payloads could close nested objects and introduce duplicate or unexpected top-level fields. The resulting behavior depends on the remote API's schema validation and duplicate-key handling. Inputs containing ordinary quotation marks or backslashes can also produce malformed JSON and cause a denial of service for the individual request.

This is JSON injection, not shell command injection: WD remains within a shell-quoted argument, so shell metacharacters embedded in it are not evaluated as commands.

Attack Path

  1. An attacker or untrusted caller supplies a crafted search keyword containing quotation marks and JSON syntax.
  2. The script as ...[truncated 1081 chars]
Remediation
View remediation

Remediation Suggestions

Construct the request body with a JSON-aware serializer rather than manual interpolation. For example, using jq:

bash
payload="$(
  jq -n --arg query "$WD" \
    '{type: "search", inputs: {query: $query}, prefer: "balanced"}'
)"

curl --fail-with-body --silent --show-error -X POST \
  -H "Authorization: Bearer $SKILLBOSS_API_KEY" \
  -H "Content-Type: application/json" \
  --data-binary "$payload" \
  "https://api.skillboss.co/v1/pilot"

If jq is used, declare it as a required executable in the Skill metadata. Alternatively, use another available JSON library that guarantees correct string escaping.

Additional hardening should include:

  • Rejecting search terms containing disallowed control characters or exceeding a reasonable length.
  • Enabling curl --fail-with-body --show-error so transport and HTTP failures are visible.
  • Validating that the generated payload is valid JSON before transmission.
  • Adding regression tests for quotation marks, backslashes, newlines, Unicode text, and attempted structural JSON injection.
  • Either implementing and validating pageNum and enable_abstract or removing those currently unused arguments to prevent misleading behavior.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill executes shell code but does not declare any explicit tool scope or permissions, which weakens sandboxing and review controls. In practice this increases the chance that a host agent permits broader execution than intended and makes the skill's operational capabilities less transparent to users and auditors.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

Example Usage

bash
curl -s -X POST 'https://api.skillboss.co/v1/pilot' \
-H 'Authorization: Bearer $SKILLBOSS_API_KEY' \
-H 'Content-Type: application/json' \
-d '{"type": "search", "inputs": {"query": "人工智能"}, "prefer": "balanced"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The executable script sends user-controlled input and an authorization bearer token to an external third-party endpoint, creating real data egress and trust-boundary crossing. More importantly, the JSON body is built by interpolating the raw shell variable into a quoted string, so crafted input containing quotes can break the JSON structure and potentially alter request fields or cause unintended data transmission.

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

-H "Authorization: Bearer $SKILLBOSS_API_KEY"
-H "Content-Type: application/json"
-d "{"type": "search", "inputs": {"query": "$WD"}, "prefer": "balanced"}"
"https://api.skillboss.co/v1/pilot"

Response path: .result.results

text

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

This code performs an outbound HTTPS POST containing user-supplied input and an authorization token to an external service. External transmission is inherent to remote search functionality, but it still creates a real data exposure boundary: sensitive queries, institutional research terms, or regulated content may be disclosed to the service provider if users are not aware.

Content

Scanner excerpt · baidu_scholar_search.sh (reported line 23)May include surrounding context.

sh
pageNum="${2:-0}"
enable_abstract="${3:-false}"

curl -s -X POST \
  -H "Authorization: Bearer $SKILLBOSS_API_KEY" \
  -H "Content-Type: application/json" \
  -d "{\"type\": \"search\", \"inputs\": {\"query\": \"$WD\"}, \"prefer\": \"balanced\"}" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script transmits the user's query and bearer credential to a third-party service without any user-facing disclosure, consent, or local indication that data leaves the environment. For a search skill this may be expected technically, but lack of transparency can expose sensitive research topics or proprietary queries and can cause users to unknowingly send data to an external operator.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
-H "Authorization: Bearer $SKILLBOSS_API_KEY" \
  -H "Content-Type: application/json" \
  -d "{\"type\": \"search\", \"inputs\": {\"query\": \"$WD\"}, \"prefer\": \"balanced\"}" \
  "https://api.skillboss.co/v1/pilot"
# Response path: .result.results

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

md
-H "Authorization: Bearer $SKILLBOSS_API_KEY" \
  -H "Content-Type: application/json" \
  -d "{\"type\": \"search\", \"inputs\": {\"query\": \"$WD\"}, \"prefer\": \"balanced\"}" \
  "https://api.skillboss.co/v1/pilot"
# Response path: .result.results

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · baidu_scholar_search.sh (reported line 27)May include surrounding context.

sh
-H "Authorization: Bearer $SKILLBOSS_API_KEY" \
  -H "Content-Type: application/json" \
  -d "{\"type\": \"search\", \"inputs\": {\"query\": \"$WD\"}, \"prefer\": \"balanced\"}" \
  "https://api.skillboss.co/v1/pilot"
# Response path: .result.results

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest describes a literature search capability, but the code requires and reads the SKILLBOSS_API_KEY environment variable to operate. While network access is expected for search, accessing runtime credentials is a broader capability not stated in the manifest text and is not inherently implied by the user-facing purpose alone.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.