Back to skill

Security audit

Target Contact Finder

Security checks for vulnerabilities and agentic risk

Overview

This CRM lead-search skill is mostly coherent, but it sends credentials and customer contact data to a raw IP address over unencrypted HTTP.

Review this carefully before installing. Use it only if you trust the service operator and are comfortable sending CRM lead and contact data to the listed external endpoint; the current artifact should be updated to use HTTPS, scope triggers more narrowly, and explain privacy/compliance responsibilities before import.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:13
Finding

Authentication Credential and Customer PII Transmitted over Plaintext HTTP

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 13 and 26–66
Vulnerability Type: Plaintext transmission of sensitive information
Risk Level: High

Vulnerable Code

markdown
**Base URL:** `http://39.108.114.224:9059`
bash
# Customer profile search
curl -s -X POST -H "Content-Type: application/json" \
  "http://39.108.114.224:9059/skill/search_customer_profile" \
  -d '{
    "user_key": "<user_key>",
    "q_keywords": "hotel hospitality resort",
    "organization_locations": ["Japan"],
    "person_titles": ["Business Development", "Partnership Manager"],
    "person_seniorities": ["manager", "director", "head"],
    "contact_email_status": ["verified", "likely to engage"],
    "per_page": 10,
    "page": 1
  }'

# Bulk customer import
curl -s -X POST -H "Content-Type: application/json" \
  "http://39.108.114.224:9059/skill/batch_import_customer" \
  -d '{
    "user_key": "<user_key>",
    "customers": [
      {
        "name": "Hilton Tokyo",
        "contact_name": "John Smith",
        "contact_email": "john@hiltontokyo.com",
        "contact_phone": "80012345",
        "contact_phone_prefix": "+81",
        "country_code": "JP",
        "address": "Tokyo, Japan",
        "remark": "Business Development | Hospitality"
      }
    ]
  }'

Technical Analysis

The Skill configures both API operations to use unencrypted HTTP. HTTP does not provide transport confidentiality, message integrity, or authenticated server identity. Consequently, every request can expose the user_key credential and customer personal information—including names, email addresses, telephone numbers, and physical addresses—to an attacker with visibility into the network path.

An on-path attacker could also modify requests or responses without detection. This could alter search results, inject fraudulent customer records, replace CRM import data, or c ...[truncated 1954 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace every http://39.108.114.224:9059 endpoint with an https:// endpoint protected by a valid TLS certificate.
  2. Use a DNS hostname whose identity can be validated against the certificate rather than relying on a bare IP address.
  3. Configure clients to verify the certificate chain and hostname. Do not disable TLS verification or accept self-signed certificates without a securely managed private trust anchor.
  4. Reject redirects from HTTPS to HTTP and prevent protocol downgrade behavior.
  5. Rotate all user_key values that may previously have been transmitted over HTTP.
  6. Store authentication credentials in an operating-system secret store or another protected credential mechanism. If a file remains necessary, enforce owner-only permissions and avoid exposing its contents in logs or error messages.
  7. Apply short credential lifetimes, revocation support, rate limits, and least-privilege scopes to reduce the value of a captured key.
  8. Minimize customer data transmitted and displayed to only the fields required for the requested operation.
  9. Add request timeouts, explicit status handling, response validation, and audit logging that redacts credentials and personal data.
  10. Document the external data processor and ensure appropriate user notice, consent, retention controls, and privacy safeguards are in place before transmitting customer information.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill declares that it must be invoked for a very broad set of ordinary customer-search phrases, which can override more appropriate tools or user-consent checks. In this skill’s context, that broad trigger is especially risky because the tool performs external lead search and CRM import operations involving personal/business contact data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill handles and imports personal contact data such as names, emails, phone numbers, and company details, yet it provides no explicit privacy notice, lawful-basis guidance, retention expectations, or user-facing warning before processing. In a CRM enrichment/import workflow, this omission increases the chance of unauthorized or non-compliant handling of personal data.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

The skill sends authentication material and customer search/import data to an external service over plain HTTP to a raw IP address, exposing the traffic to interception or tampering in transit. Because the payload includes user_key and personal contact information, this context materially increases the risk of credential compromise, data leakage, and unauthorized CRM actions.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

bash
# 搜索客户画像
curl -s -X POST -H "Content-Type: application/json" \
  "http://39.108.114.224:9059/skill/search_customer_profile" \
  -d '{
    "user_key": "<user_key>",

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

文档明确规定 q_keywords “必须转成英文关键词”“不要传中文”,属于语言/locale 约束。文件中未向用户提供语言选择,也未将该限制解释为特定地区合规或接口硬性要求下的用户可见例外,因而构成自然语言层面的语言政策问题。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.