Back to skill

Security audit

Baixing Agent Cli

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for a Baixing listing CLI, but it asks agents to install unpinned executable npm code and can publish real listings with fabricated contact data.

Review this skill before installing. Use a pinned, trusted version of baixing-agent-cli if possible, avoid global installation when a local install will work, verify BX_API_BASE_URL/baseUrl points to the intended Baixing endpoint, and do not let the agent publish a listing unless the user explicitly provided and confirmed the contact details.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:18
Finding

Unpinned npm Package Is Downloaded and Executed

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:42
Finding

Configurable API Endpoint Can Redirect Sensitive Listing Data

Content
View full analysis
configuration file baseUrl > https://www.baixing.com ``` The posting workflow transmits user-provided metadata, including a contact number: ```bash baixing post \ --category m37501 \ -f contact=13800001111 \ -f price=4500 \ -f region=m30 ``` The relevant documented configuration identifiers are: ```text BX_API_BASE_URL baseUrl https://www.baixing.com ``` ### Technical Analysis Network communication is necessary for the Skill's declared purpose because it provides a CLI for publishing and querying listings through Baixing HTTP APIs. Transmission to the declared production service is therefore expected. The excess risk arises from allowing `BX_API_BASE_URL` or the persisted `baseUrl` configuration value to override the production endpoint without documenting an HTTPS requirement, certificate policy, or trusted-host allowlist. The endpoint decision can occur before the agent collects and submits listing content and contact information. The workflow explicitly recommends obtaining a real contact number from the user. Posting can also disclose listing text, category, location, price, UUID, and other metadata. If the environment variable or configuration file is attacker-controlled, these values can be redirected to an unintended server. The supplied project does not contain the CLI implementation, so it was not possible to verify whether the external package independently validates the URL scheme, hostname, redirects, or TLS behavior. ### Attack Path 1. An attacker or compromised execution environment sets `BX_API_BASE_URL` to an attacker-contr ...[truncated 1101 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The guidance normalizes handling and submission of contact information without clear user consent by telling the agent to populate a phone number placeholder when none was supplied. In the context of an automated posting workflow against real Baixing APIs, this is especially dangerous because it can lead to unauthorized or inaccurate listings being published at scale.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs the agent to post a fabricated fallback phone number when the user has not provided real contact information. This can cause publication of false personal/contact data to a live external service, creating integrity, consent, abuse, and possible privacy/compliance issues for both the user and the uninvolved owner of the placeholder number.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents all user-facing guidance only in Chinese, which can constitute a language/locale policy issue when no user opt-in, alternative language, or justification is provided. The content does not indicate that the skill is intentionally region-specific or that other language options exist.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.