Back to skill

Security audit

B2B 线索生成聚合工具,将海关贸易情报、全球企业深度背调与 LinkedIn 职业人脉数据整合为统一工作流。分析 HS 编码的市场分布、贸易趋势与企业贸易占比以评估产品市场规模;基于 220+ 国家海关记录剖析单个公司的真实贸易规模、伙伴、产品与港口;获取宏观国家级贸易概览、Top 买家/供应商与美国进口统计;开展公司深度背调(员工、股东、最终受益人UBO、决策人)并绘制 LinkedIn 职业人脉图谱(同事、校友、履历与学历)。帮助出口商、采购代理、销售团队与 B2B获客专家发现海外买家、验证供应商、加速跨境客户开发,适用于外贸找客户、供应商寻源与销售线索挖掘。

Security checks across malware telemetry and agentic risk

Overview

The skill mostly matches its B2B lead-generation purpose, but it handles paid API credentials and bulk personal/contact data with weak privacy, retention, and local-secret safeguards.

Review before installing. Use this only for lawful B2B due diligence or lead generation, avoid bulk collection of personal/contact data without a valid basis, and treat task_data results as sensitive. Prefer supplying the API key through a managed secret mechanism if possible, restrict file permissions on ~/.upkuajing/.env, and periodically delete stored result files you no longer need.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (22)

Lp3

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding
The skill explicitly instructs reading environment variables, reading and writing local files under ~/.upkuajing and task_data/, and making network calls, yet it declares no permissions or equivalent capability disclosures. This creates a transparency and consent gap: an agent may access secrets, persist data, and contact external services without users understanding the full operational scope.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding
The skill is presented as a lead-generation and due-diligence tool, but it also performs account-management and monetization actions such as key issuance, account lookup, recharge order creation, pricing queries, local persistence, and remote version checks. These extra behaviors materially expand the trust boundary and can lead to unexpected secret handling, billing actions, and data retention beyond the user's likely expectations.

Context-Inappropriate Capability

Medium
Confidence
81% confidence
Finding
The skill can autonomously request a new API key from the backend and persist it locally, which expands its authority beyond the lead-generation features described to users. In a skill context, hidden credential provisioning is risky because it creates long-lived access material on disk and may surprise users who did not consent to credential creation or local secret storage.

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
The module adds persistent local state under the user's home directory and performs outbound version-check requests that are unrelated to the lead-generation functionality described for the skill. While this looks more like updater/telemetry behavior than an overt exploit, it creates hidden network and persistence behavior that can surprise users, leak installation metadata, and expand the skill's attack surface if the remote endpoint or base URL is compromised.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill promotes collection of sensitive due-diligence, employee, shareholder/UBO, decision-maker, and professional-network data without clearly warning about privacy, legal, and acceptable-use implications. In this context, the absence of safeguards increases the risk of misuse for invasive profiling, unauthorized surveillance, or non-compliant handling of personal data.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The API reference explicitly supports filtering for the existence of phone, email, WhatsApp, website, and even core member contact information, but provides no privacy, consent, or permitted-use constraints. In a lead-generation and due-diligence skill, this materially increases the risk of bulk harvesting and misuse of personal or quasi-personal contact data for profiling, spam, or intrusive outreach.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The documented response includes fields such as `person_contact_show` and counts of phone, email, website, social, and WhatsApp contacts without any warning that these outputs may contain sensitive personal or employee contact information. Because this skill is specifically marketed for lead generation and LinkedIn-style relationship mapping, exposing such outputs without safeguards makes downstream misuse more likely and more operationally dangerous.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The API reference explicitly supports filtering for and returning indicators of personal contact data availability, including phone, WhatsApp, email, website, and social accounts, without any guidance on lawful basis, consent, minimization, or permitted use. In a lead-generation skill focused on sourcing people and company contacts, this materially increases the risk of privacy abuse, unauthorized profiling, and non-compliant outreach at scale.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The response schema includes gender as a returned personal attribute without any warning that it may constitute sensitive or regulated personal data depending on jurisdiction and use. In the context of B2B lead generation and people search, exposing gender enables profiling and potentially discriminatory targeting, which raises privacy, compliance, and misuse concerns.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The documentation explicitly enables filtering for the existence of phone, email, WhatsApp, website, social accounts, valid contact details, and core member contact information, which materially facilitates discovery and targeting of personal and business contact data. In a lead-generation and LinkedIn-enrichment skill, this increases the risk of privacy abuse, scraping-driven profiling, spam, and unauthorized outreach because no consent, lawful-use, minimization, or handling constraints are described.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The response schema includes `person_contact_show` and counts of phone, email, website, social, and WhatsApp data, indicating direct exposure of employee or company contact intelligence. Providing this in a B2B lead-generation context without privacy warnings or downstream-use restrictions makes the skill more dangerous because it can be used for deanonymization, profiling, phishing target selection, and large-scale unsolicited contact campaigns.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The document explicitly supports searching and filtering for personal contact-related attributes such as phone, WhatsApp, email, website, and social presence, but provides no privacy notice, lawful-basis guidance, consent expectations, or usage restrictions. In the context of a B2B lead-generation and LinkedIn people-search skill, this materially increases the risk of privacy violations, unauthorized profiling, scraping abuse, and non-compliant handling of personal data.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The script persists retrieved person records and task metadata to local files without any visible notice, consent flow, retention control, or access protection. In this skill’s context, the data includes potentially sensitive personal and corporate intelligence, so silent persistence increases the risk of privacy violations, unauthorized secondary use, and leakage from shared hosts or insecure storage.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The script fetches and outputs a company's LinkedIn employee list, which can include personally identifying or professionally sensitive data, but provides no user-facing notice, consent check, purpose limitation, or handling guidance. In the context of a lead-generation and due-diligence skill that explicitly aggregates people and relationship data, this increases privacy and compliance risk and can enable misuse such as profiling or scraping at scale.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The script persists retrieved LinkedIn person records to task result files without any visible consent prompt, retention control, minimization, or access-control handling in this file. Because the skill is explicitly designed for lead generation, due diligence, and relationship mapping, the stored data can include personal and potentially sensitive professional information, increasing privacy, compliance, and unauthorized-access risk if result files are exposed or retained longer than necessary.

Missing User Warnings

Low
Confidence
83% confidence
Finding
The script sends person and school identifiers to an external API endpoint without any user-facing notice, consent flow, or documentation at the point of use. In a lead-generation and due-diligence context that processes personal relationship data, silent transmission of identifiers increases privacy and compliance risk even if the request is expected functionality.

Missing User Warnings

Low
Confidence
91% confidence
Finding
The function automatically sends the skill name to a remote API without any user-facing consent, disclosure, or runtime prompt. Even though the payload is small, this is still undisclosed outbound communication and can enable environment or usage tracking, which is especially questionable because it is not necessary for the advertised business purpose of B2B lead generation.

Credential Access

High
Category
Privilege Escalation
Content
"""
    申请新的 API 密钥。
    """
    # 检查是否已存在 .env 文件和 API key
    env_file = UPKUAJING_ENV_FILE

    if env_file.exists():
Confidence
96% confidence
Finding
.env

Credential Access

High
Category
Privilege Escalation
Content
env_file = UPKUAJING_ENV_FILE

    if env_file.exists():
        # 读取现有的 .env 文件
        try:
            with open(env_file, 'r', encoding='utf-8') as f:
                content = f.read()
Confidence
95% confidence
Finding
.env

Credential Access

High
Category
Privilege Escalation
Content
"envFilePath": str(env_file)
        }

    # 保存到 .env 文件
    try:
        with open(env_file, 'w', encoding='utf-8') as f:
            f.write(f"{API_KEY_ENV}={api_key}\n")
Confidence
98% confidence
Finding
.env

Credential Access

High
Category
Privilege Escalation
Content
except IOError as e:
        return {
            "success": False,
            "message": f"API密钥申请成功,但保存到 .env 文件失败:{str(e)}。\n请手动设置环境变量 {API_KEY_ENV}。",
            "envFilePath": str(env_file)
        }
Confidence
84% confidence
Finding
.env

Unpinned Dependencies

Low
Category
Supply Chain
Content
httpx>=0.23.0
Confidence
92% confidence
Finding
httpx>=0.23.0

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/common.py:196