Back to skill

Security audit

Locate internal staff within international enterprises via company ID and personnel ID queries against global corporate databases. Pull full colleague rostersof any target employee with one-click search operations. Recruiters, sales teams and B2B lead generation specialists source bulk batches of valuable businesscontacts seamlessly. Expand professional networking resources and conduct in-depth talent background research. Map out clients’ internal decision-makinghierarchies and unlock additional hidden stakeholders once a core decision-maker is identified.

Security checks for vulnerabilities and agentic risk

Overview

This paid colleague-lookup skill is mostly coherent, but it handles API keys and auxiliary platform calls in ways users should review before installing.

Before installing, confirm you are comfortable giving this skill a paid UpKuaJing API key and letting it contact UpKuaJing services. Do not allow the agent to print ~/.upkuajing/.env; use a redacted presence check instead, restrict the credential file permissions, and review every paid query, top-up order, and error report before it is sent.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/auth.py:64
Finding

API Key Stored Without Enforced Restrictive File Permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:39
Finding

Documentation Directs the Agent to Print the Complete Credential File

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Dependency Uses an Open-Ended Version Constraint Without Integrity Verification

Content
View full analysis
=0.23.0 ``` The installation instruction in `SKILL.md` executes this requirement directly: ```bash pip install -r requirements.txt ``` ### Technical Analysis The `>=0.23.0` constraint permits pip to install any later `httpx` version selected from the configured package index. The project provides no lock file, exact version, or cryptographic hashes for the package and its transitive dependencies. This makes installations non-reproducible and expands the trusted supply-chain surface to future, unaudited releases and the package index configured in the execution environment. A compromised package source or dependency release could introduce malicious installation or runtime behavior. A future incompatible release could also alter HTTP, TLS, proxy, or timeout behavior. No misspelled package name, custom package index, or demonstrably malicious dependency was found. This is therefore a dependency-hardening weakness rather than evidence that the current `httpx` package is malicious. ### Attack Path 1. A user or Agent follows the documented setup command. 2. pip resolves the newest compatible package versions from its configured index. 3. The selected release or one of its transitive dependencies differs from the version originally reviewed. 4. If that artifact or package source is compromised, malicious package code executes in the installation or runtime environment. 5. The malicious dependency receives the privileges of the user running pip or the Skill and may access process data, local files, or API traffic available to that environment. ### Impact Assessment The maximum impact depends on the privileges used to install and execute the Skill. A compromised dependency could potentially: - Execute arbitrary code with the installing user’s privileges - Read the UpKuaJing ...[truncated 381 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (39)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to perform remote version checks, read local metadata, and write cache data under the user's home directory, none of which is disclosed by its stated purpose. Undeclared update-checking and cache persistence create additional network and filesystem exposure that can leak usage patterns or introduce integrity concerns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill appears to perform remote version checks, read local metadata, and write cache data under the user's home directory, none of which is disclosed by its stated purpose. Undeclared update-checking and cache persistence create additional network and filesystem exposure that can leak usage patterns or introduce integrity concerns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to perform remote version checks, read local metadata, and write cache data under the user's home directory, none of which is disclosed by its stated purpose. Undeclared update-checking and cache persistence create additional network and filesystem exposure that can leak usage patterns or introduce integrity concerns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to perform remote version checks, read local metadata, and write cache data under the user's home directory, none of which is disclosed by its stated purpose. Undeclared update-checking and cache persistence create additional network and filesystem exposure that can leak usage patterns or introduce integrity concerns.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The skill instructs reading a plaintext credential file from the user's home directory using a shell command. Exposing or encouraging direct inspection of secret-bearing .env files increases the chance of credential disclosure to logs, transcripts, or downstream tools.

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

This skill requires an API key. The API key is stored in the ~/.upkuajing/.env file:

bash
cat ~/.upkuajing/.env

Example file content:

text

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

The skill workflow directs the agent to check for and potentially manage API keys in a local .env file, including prompting for user-supplied secrets and storing them on disk. This expands the skill from data lookup into credential collection and persistence, increasing risk of accidental disclosure or misuse.

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

md
### **API Key Not Set**
First check if the `~/.upkuajing/.env` file has UPKUAJING_API_KEY;
If UPKUAJING_API_KEY is not set, prompt the user to choose:
1. User has one: User provides it (manually add to ~/.upkuajing/.env file)
2. User doesn't have one: You can apply using the interface (`auth.py --new_key`), the new key will be automatically saved to ~/.upkuajing/.env
Wait for user selection;

Credential Access

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

Automatically applying for a new API key and saving it to ~/.upkuajing/.env creates and persists credentials locally without clear security controls. In combination with the skill's external network behavior and broad contact-discovery purpose, this makes the context more dangerous because it normalizes silent credential provisioning for an unrelated business-intelligence task.

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
First check if the `~/.upkuajing/.env` file has UPKUAJING_API_KEY;
If UPKUAJING_API_KEY is not set, prompt the user to choose:
1. User has one: User provides it (manually add to ~/.upkuajing/.env file)
2. User doesn't have one: You can apply using the interface (`auth.py --new_key`), the new key will be automatically saved to ~/.upkuajing/.env
Wait for user selection;

### **Account Top-up**

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script's behavior is materially inconsistent with the declared skill purpose. Instead of finding internal colleagues or mapping stakeholders, it implements API key issuance, account lookup, pricing, and recharge flows for an external platform, which is a strong indicator of scope drift and can facilitate unauthorized monetization or hidden service enablement inside a seemingly unrelated skill.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/auth.py (reported line 18)May include surrounding context.

python
"""
    申请新的 API 密钥。
    """
    # 检查是否已存在 .env 文件和 API key
    env_file = UPKUAJING_ENV_FILE

    if env_file.exists():

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/auth.py (reported line 22)May include surrounding context.

python
"""
    申请新的 API 密钥。
    """
    # 检查是否已存在 .env 文件和 API key
    env_file = UPKUAJING_ENV_FILE

    if env_file.exists():

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/common.py (reported line 63)May include surrounding context.

python
"""
    申请新的 API 密钥。
    """
    # 检查是否已存在 .env 文件和 API key
    env_file = UPKUAJING_ENV_FILE

    if env_file.exists():

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/common.py (reported line 85)May include surrounding context.

python
"""
    申请新的 API 密钥。
    """
    # 检查是否已存在 .env 文件和 API key
    env_file = UPKUAJING_ENV_FILE

    if env_file.exists():

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/common.py (reported line 90)May include surrounding context.

python
"""
    申请新的 API 密钥。
    """
    # 检查是否已存在 .env 文件和 API key
    env_file = UPKUAJING_ENV_FILE

    if env_file.exists():

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

The script writes a newly issued API key to a .env file without any visible permission hardening or secure secret-store usage. Storing credentials in plaintext on disk can expose them to other local users, backup systems, or accidental inclusion in logs, archives, or repositories.

Content

Scanner excerpt · scripts/auth.py (reported line 71)May include surrounding context.

python
"envFilePath": str(env_file)
        }

    # 保存到 .env 文件
    try:
        with open(env_file, 'w', encoding='utf-8') as f:
            f.write(f"{API_KEY_ENV}={api_key}\n")

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

Returning the exact environment variable name and secret-storage path in error messages increases sensitive operational disclosure and encourages manual secret handling. In combination with plaintext local storage, this makes accidental leakage or mishandling of credentials more likely.

Content

Scanner excerpt · scripts/auth.py (reported line 78)May include surrounding context.

python
except IOError as e:
        return {
            "success": False,
            "message": f"API密钥申请成功,但保存到 .env 文件失败:{str(e)}。\n请手动设置环境变量 {API_KEY_ENV}。",
            "envFilePath": str(env_file)
        }

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

Recharge-order creation and pricing retrieval are unrelated to the stated colleague-discovery function and introduce financial operations into a deceptive context. Hidden billing capabilities increase the risk of user confusion, unintended charges, and abuse of enterprise environments where agents are expected to perform only contact-discovery tasks.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/common.py (reported line 19)May include surrounding context.

python
API_BASE_URL = "https://openapi.upkuajing.com"
API_KEY_ENV = "UPKUAJING_API_KEY"
UPKUAJING_DIR = Path.home() / '.upkuajing'
UPKUAJING_ENV_FILE = UPKUAJING_DIR / '.env'
UPKUAJING_LOGS_DIR = UPKUAJING_DIR / 'logs'

# 日志开关

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest describes a skill for finding internal company teammates and mapping decision-making circles, but this file implements exception reporting to a platform endpoint and auto-populates skill metadata. Reporting runtime errors is not part of the user-facing teammate/contact discovery behavior claimed by the skill description.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill declares executable behaviors that imply environment access, file reads/writes, and network communication, but it does not define an explicit tool scope or permissions boundary. That omission increases the chance of over-privileged execution and makes it harder for reviewers or runtime policy engines to constrain what the skill can do.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough to match common sales, networking, and business-research requests, which can cause the skill to activate outside a narrowly intended context. Over-broad invocation raises the risk of unintended data collection, contact discovery, or execution of fee-incurring queries when users did not specifically request this capability.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly promotes uncovering hidden stakeholders and mapping client-side decision-making circles, which can facilitate profiling and non-transparent contact network expansion. In this business-intelligence context, the language makes the capability more sensitive because it encourages discovery of people who may not expect to be surfaced for outreach or influence mapping.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation explicitly encourages sending exception context plus raw request parameters and response data to a centralized error-report API, while only stating that sensitive fields are 'automatically desensitized' without defining scope, guarantees, or user/operator safeguards. In a skill that maps internal colleagues and stakeholder networks, those payloads can plausibly contain internal identifiers, relationship data, and other sensitive enterprise information, so error reporting can become an unintended data-exfiltration channel if logging is overbroad or masking is incomplete.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and all user-facing CLI descriptions/messages are written only in Chinese, which imposes a specific language on users. The file does not indicate that Chinese is optional, user-selected, or required for a documented region-specific purpose.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · scripts/auth.py (reported line 41)May include surrounding context.

python
pass  # 如果读取失败,继续执行

    # 不需要认证申请新密钥
    response = make_request('/agent/auth/create', {}, require_auth=False)

    # 检查是否申请成功
    if response.get('code') != 0:

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · scripts/auth.py (reported line 41)May include surrounding context.

python
pass  # 如果读取失败,继续执行

    # 不需要认证申请新密钥
    response = make_request('/agent/auth/create', {}, require_auth=False)

    # 检查是否申请成功
    if response.get('code') != 0:

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/common.py:196

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:60