Back to skill

Security audit

Conduct global company-level lookup to retrieve shareholders, C-suite executives and multi-tier equity structure data from worldwide corporate databases.Generate full shareholder rosters including ownership ratios, share classes and hierarchical ownership chains via simple company ID searches.Investors, industryanalysts, sales teams and risk management specialists audit equity frameworks and pinpoint ultimate beneficial owners and actual corporate controllersefficiently.Streamline full corporate due diligence, investment performance analysis, competitor group affiliation research and related-party transactionscreening workflows. Verify target enterprises’ controlling parties and assess overall corporate financial standing for risk assessment and B2B prospecting.

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly performs paid company-shareholder lookups, but it handles API keys and account/payment functions in ways users should review before installing.

Review this skill before installing. Use it only if you trust UpKuaJing and are comfortable with paid API calls, local plaintext storage of UPKUAJING_API_KEY, account and top-up helper commands, and confirmed error reports to the platform. Do not let the agent print ~/.upkuajing/.env; provide the key through a safer secret mechanism or ensure the file is owner-only readable.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:39
Finding

API Key May Be Exposed Through Full Credential File Output

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 39-48
Vulnerability Type: Credential disclosure through unsafe operational instructions
Risk Level: Medium

markdown
This skill requires an API key. The API key is stored in the `~/.upkuajing/.env` file:
```bash
cat ~/.upkuajing/.env

Example file content:

text
UPKUAJING_API_KEY=your_api_key_here

API Key Not Set

First check if the ~/.upkuajing/.env file has UPKUAJING_API_KEY;

text

### Technical Analysis

The Skill instructs the Agent to display the complete contents of a plaintext credential file with `cat`. Although reading the dedicated API key is necessary to authenticate requests, printing the file is unnecessary and violates least-disclosure principles.

Command output may become visible in terminal history, execution logs, Agent context, captured transcripts, monitoring systems, or user-facing responses. The file could also contain additional environment variables beyond the documented API key, causing disclosure of unrelated secrets.

The Python implementation can already obtain the required value directly from the process environment or parse the named variable from the file. Consequently, displaying the complete file exceeds the minimum access required for the declared shareholder-query functionality.

### Attack Path

1. A valid API key is stored in `~/.upkuajing/.env`.
2. The Agent follows the Skill instruction and executes `cat ~/.upkuajing/.env`.
3. The complete plaintext file enters command output and potentially the Agent's context, logs, or transcript.
4. A party with access to those records obtains the API key.
5. The exposed Bearer token is reused to access authenticated UpKuaJing operations or consume paid API services.

### Impact Assessment

Exposure grants the privileges associated with the affected UpKuaJing API key. Depending on the account configuration, an attacker could perform authenticated
...[truncated 195 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove the instruction to run cat ~/.upkuajing/.env.
  • Check only whether UPKUAJING_API_KEY exists, without printing its value.
  • Prefer passing the key through the process environment rather than reading a plaintext file.
  • If file fallback remains necessary, parse only the named variable internally and never include its value in output, logs, errors, or Agent-visible context.
  • Document that credential values must be redacted from troubleshooting output.
  • Consider using an operating-system credential store or secret manager instead of a plaintext .env file.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/auth.py:61
Finding

API Key File Is Written Without Explicit Restrictive Permissions

Content
View full analysis

Vulnerability Details

File Location: scripts/auth.py, lines 61-74
Vulnerability Type: Insecure plaintext credential storage permissions
Risk Level: Medium

python
UPKUAJING_DIR.mkdir(parents=True, exist_ok=True)
python
with open(env_file, 'w', encoding='utf-8') as f:
    f.write(f"{API_KEY_ENV}={api_key}\n")

Technical Analysis

The script stores the API key in plaintext but does not explicitly set restrictive permissions on either the ~/.upkuajing directory or the .env file. The resulting permissions depend on the process umask and any permissions already present on the path.

On a multi-user system with a permissive umask, the file may be readable by other local users. If an existing file has unsafe permissions, opening it with mode w truncates and rewrites it without correcting those permissions. The implementation also does not explicitly defend against the destination being a symbolic link.

Plaintext storage is not inherently avoidable for every command-line integration, but secret files must be created and maintained with permissions limited to their owner.

Attack Path

  1. The Skill runs auth.py --new_key under an account with a permissive umask, or an existing .env file already has broad permissions.
  2. The script creates or rewrites ~/.upkuajing/.env without enforcing owner-only access.
  3. Another local user or process reads the file.
  4. The attacker extracts UPKUAJING_API_KEY.
  5. The attacker reuses the token against authenticated UpKuaJing API endpoints.

A separate local filesystem attack may be possible if an attacker can pre-create or replace the destination with a symbolic link under circumstances where they can influence the user's home-directory contents. Exploitability depends on existing filesystem permissions.

Impact Assessment

Successful exploitation discloses the UpKuaJing Bearer token and grants the API-level privileges assigned to it ...[truncated 238 chars]

Remediation
View remediation

Remediation Suggestions

  • Create ~/.upkuajing with owner-only permissions, equivalent to mode 0700.
  • Create the credential file atomically with owner read/write permissions, equivalent to mode 0600.
  • Explicitly correct permissions on an existing credential file before or after writing it.
  • Where supported, use flags such as O_NOFOLLOW, O_CREAT, and O_EXCL to reduce symbolic-link and race-condition risks.
  • Write through a securely created temporary file in the same directory, apply mode 0600, and atomically replace the destination.
  • Verify that both the directory and destination are owned by the current user and are not symbolic links.
  • Prefer an operating-system keyring or managed secret store where available.

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Unpinned Third-Party Dependency Allows Unreviewed Future Releases

Content
View full analysis

Vulnerability Details

File Location: requirements.txt, line 1
Vulnerability Type: Non-reproducible and insufficiently constrained dependency installation
Risk Level: Low

text
httpx>=0.23.0

The associated installation instruction appears in SKILL.md, line 22:

text
pip install -r requirements.txt

Technical Analysis

The dependency is specified only with a lower bound. Package resolution can therefore select any later httpx release accepted by the environment, including versions that were not reviewed with this Skill. No hashes or lock file are supplied to verify the exact package artifacts.

This does not establish that httpx is malicious. The risk is that builds are not reproducible and may automatically consume a future compromised, incompatible, or behavior-changing release. Package-index configuration outside the project may further affect which artifacts are selected.

Attack Path

  1. A user follows the Skill documentation and runs pip install -r requirements.txt.
  2. The resolver selects an unpinned release newer than version 0.23.0.
  3. A compromised package artifact, compromised future release, or unsafe configured package source supplies the selected dependency.
  4. Package installation or later import executes attacker-controlled code in the user's Python environment.
  5. That code receives the privileges of the user running the Skill and could access files, environment variables, and network resources available to that user.

This attack path requires compromise or malicious control of a resolved package artifact or configured package source; the repository itself does not contain evidence that the current dependency is malicious.

Impact Assessment

In the worst case, malicious dependency code would execute with the privileges of the user installing or running the Skill. It could read the UPKUAJING_API_KEY, access user-readable files, alter the Python en ...[truncated 173 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin httpx to a reviewed exact version rather than using only a lower bound.
  • Generate and maintain a dependency lock file.
  • Require cryptographic hashes for downloaded artifacts, such as through pip's --require-hashes workflow.
  • Install packages only from an explicitly trusted package index.
  • Regularly scan locked dependencies for known vulnerabilities and update them through a controlled review process.
  • Test dependency updates before changing the pinned version.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (38)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Remote version checks and writing version cache files in the user's home directory are unrelated to the stated shareholder/UBO research purpose. Such hidden update/telemetry mechanisms expand the attack surface, create persistence-like local writes, and can surprise users who expected only a read-only lookup workflow.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

Remote version checks and writing version cache files in the user's home directory are unrelated to the stated shareholder/UBO research purpose. Such hidden update/telemetry mechanisms expand the attack surface, create persistence-like local writes, and can surprise users who expected only a read-only lookup workflow.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Remote version checks and writing version cache files in the user's home directory are unrelated to the stated shareholder/UBO research purpose. Such hidden update/telemetry mechanisms expand the attack surface, create persistence-like local writes, and can surprise users who expected only a read-only lookup workflow.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Remote version checks and writing version cache files in the user's home directory are unrelated to the stated shareholder/UBO research purpose. Such hidden update/telemetry mechanisms expand the attack surface, create persistence-like local writes, and can surprise users who expected only a read-only lookup workflow.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

The skill explicitly instructs reading the full contents of ~/.upkuajing/.env using cat, which exposes secrets stored in that file beyond the single required API key. Reading raw credential files is dangerous because it can disclose unrelated tokens, facilitate exfiltration through logs or model output, and normalize secret access in a user-facing workflow.

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

This skill requires an API key. The API key is stored in the ~/.upkuajing/.env file:

bash
cat ~/.upkuajing/.env

Example file content:

text

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

The workflow instructs the agent to inspect whether UPKUAJING_API_KEY is set in a local .env file and to support writing user-provided secrets there. This is sensitive credential handling in a skill not framed as an authentication manager, increasing the risk of leaking, overwriting, or mishandling secrets on the local system.

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

md
### **API Key Not Set**
First check if the `~/.upkuajing/.env` file has UPKUAJING_API_KEY;
If UPKUAJING_API_KEY is not set, prompt the user to choose:
1. User has one: User provides it (manually add to ~/.upkuajing/.env file)
2. User doesn't have one: You can apply using the interface (`auth.py --new_key`), the new key will be automatically saved to ~/.upkuajing/.env
Wait for user selection;

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

The skill further instructs creating a new API key and automatically saving it into ~/.upkuajing/.env, which combines credential issuance with local secret persistence. Automatic writing of credentials to a local file can leave sensitive tokens in insecure storage, create persistence beyond user expectations, and expose them to other tools or users on the host.

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
First check if the `~/.upkuajing/.env` file has UPKUAJING_API_KEY;
If UPKUAJING_API_KEY is not set, prompt the user to choose:
1. User has one: User provides it (manually add to ~/.upkuajing/.env file)
2. User doesn't have one: You can apply using the interface (`auth.py --new_key`), the new key will be automatically saved to ~/.upkuajing/.env
Wait for user selection;

### **Account Top-up**

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/auth.py (reported line 18)May include surrounding context.

python
"""
    申请新的 API 密钥。
    """
    # 检查是否已存在 .env 文件和 API key
    env_file = UPKUAJING_ENV_FILE

    if env_file.exists():

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/auth.py (reported line 78)May include surrounding context.

python
"""
    申请新的 API 密钥。
    """
    # 检查是否已存在 .env 文件和 API key
    env_file = UPKUAJING_ENV_FILE

    if env_file.exists():

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/common.py (reported line 63)May include surrounding context.

python
"""
    申请新的 API 密钥。
    """
    # 检查是否已存在 .env 文件和 API key
    env_file = UPKUAJING_ENV_FILE

    if env_file.exists():

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/common.py (reported line 85)May include surrounding context.

python
"""
    申请新的 API 密钥。
    """
    # 检查是否已存在 .env 文件和 API key
    env_file = UPKUAJING_ENV_FILE

    if env_file.exists():

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/common.py (reported line 90)May include surrounding context.

python
"""
    申请新的 API 密钥。
    """
    # 检查是否已存在 .env 文件和 API key
    env_file = UPKUAJING_ENV_FILE

    if env_file.exists():

Credential Access

High
Category
Privilege Escalation
Confidence
79% confidence
Finding

The function reads an existing .env file and parses the stored API key, then includes a prefix of that secret in a returned message. Even partial secret disclosure increases leakage risk via terminal history, logs, agent transcripts, or screenshots, and the skill context makes this more sensitive because credential handling is not part of the declared research purpose.

Content

Scanner excerpt · scripts/auth.py (reported line 22)May include surrounding context.

python
env_file = UPKUAJING_ENV_FILE

    if env_file.exists():
        # 读取现有的 .env 文件
        try:
            with open(env_file, 'r', encoding='utf-8') as f:
                content = f.read()

Credential Access

High
Category
Privilege Escalation
Confidence
86% confidence
Finding

Writing a newly provisioned API key to a local .env file creates a persistent secret on disk, which is vulnerable to theft from local compromise, backups, misconfigured permissions, or accidental inclusion in support bundles. Because this skill is ostensibly for due-diligence lookups, embedding secret persistence into it adds unnecessary credential exposure.

Content

Scanner excerpt · scripts/auth.py (reported line 71)May include surrounding context.

python
"envFilePath": str(env_file)
        }

    # 保存到 .env 文件
    try:
        with open(env_file, 'w', encoding='utf-8') as f:
            f.write(f"{API_KEY_ENV}={api_key}\n")

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/common.py (reported line 19)May include surrounding context.

python
API_BASE_URL = "https://openapi.upkuajing.com"
API_KEY_ENV = "UPKUAJING_API_KEY"
UPKUAJING_DIR = Path.home() / '.upkuajing'
UPKUAJING_ENV_FILE = UPKUAJING_DIR / '.env'
UPKUAJING_LOGS_DIR = UPKUAJING_DIR / 'logs'

# 日志开关

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill declares no explicit tool scope or permissions even though the instructions clearly require environment access, local file reads/writes, and network/API calls. That over-privileged, undeclared capability increases the chance of accidental credential exposure, unexpected filesystem modification, or unauthorized outbound requests because consumers cannot accurately assess what the skill may do.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description says the skill can retrieve overseas shareholders, executives, and ultimate beneficial owners and analyze equity structure. However, the body of the file documents only one script, company_shareholder_list.py, and all usage/examples are limited to shareholder list lookup; no executive or UBO-specific capability is described anywhere in the implementation-facing documentation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document instructs agents to send request parameters, response data, and error context to an external error-reporting endpoint, which can include sensitive corporate due-diligence inputs, identifiers, and internal error details. Although it notes that sensitive fields are 'automatically desensitized,' it does not define the scope of redaction, require minimization, or warn operators about privacy and data-handling risks, creating a real risk of unintended data disclosure.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file implements authentication lifecycle and billing-related operations that are outside the stated purpose of shareholder and equity research. Scope expansion like API key provisioning, account lookup, recharge-order creation, and pricing queries increases attack surface and gives the skill capabilities to manage credentials and funds, which can surprise users and enable misuse if the skill is invoked in broader agent workflows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module docstring and all user-facing CLI messages are written only in Chinese, indicating a fixed language/locale experience. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill can request a new API key from a remote service and persist it locally, even though that capability is not part of its declared research purpose. Secret provisioning and local credential storage materially increase sensitivity because compromise of the host, logs, or downstream tooling could expose a reusable API credential and enable unauthorized API usage.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
84% confidence
Finding

The explicit require_auth=False setting disables the normal authentication expectation for a sensitive operation that issues credentials. In the context of a research skill, this is especially risky because it embeds account bootstrap behavior where users would expect read-only lookup capabilities, making abuse less visible.

Content

Scanner excerpt · scripts/auth.py (reported line 41)May include surrounding context.

python
pass  # 如果读取失败,继续执行

    # 不需要认证申请新密钥
    response = make_request('/agent/auth/create', {}, require_auth=False)

    # 检查是否申请成功
    if response.get('code') != 0:

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
84% confidence
Finding

The explicit require_auth=False setting disables the normal authentication expectation for a sensitive operation that issues credentials. In the context of a research skill, this is especially risky because it embeds account bootstrap behavior where users would expect read-only lookup capabilities, making abuse less visible.

Content

Scanner excerpt · scripts/auth.py (reported line 41)May include surrounding context.

python
pass  # 如果读取失败,继续执行

    # 不需要认证申请新密钥
    response = make_request('/agent/auth/create', {}, require_auth=False)

    # 检查是否申请成功
    if response.get('code') != 0:

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Recharge-order creation and billing/account functionality are not necessary for due-diligence or shareholder lookup and therefore represent overprivileged behavior for this skill. In an agent setting, hidden monetization or account-management actions can trigger unintended financial operations or expose account state without the user expecting such behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code file contains natural-language descriptions and user-facing output entirely in Chinese, beginning with the module docstring. Under the policy, forcing a specific language without user opt-in can be a locale-policy violation unless the regional restriction is explicitly documented and justified, which is not present in this file.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/common.py:196

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:60