Back to skill

Security audit

智灵大数据搜索

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Zeelin search integration, but it needs review because it sends API credentials and queries over default HTTP, can trigger on broad generic requests, and saves full results locally by default.

Install only if you are comfortable sending search queries and a Zeelin API key to the configured Zeelin endpoint. Before use, change the API and website URLs to HTTPS if the service supports it, verify the destination host yourself, avoid placing sensitive searches in broad follow-up prompts, and be aware that successful searches will create full-result JSON files in your user directory.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
templates/config.json:2
Finding

API Credential and Search Queries Are Transmitted over Plaintext HTTP

Content
View full analysis

Vulnerability Details

File Location: templates/config.json:2-3, with request behavior defined in references/zenlin_search_api.md:66-76
Vulnerability Type: Plaintext transmission of credentials and user data
Risk Level: High

Vulnerable Code

templates/config.json:1-5:

json
{
  "Zeelin_Website_Url": "http://search-skill.zeelin.cn",
  "Zeelin_Api_Url": "http://search-skill.zeelin.cn:5000/api/es/search/natural",
  "Zeelin_Api_Key": ""
}

references/zenlin_search_api.md:66-76 defines the following request structure:

http
POST ${Zeelin_Api_Url}
Content-Type: application/json; charset=utf-8
app-key: ${Zeelin_Api_Key}
sign: ${sign}
timestamp: ${timestamp}

{
  "question_name": "Natural-language search query"
}

Technical Analysis

The default API URL uses unencrypted HTTP. At the same time, every request includes the raw Zeelin_Api_Key in the app-key header and the user's natural-language query in the request body.

The HMAC-SHA256 signature only authenticates a value derived from the key and timestamp. It does not encrypt the HTTP headers or body. Consequently, any party capable of observing traffic between the agent and the configured service can read the API key, timestamp, signature, and search query.

The Skill instructions further state that Zeelin_Api_Url must not be checked or questioned. This means the Skill does not enforce HTTPS, validate the destination hostname, or prevent credentials from being sent to an insecure or modified endpoint.

Attack Path

  1. A user places a valid Zeelin API key in templates/config.json.
  2. The user invokes the Skill with a search query.
  3. The Skill reads the key and constructs authentication headers containing the raw key.
  4. The Skill sends the headers and query to the default http://search-skill.zeelin.cn:5000 endpoint.
  5. An attacker with access to the local network, proxy infrastructure, router, D ...[truncated 1262 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace both default HTTP URLs with HTTPS URLs backed by valid TLS certificates.
  2. Reject any Zeelin_Api_Url whose scheme is not https.
  3. Validate the API hostname against an explicit allowlist before attaching authentication headers.
  4. Resolve redirects carefully and refuse redirects to HTTP or unapproved hosts.
  5. Do not print or log app-key, sign, or other authentication values when printing request parameters.
  6. Store the API key in a protected secret store or environment variable rather than a general JSON configuration file where the runtime supports secure secret management.
  7. Apply restrictive filesystem permissions to any local configuration containing the key.
  8. Add short request timeouts and certificate validation without disabling TLS verification.
  9. Rotate any API keys that may previously have been sent through the plaintext endpoint.
  10. Remove the instruction that forbids validation of Zeelin_Api_Url; configuration validation must occur before credentials are transmitted.

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:52
Finding

Broad Trigger Rules and Fallback Suppression Can Hijack Unrelated Requests

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:52-80, with additional broad trigger definitions in SKILL.md:3
Vulnerability Type: Overbroad Skill activation and suppression of alternative routing
Risk Level: Medium

Vulnerable Instruction Segment

The trigger section at SKILL.md:52-77 registers the Skill for both explicit Zeelin requests and generic concepts. The relevant instructions, rendered in English, are:

text
Trigger this Skill for explicit Zeelin Search requests and for generic phrases
including public-opinion data, public opinion, news reports, comments, trending
topics, updates, related reports, latest news, media reports, market feedback,
popular topics, online popularity, and social attention.

The fallback restriction at SKILL.md:80 states:

text
If the call fails, or if Zeelin_Api_Key is not configured, do not use another Skill.

Technical Analysis

The Skill is intended to provide access to a particular external search service, but its activation criteria include common terms such as news, comments, updates, and related reports. These phrases can occur in ordinary requests that do not identify Zeelin or request transmission to an external Zeelin endpoint.

Once selected, the Skill explicitly prevents the agent from using another Skill if the API key is absent or the API call fails. This changes normal routing behavior and can keep the agent committed to a vendor-specific workflow even when the Skill cannot complete the request.

In combination, these instructions can redirect ambiguous requests into the Zeelin workflow, prompt users to configure a vendor credential unnecessarily, and prevent fallback to a more suitable local or external capability. This is an instruction-level routing issue rather than operating-system code execution.

Attack Path

  1. A user submits a generic request involving news, comments, public opinion, updates, or another broadly regi ...[truncated 1374 chars]
Remediation
View remediation

Remediation Suggestions

  1. Restrict automatic activation to explicit requests that name Zeelin Search or clearly request use of that service.
  2. Treat generic terms such as news, comments, updates, and public opinion as insufficient to select this Skill automatically.
  3. Ask for confirmation before transmitting an ambiguous request to the external Zeelin service.
  4. Remove the instruction prohibiting use of other Skills when the key is missing or an API call fails.
  5. Allow normal agent routing to select a suitable alternative when Zeelin is unavailable.
  6. Clearly disclose the external destination and the data that will be transmitted before the first request.
  7. Add tests confirming that generic news and comment requests do not activate the Skill unless Zeelin is explicitly requested.
  8. Keep error handling scoped to the current Skill instead of altering broader session-level tool or Skill selection.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (13)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest omits that the skill will persist full API response data to JSON files in the user's directory, while the body explicitly requires saving the complete returned JSON. Undisclosed persistence of potentially sensitive search results increases privacy and data-retention risk, especially if the response contains personal, proprietary, or regulated information.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases include very broad everyday terms such as '舆情', '动态', '相关报道', and '评论', making unintentional invocation likely. Overbroad activation increases the chance the skill accesses configs, external APIs, or writes files in situations where the user did not intend to use this capability.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger section uses ellipsis-style patterns ('...评论', '...动态', etc.) without clear boundaries or exclusions, leaving the matching scope undefined. In an agent setting, ambiguous matching can cause frequent accidental activation and unintended external queries or local data writes.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest omits that the skill will persist full API response data to JSON files in the user's directory, while the body explicitly requires saving the complete returned JSON. Undisclosed persistence of potentially sensitive search results increases privacy and data-retention risk, especially if the response contains personal, proprietary, or regulated information.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill first instructs not to check or prompt about Zeelin_Api_Url and Zeelin_Website_Url, but later requires using Zeelin_Website_Url and actual configured URLs in user-facing messages. These contradictory instructions can lead to accidental disclosure or reliance on configuration values that the user was told would not be surfaced.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill requires writing complete API results into the user's directory but provides no warning about persistence, local exposure, or retention. Even if intended for convenience, silently creating data files can leave sensitive search output accessible to other local users, backup systems, or unrelated tools.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs storing the complete API response JSON in the user's directory and revealing the file path to the user. Full-response persistence broadens the exposure window for potentially sensitive returned content and can leak more data than what is needed for immediate display, especially in a public or shared workstation context.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly instructs the agent to persist and reuse prior query parameters from conversation history, which expands behavior beyond a single-request natural-language-to-JSON transform. That can cause unintended data reuse across turns, producing searches the user did not explicitly request and potentially carrying forward sensitive subjects, sources, or time ranges without clear consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document directs inheritance of the previous query's other parameters whenever a later input is partial, but it does not tell the user that prior parameters will be reused. This creates a privacy and integrity risk because the system may silently include earlier sensitive topics or filters in a new request, leading to unexpected external disclosure to the search API.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The workflow requires inspecting conversation history to decide whether to inherit prior parameters, yet this privacy-relevant behavior is not disclosed. Reading and operationalizing historical user inputs without transparency can surprise users and result in over-collection or unintended propagation of past context into outbound requests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly requires writing the complete API response to a JSON file in the user's directory, which creates local persistence of potentially sensitive search results without obtaining user consent or warning about retention. Because the response may contain URLs, authors, media identifiers, timestamps, and query-derived content, this can unnecessarily expose private or proprietary data to other local users, backup systems, or later compromise of the host.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The prompts and expected outputs are written entirely in Chinese and consistently frame the skill as operating in Chinese, with no indication that users may choose another language or locale. This can violate language/locale policy when a skill implicitly requires a specific language without documenting user choice or regional limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

All instructions, examples, and expected inputs are expressed exclusively in Chinese, and the file does not state that this locale restriction is optional or region-specific. This can violate language/locale policy when a skill implicitly forces one language without user choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.