Back to skill

Security audit

Byted Market Insight Agent

Security checks for vulnerabilities and agentic risk

Overview

This market-insight skill is mostly coherent, but it handles cloud credentials and business data with several under-scoped and risky defaults.

Review this skill before installing. Use it only in an environment where you are comfortable granting access to Volcengine or Gateway credentials and market-insight data. Prefer explicit environment variables or a secure secret store, disable automatic pip installation, avoid relying on shell rc-file scanning, and do not use a custom Gateway URL unless you trust and verify the destination.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/providers/gateway_provider.py:77
Finding

Bearer Credentials and Request Data Can Be Sent to an Unrestricted Gateway Destination

Content
View full analysis
Dict[str, Any]: """Execute one HTTP request and parse its JSON response.""" data = json.dumps(payload).encode("utf-8") headers = { "Content-Type": "application/json; charset=UTF-8", "Authorization": f"Bearer {api_key}", "ServiceName": "insight", } for attempt in range(MAX_RETRIES): try: _debug_request_summary(action, method, url, payload) if method == "GET": req = urllib.request.Request(url, data=data, headers=headers) req.get_method = lambda: "GET" # type: ignore[assignment] else: req = urllib.request.Request( url, data=data, headers=headers, method="POST" ) with urllib.request.urlopen(req, timeout=DEFAULT_TIMEOUT) as resp: body = resp.read() ``` The destination is constructed without validation: ```python def _build_url(api_base: str, action: str) -> str: return f"{api_base.rstrip('/')}/?Action={action}&Version={API_VERSION}" ``` ### Technical Analysis The gateway provider sends an API key in an `Authorization: Bearer` header together with market-insight request parameters. Authentication data must be transmitted for the gateway functionality, but the destination comes from `ARK_SKILL_API_BASE` or the persisted authentication file and is not constrained to an official service. The implementation does not: - Require HTTPS. - Restrict the hostname to an approved gateway domain. - Reject URL user information or unexpected ports. - Prevent redirects to a different origin. - Require confi ...[truncated 1457 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/auth_resolver.py:171
Finding

Automatic Shell Startup-File Scanning Silently Adopts Credentials Outside the Skill Directory

Content
View full analysis
Dict[str, str]: """Parse export lines from common rc files.""" if _RC_ENV_CACHE: return dict(_RC_ENV_CACHE) home = Path.home() rc_files = [ ("~/.bashrc", home / ".bashrc"), ("~/.bash_profile", home / ".bash_profile"), ("~/.zshrc", home / ".zshrc"), ("~/.profile", home / ".profile"), ] pattern = re.compile(r"^\s*export\s+([A-Za-z_][A-Za-z0-9_]*)=(.*)$") for display_name, path in rc_files: if not path.exists() or not path.is_file(): continue try: content = path.read_text(encoding="utf-8", errors="ignore") except Exception: continue for line in content.splitlines(): match = pattern.match(line) if not match: continue var_name, raw_value = match.group(1), match.group(2).strip() if var_name not in RC_ENV_TARGET_VARS: continue ``` The discovered values are automatically activated: ```python if need_gateway or need_sdk: rc_env = load_rc_env() if need_gateway: rc_base = rc_env.get("ARK_SKILL_API_BASE") rc_key = rc_env.get("ARK_SKILL_API_KEY") if rc_base and rc_key: auth.gateway_api_base = rc_base auth.gateway_api_key = rc_key if need_sdk: rc_ak = rc_env.get("VOLCSTACK_ACCESS_KEY_ID") rc_sk = rc_env.get("VOLCSTACK_SECRET_ACCESS_KEY") if rc_ak and rc_sk: auth.sdk_access_key_id = rc_ak auth.sdk_secret_access_key = rc_sk ``` ### Technical Analysis The Skill reads several files in the user's home directory and extracts selected gateway and cloud credentials. It does not execute the files, and parsing is limited t ...[truncated 1747 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/auth_resolver.py:281
Finding

Cloud Credentials Are Persisted in Plaintext Without Enforced File Permissions

Content
View full analysis
None: try: path.parent.mkdir(parents=True, exist_ok=True) payload = json.dumps(data, ensure_ascii=False) path.write_text(payload, encoding="utf-8") except Exception: return ``` Gateway and SDK secrets are written directly into the JSON document: ```python def save_auth_gateway(api_base: str, api_key: str) -> None: raw = _safe_read_json(AUTH_FILE) raw["gateway"] = { "api_base": api_base, "api_key": api_key, } _safe_write_json(AUTH_FILE, raw) def save_auth_sdk(access_key_id: str, secret_access_key: str, region: str) -> None: raw = _safe_read_json(AUTH_FILE) raw["sdk"] = { "access_key_id": access_key_id, "secret_access_key": secret_access_key, "region": region, } _safe_write_json(AUTH_FILE, raw) ``` ### Technical Analysis The Skill stores reusable gateway tokens and Volcengine access-key credentials as plaintext JSON. `Path.write_text()` creates or truncates the file using permissions derived from the process umask; the code does not enforce owner-only access. The implementation also lacks: - A secure operating-system credential store. - Explicit `0600` file and `0700` directory modes. - Symlink rejection. - Atomic file replacement. - Validation that the persistence path remains a regular file under the intended directory. - User opt-in at the storage function boundary. The documented private `persist/` directory provides organizational isolation but does not guarantee confidentiality or integrity. ### Attack Path 1. The Agent collects gateway or SDK credentials through the documented minimal-question workflow. 2. The Agent calls `save_auth_gateway()` or `save_auth_sdk()`. 3. ...[truncated 939 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/auth_resolver.py:443
Finding

SDK Dependency Is Automatically Installed at Runtime Without an Exact Version or Integrity Pin

Content
View full analysis
bool: """Ensure that the SDK is available.""" st = state or load_state() if st.sdk_install_failed: return False if _try_import_sdk(): if not st.sdk_installed: st.sdk_installed = True save_state(st) return True auto_pip_flag = os.getenv("MARKET_INSIGHT_AUTO_PIP", "1").lower() allow_auto_pip = auto_pip_flag in {"1", "true", "yes", "y"} if not allow_auto_pip: return False print( "[INFO] SDK is not installed; automatically installing " f"{SDK_MIN_VERSION_SPEC}..." ) cmd = [sys.executable, "-m", "pip", "install", SDK_MIN_VERSION_SPEC] try: proc = subprocess.run( cmd, check=False, stdout=subprocess.PIPE, stderr=subprocess.PIPE, text=True, ) ``` The version specification is open-ended: ```python SDK_MIN_VERSION_SPEC = "volcengine-python-sdk>=5.0.22" ``` ### Technical Analysis Automatic installation is enabled by default. When the SDK cannot be imported and SDK credentials are available, the Skill launches pip without explicit user approval. The dependency uses a minimum-version constraint rather than an audited exact version. No lockfile, package hash, isolated environment, or fixed package index is enforced. Therefore, the effective code installed in the future can differ from the code reviewed with this Skill. Pip installation may execute package build hooks, and imported packages execute with the same privileges as the Agent process. No evidence was found that the named dependency is currently malicious. The vulnerability is the unsafe supply-chain mechanism, not a confirmed malicious package. ...[truncated 1002 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/providers/gateway_provider.py:65
Finding

Gateway Response Bodies Are Printed Unconditionally and May Expose Sensitive Business Data

Content
View full analysis
None: try: text = body.decode("utf-8", errors="replace") except Exception: # noqa: BLE001 return snippet = text[:500] print( f"[DEBUG][gateway] Action={action} response body first 500 characters:" f" {snippet!r}" ) ``` The function is called for every successful gateway response: ```python with urllib.request.urlopen(req, timeout=DEFAULT_TIMEOUT) as resp: body = resp.read() _debug_response_summary(action, body) try: parsed = json.loads(body.decode("utf-8")) ``` ### Technical Analysis Although the output is labeled as debug logging, it is not controlled by a debug flag. The first 500 characters of every successful gateway response are printed to standard output. The affected APIs return task metadata, filtered social-media content, company profiles, opportunity clues, identifiers, and pagination tokens. These records may contain commercially sensitive or account-specific information. Standard output may be retained in terminal history, Agent transcripts, CI logs, centralized observability systems, or support bundles. The code only avoids printing HTTP error bodies. It does not redact or suppress successful response content. ### Attack Path 1. A user invokes one of the gateway-backed market-insight operations. 2. The gateway returns task, post, or clue data. 3. `_debug_response_summary()` decodes the complete response and extracts the first 500 characters. 4. The snippet is printed unconditionally. 5. Any party with access to captured process output or aggregated logs can read the exposed data. A malicious gateway could deliberately place secrets or misleading content at the start of its response to ...[truncated 486 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (23)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented behavior claims broad market-intelligence and data-retrieval functions, while the described implemented behavior is largely local environment inspection and project validation. This mismatch is dangerous because users and orchestrators may authorize the skill expecting benign business-data retrieval, while it actually accesses local configuration sources and persisted credentials, creating a consent and trust-boundary failure.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger conditions are extremely broad, covering many common discussion topics and even indirect references, which can cause the skill to activate in conversations where users did not intend to invoke a market-insight integration. Because this skill may inspect local environment data and stored credentials, accidental activation materially raises the chance of unnecessary sensitive-data access and unintended external requests.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
Skill 内部通过 `scripts/auth_resolver.py` 实现了一套智能的 Provider 选择策略,其决策顺序如下:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill advertises and documents capabilities to read environment variables, inspect shell rc files, persist credentials to disk, invoke shell-based validation, and access networked providers, but it declares no explicit tool scope or permission boundaries. In an agent ecosystem, that omission increases the chance of overbroad access being granted implicitly and makes security review, least-privilege enforcement, and user consent much weaker.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly describes persisting user credentials and reading shell configuration files to discover secrets, yet it does not present a strong, user-facing risk notice or consent model. This is dangerous because rc files and persisted auth stores often contain sensitive tokens unrelated to the immediate task, and silent discovery/storage increases the likelihood of unauthorized secret exposure, cross-session leakage, and excessive retention.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The 'trigger scenarios' section lists broad use cases but lacks clear constraints, exclusions, or a confirmation boundary before sensitive actions. In context, that is risky because the skill is not purely informational: it may read rc files, inspect environment variables, and use persisted credentials, so ambiguous triggering can expand data access beyond user expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file presents all user-facing documentation in Chinese, and there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation describes persisting API keys and access keys in persist/auth.json and also scanning shell startup files for candidate credentials, but it does not present a strong warning, consent mechanism, or secure-storage guarantees. This creates a privacy and security issue because highly sensitive credentials may be harvested from broader user context and stored locally in ways users may not expect, increasing exposure if the host or workspace is compromised.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly documents scanning users' shell rc files to discover credentials unrelated to the immediate task flow. Even though it claims to parse only simple export lines and avoid command execution, this still expands the skill's access into sensitive local files and can collect secrets without an explicit, contextual user action. In a market-insight skill, that behavior is not necessary to fulfill the core business purpose and increases the risk of over-collection of credentials.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The resolver scans user shell rc files to discover credentials, reaching into local configuration files that may contain unrelated secrets. For a market-insight skill, this exceeds least-privilege expectations and can expose or normalize access to sensitive host data without a clear, narrowly scoped need.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Auto-installing volcengine-python-sdk is not required for merely resolving credentials and selecting a provider, so it expands the skill's capabilities beyond user expectations. In this market-insight context, silently fetching and installing software creates a supply-chain and persistence risk that is disproportionate to the stated purpose.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The module documentation says it performs no real network calls, but the runtime pip install path typically requires network access. This mismatch is security-relevant because it can mislead reviewers, operators, and users about the trust boundary and side effects of loading the skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code persists API keys and access keys to persist/auth.json in plaintext with no evident encryption, permission hardening, or explicit disclosure. If the host filesystem is accessible to other users, processes, backups, or logs, these credentials can be recovered and reused to access external services.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
95% confidence
Finding

The code executes pip install at runtime via subprocess.run, which introduces an unnecessary code-execution and supply-chain risk inside an auth resolver. Even though the command is not directly shell-injected, it can trigger network access, install untrusted or tampered packages, and mutate the runtime environment in response to ordinary skill use.

Content

Scanner excerpt · scripts/auth_resolver.py (reported line 477)May include surrounding context.

python
cmd = [sys.executable, "-m", "pip", "install", SDK_MIN_VERSION_SPEC]

    try:
        proc = subprocess.run(
            cmd,
            check=False,
            stdout=subprocess.PIPE,

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Natural-language strings throughout the file, including the top-level docstring and CLI descriptions, are presented only in Chinese. The file does not offer any user opt-in, locale selection, or justification for restricting interaction to a specific language.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This Python code performs external API requests using access keys and request parameters such as task IDs, time ranges, and clue/post retrieval inputs, but the file provides no user-facing warning, confirmation, or logging that data is being sent to a remote service. For code files, network/HTTP transmission of user or system data should have some visible disclosure unless clearly covered elsewhere; this file contains only developer-oriented docstrings and comments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

All user- and developer-facing natural-language guidance in the module docstring is written in Chinese, and the prompt text shown to the Agent layer is also Chinese-only. The file does not indicate that the skill is intentionally China-specific or provide any language/locale opt-in, which can violate a language-choice policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The MINIMAL_ASK_HINT string contains the user-facing credential request entirely in Chinese. Because this text is intended to be surfaced by the Agent layer to users, it enforces a single language without opt-in or documented locale justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This Python code routes requests through a Gateway or SDK provider and exposes functions that query remote services, which implies network transmission of user-supplied parameters such as TaskID, time ranges, and task names. While the module documents provider selection and fallback behavior, it does not disclose to users that invoking these commands sends data to external services.

Content

No source excerpt is available for this finding.

Dynamic attribute access via getattr()

Low
Category
Dangerous Code Execution
Confidence
50% confidence
Finding

Dynamic getattr() with a non-literal attribute name can access arbitrary object attributes, potentially bypassing access controls.

Content

Scanner excerpt · scripts/client.py (reported line 66)May include surrounding context.

python
for _ in range(2):
        provider = get_provider(exclude)
        try:
            func = getattr(provider, method_name)
        except AttributeError as exc:  # noqa: BLE001
            raise RuntimeError(
                f"Provider {provider.name} 不支持方法 {method_name}"

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The module docstring is entirely in Chinese and presents the implementation details, warnings, and behavior in a single language with no indication of locale choice or user opt-in. Under the stated policy, forcing a specific language without offering a choice can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The natural-language documentation in this file is entirely in Chinese and does not indicate that language selection is optional or contextually required. Under the policy, forcing a specific language without user opt-in can be a locale/language policy violation unless the constraint is documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and all printed status messages are written only in Chinese, which imposes a specific language on users. The file does not offer an opt-in language choice or explain that the skill is intentionally limited to a Chinese-speaking context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.