Back to skill

Security audit

magic-api-generate

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a legitimate magic-api reference skill, but its security-sensitive examples are unsafe enough to require review before installation.

Use this only as a magic-api reference, not as production-ready security guidance. Before copying examples, replace MD5/plain password handling with modern password hashing, use random session tokens, avoid returning raw user objects, add authentication and authorization to export/delete/cleanup endpoints, harden file uploads, and review any outbound HTTP destinations and data sent.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:193
Finding

Insecure Password Comparison, Predictable Session Tokens, and Sensitive User Object Exposure

Content
View full analysis
_ ``` Neither component has sufficient unpredictability for an authentication credential. User IDs are commonly enumerable, and login timestamps can often be estimated within a narrow time window. The token therefore lacks the cryptographic entropy expected of a bearer credential. The response also returns the complete database record through `user`. Because the record was obtained with `select *`, it is likely to include the password field and other internal account attributes. ### Attack Path 1. An attacker determines or estimates the target's numeric user ID. 2. The attacker identifies an approximate time at which the target logged in, such as through observable user activity or a login event triggered by social engineering. 3. The attacker generates candidate tokens using the documented `token__` pattern. 4. The attacker submits candidates in the `Authorization` header to protected endpoints. 5. If a candidate matches a token s ...[truncated 828 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/examples.md:43
Finding

Passwords Hashed with Unsalted MD5

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/examples.md:211
Finding

File Upload Validation Trusts Client-Controlled MIME Type and Extension

Content
View full analysis
5 * 1024 * 1024) { return {code: 400, msg: "文件不能超过5MB"}; } // 限制类型 var allowed = ["image/jpeg", "image/png", "image/gif"]; var allowFlag = false; for (var t in allowed) { if (t == contentType) { allowFlag = true; break; } } if (!allowFlag) { return {code: 400, msg: "只支持 JPG/PNG/GIF"}; } // 保存文件 var ext = fileName.substring(fileName.lastIndexOf(".")); var newFileName = Date.now() + ext; var savePath = "/uploads/" + newFileName; file.transferTo(new java.io.File(savePath)); ``` ### Technical Analysis `file.getContentType()` generally reflects the multipart `Content-Type` supplied by the client. An attacker can label arbitrary content as `image/jpeg`, `image/png`, or `image/gif`; this value does not prove that the uploaded bytes are a valid image. The destination extension is copied from the attacker-controlled original filename without mapping it to the accepted media type. Consequently, a request can claim an image MIME type while retaining an active extension such as `.html`, `.svg`, `.jsp`, or another server-relevant suffix. The upload is written directly under `/uploads`. The example does not establish that this directory is outside the web root, non-executable, served from a separate origin, or configured with safe response headers. ### Attack Path 1. An attacker creates an HTML, script, server template, or other active payload. 2. The attacker names it with an executable or browser-active extension. 3. The attacker uploads it while setting the multipart `Content-Type` to an allowed value such as `image/png`. 4. The application accepts the upload because validat ...[truncated 889 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/examples.md:267
Finding

CSV Formula Injection in User Data Export

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (13)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 168)May include surrounding context.

db.update("user", body, "id = ?", path.id); return {code: 200, msg: "更新成功"};

// DELETE /api/user/:id - 删除 db.delete("user", "id = ?", path.id); return {code: 200, msg: "删除成功"};

text

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest says the skill triggers when the user mentions broad phrases like '接口快速开发' and describes wide applicability across Spring Boot integration, database operations, scripting syntax, and RESTful development. It does not clearly bound when the skill should not activate or provide exclusion examples, which could cause unintended invocation in ordinary technical conversations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file includes insert, update, and delete examples that directly modify or remove database records, but it does not provide any warning about the risk of altering production data or causing irreversible loss. Under the markdown-specific warning criteria, behaviors affecting user data or system integrity should be disclosed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The transaction section shows examples that adjust account balances, order records, and product stock, which are integrity-critical operations. The documentation does not warn users that these examples can affect financial or inventory data if run against real systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file includes an upload example that saves an uploaded file to /uploads/ via file.transferTo(...), which affects system storage and persists user data. The surrounding documentation presents the behavior as a generic example but does not include any warning about disk writes, retention, or operational impact.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation includes outbound HttpUtil.get and HttpUtil.post examples to api.example.com, demonstrating network transmission of request data. There is no accompanying warning that using such patterns can send user or system data to external services, which has privacy and integrity implications.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/examples.md (reported line 252)May include surrounding context.

md
var HttpUtil = import('cn.hutool.http.HttpUtil');

// GET 请求
var result = HttpUtil.get("https://api.example.com/users");

// POST 请求
var json = JSON.stringify({name: "张三", age: 25});

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/examples.md (reported line 256)May include surrounding context.

md
var HttpUtil = import('cn.hutool.http.HttpUtil');

// GET 请求
var result = HttpUtil.get("https://api.example.com/users");

// POST 请求
var json = JSON.stringify({name: "张三", age: 25});

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The export example returns all user records without any authentication, authorization, field minimization, or masking. In the context of an API-generation skill, users may copy this directly into production, creating an insecure direct bulk export of personal data that could expose usernames, emails, and account status.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The scheduled cleanup example is exposed as a GET endpoint that deletes data, with no authentication, authorization, or anti-abuse controls. If reachable by an attacker or crawler, it can trigger irreversible deletion of records, making this more serious than a mere missing warning about data removal.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

A natural-language policy issue may exist because the skill documentation appears to force a specific language without offering user choice or documenting that it is intended for a Chinese-speaking audience. The file contains no opt-in, alternative language guidance, or justification for the locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The natural-language headings, comments, and messages throughout the file are written in Chinese, but the document does not indicate that this locale is intentional or offer an alternative language option. Under the stated policy, forcing a specific language without opt-in can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The title and the entire syntax reference are presented in Chinese, and the file does not indicate that other languages are supported or that Chinese is a required locale. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.