T05 · Unauthorized Access and Privilege Escalation
- Location
search-intelligence-skill/search_dorks_skill/config.py:387- Finding
Undeclared Credential Discovery and Security Reconnaissance Capabilities
- Content
View full analysis
Vulnerability Details
File Location:
search-intelligence-skill/search_dorks_skill/config.py:387-419
Vulnerability Type: Undeclared security reconnaissance and sensitive-data discovery
Risk Level: HighComplete Vulnerable Code
python DORK_TEMPLATES: dict[str, dict[str, list[str]]] = { "security": { "exposed_files": [ 'site:{domain} filetype:env', 'site:{domain} filetype:env "DB_PASSWORD" OR "SECRET_KEY" OR "API_KEY"', 'site:{domain} filetype:log', 'site:{domain} filetype:sql "password"', 'site:{domain} filetype:bak OR filetype:old OR filetype:backup', 'site:{domain} filetype:conf OR filetype:cfg OR filetype:ini', 'site:{domain} filetype:pem OR filetype:key', 'site:{domain} filetype:json "api_key" OR "secret"', ], "directory_listing": [ 'site:{domain} intitle:"index of"', 'site:{domain} intitle:"directory listing"', 'site:{domain} "parent directory" "size" "last modified"', 'site:{domain} intitle:"index of" "backup"', ], "admin_panels": [ 'site:{domain} inurl:admin', 'site:{domain} inurl:login OR inurl:signin', 'site:{domain} inurl:dashboard', 'site:{domain} intitle:"admin" OR intitle:"login" OR intitle:"panel"', 'site:{domain} inurl:wp-admin OR inurl:wp-login', 'site:{domain} inurl:phpmyadmin OR inurl:adminer', 'site:{domain} inurl:cpanel OR inurl:webmail', ], "sensitive_data": [ 'site:{domain} "password" filetype:txt OR filetype:log', 'site:{domain} "-----BEGIN RSA PRIVATE KEY-----"', 'site:{domain} "-----BEGIN OPENSSH PRIVATE KEY-----"', 'site:{domain} "AWS_ACCESS_KEY_ID" OR "AKIA"', 'site:{domain} "DATABASE_URL" OR "MONGO_URI" OR "REDIS_URL"', 'site:{domain} "smtp" "password" file ...[truncated 2538 chars]- Remediation
View remediation
Remediation Suggestions
- Remove the unrelated
search-intelligence-skillpackage from the Bitcoin-oracle artifact. - If the search package is distributed separately, disable credential, private-key, and sensitive-file templates by default.
- Require an explicit security-testing mode and informed user confirmation before generating sensitive reconnaissance queries.
- Enforce an allowlist of domains that the operator has declared as authorized targets.
- Reject broad, wildcard, or missing targets for security-related searches.
- Record the approved target and scope in a structured authorization object and validate every generated query against it.
- Separate general web search from security reconnaissance using distinct permissions and installation packages.
- Clearly disclose all OSINT and security capabilities in the primary manifest and Skill description.
- Add tests proving that security templates cannot execute without an authorized target and explicit confirmation.
- Remove the unrelated
