T09 · Insecure Skill Coding Practices
- Location
scripts/extract.js:76- Finding
SSRF Protection Bypass Through Redirects, DNS Rebinding, and Incomplete IP Validation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This search skill is mostly purpose-aligned, but its URL extraction and documentation create real review-worthy privacy and internal-network risk.
Install only if you are comfortable with search queries and extracted URLs being sent to external providers. Avoid using URL extraction on untrusted links in sensitive networks, prefer environment variables for API keys, and review or update the npm dependencies before use.
scripts/extract.js:76SSRF Protection Bypass Through Redirects, DNS Rebinding, and Incomplete IP Validation
scripts/extract.js:120Unbounded Response Buffering Enables Memory Exhaustion
package-lock.json:24Dependency Lockfile Uses a Third-Party Registry Mirror
Sequential fallback to one engine while claiming aggregation, optional APIs, ranking, and internal-network checks is materially misleading. In a network-enabled skill, false safety and capability claims can cause reviewers and users to underestimate privacy, reliability, and SSRF-related risks.
Sequential fallback to one engine while claiming aggregation, optional APIs, ranking, and internal-network checks is materially misleading. In a network-enabled skill, false safety and capability claims can cause reviewers and users to underestimate privacy, reliability, and SSRF-related risks.
Sequential fallback to one engine while claiming aggregation, optional APIs, ranking, and internal-network checks is materially misleading. In a network-enabled skill, false safety and capability claims can cause reviewers and users to underestimate privacy, reliability, and SSRF-related risks.
Sequential fallback to one engine while claiming aggregation, optional APIs, ranking, and internal-network checks is materially misleading. In a network-enabled skill, false safety and capability claims can cause reviewers and users to underestimate privacy, reliability, and SSRF-related risks.
Sequential fallback to one engine while claiming aggregation, optional APIs, ranking, and internal-network checks is materially misleading. In a network-enabled skill, false safety and capability claims can cause reviewers and users to underestimate privacy, reliability, and SSRF-related risks.
Sequential fallback to one engine while claiming aggregation, optional APIs, ranking, and internal-network checks is materially misleading. In a network-enabled skill, false safety and capability claims can cause reviewers and users to underestimate privacy, reliability, and SSRF-related risks.
Sequential fallback to one engine while claiming aggregation, optional APIs, ranking, and internal-network checks is materially misleading. In a network-enabled skill, false safety and capability claims can cause reviewers and users to underestimate privacy, reliability, and SSRF-related risks.
Sequential fallback to one engine while claiming aggregation, optional APIs, ranking, and internal-network checks is materially misleading. In a network-enabled skill, false safety and capability claims can cause reviewers and users to underestimate privacy, reliability, and SSRF-related risks.
The lockfile pins axios 1.13.6, and the static analysis indicates multiple published advisories including SSRF/proxy-bypass and prototype-pollution-related request manipulation issues. In a search aggregation skill that makes outbound HTTP requests to multiple engines and likely processes user-controlled URLs or queries, a vulnerable HTTP client materially increases risk of SSRF, credential leakage, or traffic interception effects.
form-data 4.0.5 is reported as vulnerable to CRLF injection via unescaped multipart field names and filenames. If this skill ever constructs multipart requests using user-influenced field names or filenames—for example when interacting with optional APIs or upload-style endpoints—an attacker could manipulate request structure or smuggle unexpected headers/content.
undici 7.24.4 is flagged with multiple high-severity advisories including response queue poisoning, information disclosure, and desynchronization issues. Because this package is brought in through cheerio and may be used for network fetching in a tool that retrieves arbitrary web content, these flaws can affect confidentiality and integrity of fetched results, especially under attacker-controlled server responses.
The dependency specification for axios permits installation of vulnerable versions, and the finding indicates a resolved version selection that includes known SSRF and related security advisories. Because this skill is a multi-engine search tool making outbound web requests and likely handling untrusted URLs/content, an HTTP client weakness is especially relevant and can enable request manipulation, proxy bypass, or exposure of internal resources.
The guide tells users to place long-lived API credentials directly into a local JSON config file, but does not warn about file permissions, accidental commits, backups, or other forms of secret exposure. In a developer tool skill, this is a real secret-handling weakness because users commonly store skill directories in synced folders or version control, making credential leakage plausible.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The README instructs users to run python3 search-pro/scripts/*.py, which expands to every Python script in the directory and can execute unintended files. Combined with the vague guidance to 'check scripts/ directory', this weakens execution boundaries and increases the chance of running helper, test, or maliciously added scripts without understanding their behavior.
The file advertises web search, multi-engine aggregation, and URL content extraction, but the security notes claim 'No network calls (unless specified)' and 'No data sent to external servers'. For a search skill, these statements are materially misleading because the core function necessarily involves outbound requests and possible transmission of search queries, URLs, and extracted content to third-party services, which can cause unsafe operator assumptions.
The skill advertises and documents network access and reading a local configuration file, but it does not declare an explicit tool scope such as permissions or allowed-tools. That creates a governance and review gap: downstream systems or users may not realize the skill requires network and file-read capabilities, increasing the risk of unintended data exposure or over-privileged execution.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
**注意:** API Key 存储在 `config/search-config.json`,没有单独的 api-keys.json 文件
**安全建议:**
- 配置文件权限:`chmod 600 config/search-config.json`
- 不要将 API Key 提交到 Git(添加到 .gitignore)
- 使用环境变量更安全(不写入文件)
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
'bs': 0 # 起始位置
}
response = requests.post(url, headers=headers, json=payload, timeout=10)
response.raise_for_status()
data = response.json()
The code sends the user's search query to Baidu's cloud API, but this request path does not provide any user-facing notice, consent flow, or sensitivity check before transmitting potentially private input to a third party. In a search/research skill, users may enter confidential terms, making silent external transmission a real privacy risk rather than a purely theoretical issue.
The fallback path transmits user queries to Baidu mobile web search without an explicit warning, so data may leave the system even when the official API path fails. Because this is an automatic fallback, users may not realize their input is being sent to a different third-party endpoint, increasing privacy and compliance risk.
The file's title, class docstrings, inline usage text, comments, and CLI output are written in Chinese, with no indication that users can choose another language. This can violate language/locale policy when a skill imposes a single language by default rather than offering an opt-in or alternative.
The code sends user search queries directly to third-party services including DuckDuckGo, Bing, Google, and Tavily, but provides no disclosure, consent flow, or data-handling notice to the caller. This can expose sensitive prompts, internal project names, credentials pasted into queries, or regulated data to external providers, which is a real privacy and data-governance risk in an agent skill.
Detected: suspicious.exposed_secret_literal, suspicious.obfuscated_code