Back to skill

Security audit

Zhipu Tools Coding Plan

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its stated Z.AI tool purpose, but it has review-worthy billing, privacy, and optional remote-code execution risks.

Review before installing. Use this only if you are comfortable sending search terms, URLs, repository identifiers, and selected local files or media to Z.AI/Zhipu. Prefer the Python `zhipu_tool.py` path over the direct shell search/reader wrappers, avoid sensitive documents/screenshots/videos, and do not run the optional unpinned npm command unless you pin and trust the package version.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/web_search.sh:120
Finding

Automatic Fallback to Potentially Billable Legacy APIs Without Explicit Consent

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:190
Finding

Unpinned Third-Party Package Download and Execution Through npx

Content
View full analysis
Vision MCP 需要本地 npm 运行,暂未集成到本 Skill 脚本中。 ``` ### Technical Analysis The documentation instructs users to run `npx -y @z_ai/mcp-server` without an exact version, lockfile, or integrity constraint. `npx` may download the currently resolved package from the configured npm registry and execute it immediately. The `-y` option suppresses the normal interactive confirmation. Consequently, the effective executable payload can change after the Skill itself has been audited. A compromised package release, compromised publisher account, registry substitution, or unexpected upstream update could introduce arbitrary installation or runtime code. The package is described as optional and is not automatically invoked by the included scripts. Nevertheless, the command is an executable usage instruction exposed to users and Agents. ### Attack Path 1. A user follows the documented Vision MCP instructions. 2. `npx` resolves the unversioned `@z_ai/mcp-server` package through the configured npm registry. 3. `npx` downloads the currently available package version without prompting because `-y` is specified. 4. Package lifecycle or runtime code executes locally. 5. If the resolved package or registry path is compromised, attacker-controlled code runs with the permissions of the invoking user. ### Impact Assessment A compromised dependency could access files, environment variables, API credentials, network resources, and processes available to the invoking user. It could also modify user-owned configuration or establish persistence where local permis ...[truncated 177 chars]
Remediation
View remediation
``` 2. Remove `-y` so users must confirm package retrieval. 3. Publish and verify the expected package integrity hash and provenance. 4. Prefer installation through a project-level `package.json` and committed lockfile. 5. Document the registry origin and warn users that the package executes local third-party code. 6. Review each version before updating the pinned dependency. 7. Where possible, run the package in a restricted container or sandbox without unrelated credentials or filesystem access. ]]>

T09 · Insecure Skill Coding Practices

Note
Location
scripts/web_search.sh:31
Finding

User-Controlled Values Are Interpolated Into JSON Without Escaping

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (52)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file parsing examples encourage users to process local documents but do not disclose that document contents may be uploaded to a remote service for parsing. In a skill context, users may assume local CLI processing, so this omission materially increases the risk of accidental exfiltration of sensitive documents such as reports, contracts, credentials, or internal data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

代码的实际功能是单一的“网络搜索”,这与描述中列出的多项工具能力不一致。虽然描述包含“网络搜索”这一项,且代码确实访问相符的外部智谱/Z.AI 搜索接口,但当前代码片段没有体现其余宣称功能,因此描述对该代码块的能力范围有明显夸大。未发现额外的、未声明的高风险能力;问题主要在于声明比实际实现更宽。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

代码行为明显比声明范围窄。该脚本专门面向 GitHub 仓库文档搜索,不包含通用网络搜索、网页读取、文件解析、视觉理解或额度查询功能。虽然声明中包含“GitHub 仓库文档搜索”这一项,与实际代码部分一致,但整体描述将该技能表述为多功能工具集合,而提供的代码块只实现其中一个子工具。因此描述未准确代表该代码块的实际能力范围,属于描述与行为不一致。

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/zhipu.sh (reported line 13)May include surrounding context.

sh
set -euo pipefail

SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
# 加载 .env 中的 API Key
ENV_FILE="$SCRIPT_DIR/../.env"
if [[ -f "$ENV_FILE" ]]; then
  while IFS='=' read -r key val; do

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/zhipu.sh (reported line 14)May include surrounding context.

sh
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
# 加载 .env 中的 API Key
ENV_FILE="$SCRIPT_DIR/../.env"
if [[ -f "$ENV_FILE" ]]; then
  while IFS='=' read -r key val; do
    [[ "$key" =~ ^#.*$ || -z "$key" ]] && continue

Credential Access

High
Category
Privilege Escalation
Confidence
87% confidence
Finding

Automatically reading a local .env file can expose credentials and other secrets to this tool's runtime without explicit user intent, especially because it loads from both the skill root and script directory. In a skill/plugin context, broad secret ingestion is risky because it increases the chance that unrelated credentials become accessible to code paths that also perform outbound network operations.

Content

Scanner excerpt · scripts/zhipu_tool.py (reported line 33)May include surrounding context.

python
def _load_dotenv():
    """自动加载脚本同目录或 SKILL 根目录下的 .env 文件"""
    script_dir = Path(__file__).resolve().parent
    skill_dir = script_dir.parent
    for env_path in [skill_dir / ".env", script_dir / ".env"]:

Credential Access

High
Category
Privilege Escalation
Confidence
87% confidence
Finding

The code checks for and consumes .env content from local directories, which is credential collection behavior broader than necessary for the advertised features. While not overtly malicious, it raises the blast radius of any future bug or logging issue because more secrets are placed into process environment state.

Content

Scanner excerpt · scripts/zhipu_tool.py (reported line 36)May include surrounding context.

python
"""自动加载脚本同目录或 SKILL 根目录下的 .env 文件"""
    script_dir = Path(__file__).resolve().parent
    skill_dir = script_dir.parent
    for env_path in [skill_dir / ".env", script_dir / ".env"]:
        if env_path.exists():
            with open(env_path, encoding="utf-8") as f:
                for line in f:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README promotes web search, web page reading, and repository/file retrieval features without clearly warning that user-entered queries, URLs, repository identifiers, and requested paths are transmitted to external Z.AI/Zhipu services. This can lead users to unknowingly send sensitive internal URLs, private repository names, or confidential investigation terms to a third party.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The README recommends executing an unpinned npm package directly with npx -y @z_ai/mcp-server, which fetches and runs the latest published code from the registry at execution time. If the package is compromised, hijacked, or changed unexpectedly, users may run arbitrary code on their local machine without review.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill advertises shell, network, and environment-dependent behavior but does not declare an explicit permission or allowed-tools scope. That increases the chance an agent can invoke the skill with broader capabilities than the user expects, including network access and use of API keys from the environment.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill maps broad, ordinary phrases like '搜一下/查一下/找一下' to remote tool invocations without clear scope boundaries or sensitivity checks. In an agent setting, this can cause over-eager transmission of user queries, URLs, repo names, or local media to third-party services when the user may only be asking generally, increasing privacy and data-exfiltration risk.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation gives contradictory statements about whether file parsing uses paid account balance or free Coding Plan quota. Billing and execution-path ambiguity is security-relevant because users or agents may unintentionally route data to a paid or different backend, causing unexpected charges and possibly different data-handling semantics.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The vision feature accepts remote URLs and local files for analysis but does not present a clear privacy warning about sending image or video content to a third-party API. Users may unknowingly submit sensitive screenshots, documents, faces, or internal recordings to an external provider, creating confidentiality and compliance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script transmits a local file and an API credential to a remote third-party service, but it provides no explicit warning, confirmation prompt, or data-handling notice at the point of use. In a file-parsing skill, this behavior is functionally expected, yet it still creates a real confidentiality and privacy risk because users may upload sensitive documents without realizing they are leaving the local environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script forwards a local image path or remote URL directly to an external Python tool that invokes a vision API, but it provides no explicit warning, consent prompt, or indication that the image content may leave the local environment. This creates a real privacy and data-handling risk because users may unknowingly submit sensitive local images or internal URLs to a third-party service.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/web_reader.sh (reported line 26)May include surrounding context.

sh
# 旧版 bigmodel API 网页读取
_reader_legacy() {
    local url="$1"
    curl -s --request POST \
        --url "https://open.bigmodel.cn/api/paas/v4/reader" \
        --header "Authorization: Bearer $API_KEY" \
        --header 'Content-Type: application/json' \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code posts the user-provided URL to an external API and includes the bearer API key in the request, but there is no runtime disclosure, confirmation, or user-facing warning about sending data off-host. The nearby comments are implementation-oriented and not sufficient as a user disclosure for a safety-relevant network operation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The MCP initialization and subsequent tool calls contact a remote endpoint using the bearer API key and later submit the requested URL for remote processing. Although the script has internal comments and usage text, it does not clearly warn the user that invoking the script transmits data to external services.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/web_reader.sh (reported line 70)May include surrounding context.

sh
fi

    # Step 2: Notify initialized
    curl -s --request POST \
        --url "$mcp_url" \
        --header "Authorization: Bearer $API_KEY" \
        --header "Content-Type: application/json" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/web_search.sh (reported line 76)May include surrounding context.

sh
fi

    # Step 2: Notify initialized
    curl -s --request POST \
        --url "$mcp_url" \
        --header "Authorization: Bearer $API_KEY" \
        --header "Content-Type: application/json" \

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Comments and user-visible usage/error text are written exclusively in Chinese, including setup instructions and runtime messages. This can violate language/locale policy where skills should not force a specific language without user opt-in or clear justification.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/web_search.sh (reported line 27)May include surrounding context.

sh
# 旧版 bigmodel API 搜索
_search_legacy() {
    local query="$1" count="$2"
    curl -s --request POST \
        --url "https://open.bigmodel.cn/api/paas/v4/web_search" \
        --header "Authorization: Bearer $API_KEY" \
        --header 'Content-Type: application/json' \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This shell script sends the user-provided search query to remote services via curl in both API modes, which is a network operation that transmits user data off-system. While the code contains developer comments, it lacks a user-facing disclosure at the point of execution about sending the query to third-party endpoints.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/zhipu_tool.py (reported line 86)May include surrounding context.

python
"clientInfo": {"name": "openclaw-zhipu-tools", "version": "1.1.0"},
            },
        }
        resp = requests.post(url, headers=headers, json=body, timeout=30)
        resp.raise_for_status()

        session_id = resp.headers.get("mcp-session-id", "")

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/zhipu_tool.py (reported line 105)May include surrounding context.

python
"Accept": "application/json",
            "Mcp-Session-Id": session_id,
        }
        requests.post(
            url,
            headers=notify_headers,
            json={"jsonrpc": "2.0", "method": "notifications/initialized"},

Static analysis

No suspicious patterns detected.