T09 · Insecure Skill Coding Practices
- Location
scripts/web_search.sh:120- Finding
Automatic Fallback to Potentially Billable Legacy APIs Without Explicit Consent
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly matches its stated Z.AI tool purpose, but it has review-worthy billing, privacy, and optional remote-code execution risks.
Review before installing. Use this only if you are comfortable sending search terms, URLs, repository identifiers, and selected local files or media to Z.AI/Zhipu. Prefer the Python `zhipu_tool.py` path over the direct shell search/reader wrappers, avoid sensitive documents/screenshots/videos, and do not run the optional unpinned npm command unless you pin and trust the package version.
scripts/web_search.sh:120Automatic Fallback to Potentially Billable Legacy APIs Without Explicit Consent
README.md:190Unpinned Third-Party Package Download and Execution Through npx
scripts/web_search.sh:31User-Controlled Values Are Interpolated Into JSON Without Escaping
The file parsing examples encourage users to process local documents but do not disclose that document contents may be uploaded to a remote service for parsing. In a skill context, users may assume local CLI processing, so this omission materially increases the risk of accidental exfiltration of sensitive documents such as reports, contracts, credentials, or internal data.
代码的实际功能是单一的“网络搜索”,这与描述中列出的多项工具能力不一致。虽然描述包含“网络搜索”这一项,且代码确实访问相符的外部智谱/Z.AI 搜索接口,但当前代码片段没有体现其余宣称功能,因此描述对该代码块的能力范围有明显夸大。未发现额外的、未声明的高风险能力;问题主要在于声明比实际实现更宽。
代码行为明显比声明范围窄。该脚本专门面向 GitHub 仓库文档搜索,不包含通用网络搜索、网页读取、文件解析、视觉理解或额度查询功能。虽然声明中包含“GitHub 仓库文档搜索”这一项,与实际代码部分一致,但整体描述将该技能表述为多功能工具集合,而提供的代码块只实现其中一个子工具。因此描述未准确代表该代码块的实际能力范围,属于描述与行为不一致。
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
set -euo pipefail
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
# 加载 .env 中的 API Key
ENV_FILE="$SCRIPT_DIR/../.env"
if [[ -f "$ENV_FILE" ]]; then
while IFS='=' read -r key val; do
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
# 加载 .env 中的 API Key
ENV_FILE="$SCRIPT_DIR/../.env"
if [[ -f "$ENV_FILE" ]]; then
while IFS='=' read -r key val; do
[[ "$key" =~ ^#.*$ || -z "$key" ]] && continue
Automatically reading a local .env file can expose credentials and other secrets to this tool's runtime without explicit user intent, especially because it loads from both the skill root and script directory. In a skill/plugin context, broad secret ingestion is risky because it increases the chance that unrelated credentials become accessible to code paths that also perform outbound network operations.
def _load_dotenv():
"""自动加载脚本同目录或 SKILL 根目录下的 .env 文件"""
script_dir = Path(__file__).resolve().parent
skill_dir = script_dir.parent
for env_path in [skill_dir / ".env", script_dir / ".env"]:
The code checks for and consumes .env content from local directories, which is credential collection behavior broader than necessary for the advertised features. While not overtly malicious, it raises the blast radius of any future bug or logging issue because more secrets are placed into process environment state.
"""自动加载脚本同目录或 SKILL 根目录下的 .env 文件"""
script_dir = Path(__file__).resolve().parent
skill_dir = script_dir.parent
for env_path in [skill_dir / ".env", script_dir / ".env"]:
if env_path.exists():
with open(env_path, encoding="utf-8") as f:
for line in f:
The README promotes web search, web page reading, and repository/file retrieval features without clearly warning that user-entered queries, URLs, repository identifiers, and requested paths are transmitted to external Z.AI/Zhipu services. This can lead users to unknowingly send sensitive internal URLs, private repository names, or confidential investigation terms to a third party.
The README recommends executing an unpinned npm package directly with npx -y @z_ai/mcp-server, which fetches and runs the latest published code from the registry at execution time. If the package is compromised, hijacked, or changed unexpectedly, users may run arbitrary code on their local machine without review.
The skill advertises shell, network, and environment-dependent behavior but does not declare an explicit permission or allowed-tools scope. That increases the chance an agent can invoke the skill with broader capabilities than the user expects, including network access and use of API keys from the environment.
The skill maps broad, ordinary phrases like '搜一下/查一下/找一下' to remote tool invocations without clear scope boundaries or sensitivity checks. In an agent setting, this can cause over-eager transmission of user queries, URLs, repo names, or local media to third-party services when the user may only be asking generally, increasing privacy and data-exfiltration risk.
The documentation gives contradictory statements about whether file parsing uses paid account balance or free Coding Plan quota. Billing and execution-path ambiguity is security-relevant because users or agents may unintentionally route data to a paid or different backend, causing unexpected charges and possibly different data-handling semantics.
The vision feature accepts remote URLs and local files for analysis but does not present a clear privacy warning about sending image or video content to a third-party API. Users may unknowingly submit sensitive screenshots, documents, faces, or internal recordings to an external provider, creating confidentiality and compliance risk.
The script transmits a local file and an API credential to a remote third-party service, but it provides no explicit warning, confirmation prompt, or data-handling notice at the point of use. In a file-parsing skill, this behavior is functionally expected, yet it still creates a real confidentiality and privacy risk because users may upload sensitive documents without realizing they are leaving the local environment.
The script forwards a local image path or remote URL directly to an external Python tool that invokes a vision API, but it provides no explicit warning, consent prompt, or indication that the image content may leave the local environment. This creates a real privacy and data-handling risk because users may unknowingly submit sensitive local images or internal URLs to a third-party service.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# 旧版 bigmodel API 网页读取
_reader_legacy() {
local url="$1"
curl -s --request POST \
--url "https://open.bigmodel.cn/api/paas/v4/reader" \
--header "Authorization: Bearer $API_KEY" \
--header 'Content-Type: application/json' \
This code posts the user-provided URL to an external API and includes the bearer API key in the request, but there is no runtime disclosure, confirmation, or user-facing warning about sending data off-host. The nearby comments are implementation-oriented and not sufficient as a user disclosure for a safety-relevant network operation.
The MCP initialization and subsequent tool calls contact a remote endpoint using the bearer API key and later submit the requested URL for remote processing. Although the script has internal comments and usage text, it does not clearly warn the user that invoking the script transmits data to external services.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
fi
# Step 2: Notify initialized
curl -s --request POST \
--url "$mcp_url" \
--header "Authorization: Bearer $API_KEY" \
--header "Content-Type: application/json" \
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
fi
# Step 2: Notify initialized
curl -s --request POST \
--url "$mcp_url" \
--header "Authorization: Bearer $API_KEY" \
--header "Content-Type: application/json" \
Comments and user-visible usage/error text are written exclusively in Chinese, including setup instructions and runtime messages. This can violate language/locale policy where skills should not force a specific language without user opt-in or clear justification.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# 旧版 bigmodel API 搜索
_search_legacy() {
local query="$1" count="$2"
curl -s --request POST \
--url "https://open.bigmodel.cn/api/paas/v4/web_search" \
--header "Authorization: Bearer $API_KEY" \
--header 'Content-Type: application/json' \
This shell script sends the user-provided search query to remote services via curl in both API modes, which is a network operation that transmits user data off-system. While the code contains developer comments, it lacks a user-facing disclosure at the point of execution about sending the query to third-party endpoints.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"clientInfo": {"name": "openclaw-zhipu-tools", "version": "1.1.0"},
},
}
resp = requests.post(url, headers=headers, json=body, timeout=30)
resp.raise_for_status()
session_id = resp.headers.get("mcp-session-id", "")
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"Accept": "application/json",
"Mcp-Session-Id": session_id,
}
requests.post(
url,
headers=notify_headers,
json={"jsonrpc": "2.0", "method": "notifications/initialized"},
No suspicious patterns detected.