Back to skill

Security audit

Mysteel_InfoSearch

Security checks for vulnerabilities and agentic risk

Overview

This skill performs the advertised Mysteel industry-news search, but it tells users to persist an API key in a plaintext markdown file inside the skill directory without adequate safety guidance.

Review before installing if you will use a real Mysteel API token. Prefer storing the token in an environment variable or a protected secret store instead of references/api_key.md; if you do use the file, keep it out of source control and shared workspaces, restrict local file permissions, and be aware that your query text and token are sent to Mysteel's API.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:22
Finding

Plaintext API Key Storage in the Project Directory

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:22-24; scripts/search.py:25, 28-40, 144-149
Vulnerability Type: Plaintext sensitive credential storage
Risk Level: Medium

Vulnerable Code and Instructions

SKILL.md:22-24 instructs the Agent to use a file inside the project for credential storage:

markdown
- 检查`references/api_key.md`文件是否存在
- 如果存在,读取其中的api_key
- 如果文件不存在,提示用户输入API密钥,并将用户输入的密钥保存到`references/api_key.md`文件中

In English, these instructions require checking references/api_key.md, reading its API key when present, and saving a user-provided API key there when absent.

scripts/search.py:25, 28-40 reads that plaintext credential:

python
API_KEY_FILE = SKILL_DIR / "references" / "api_key.md"


def load_api_key() -> str | None:
    """
    Load API key from file.
    Returns the API key if found and valid, None otherwise.
    """
    try:
        if API_KEY_FILE.exists():
            content = API_KEY_FILE.read_text(encoding="utf-8").strip()
            lines = content.splitlines()
            if len(lines) >= 1 and lines[0] and not lines[0].startswith("YOUR_API_KEY"):
                return lines[0].strip()
    except Exception:
        # File read error, return None
        pass
    return None

scripts/search.py:144-149 makes that project-local file the required credential source:

python
    # Load API key from file
    api_key = load_api_key()
    if not api_key:
        print("Error: API key is required. Please save it in references/api_key.md", file=sys.stderr)
        sys.exit(1)

Technical Analysis

The documented setup workflow directs an Agent to persist a reusable API credential in plaintext under the Skill's source tree. The loader reads the first line of that file without validating or enforcing restrictive file permissions. The audited project contains no .gitignore rule protecting this path and no credential-store integration.

The bundled references/api_key.md was empty during the a ...[truncated 2258 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the instruction to save credentials under references/api_key.md.
  2. Read the token from an environment variable, such as MYSTEEL_API_KEY, or use an operating-system credential manager.
  3. If file-based storage is unavoidable:
    • Store the credential outside the project and source-control tree.
    • Create the file with owner-only permissions, such as mode 0600 on POSIX systems.
    • Reject files whose ownership or permissions allow access by other users.
    • Add the credential path to .gitignore and relevant packaging exclusions.
    • Include only a non-secret example file, never a populated credential file.
  4. Avoid silently suppressing credential-file read errors. Report permission and format failures without printing the secret.
  5. Document token rotation and revocation procedures in case the project has already been shared or committed.
  6. Clearly disclose that both the token and user query are sent to the documented Mysteel service.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill documentation indicates file-read and network-capable behavior, but it does not declare any explicit tool scope or permissions boundaries. This weakens least-privilege controls and makes it harder to audit or constrain what the skill may access at runtime, increasing the risk of unintended file access or network use if the implementation is broader than the stated purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Saving a user-provided API key into references/api_key.md stores a sensitive secret in a general-purpose markdown file that may be easily read, copied, committed, or indexed. For a search-only skill, this is not clearly justified and materially increases the chance of credential leakage or reuse by other components.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The instructions tell the user to enter an API key and save it locally without any warning about plaintext storage, access by other tools, accidental source control inclusion, or revocation procedures. This can mislead users into unsafe credential handling practices and make compromise more likely in shared or agent-accessible environments.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api_reference.md (reported line 74)May include surrounding context.

  1. 情感标签:利多/利空/中性判断
  2. 关联数据:相关价格数据链接

cURL Example

bash
curl --location 'https://mcp.mysteel.com/mcp/info/ai-search/search' \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code performs an HTTP POST to an external API using the user's query text and an authentication token, but the script provides no confirmation prompt or user-facing notice that the query content will be transmitted off-system. While the module docstring says it queries an API, the operational path itself has no visible disclosure at execution time, which fits the missing-warning criterion for network transmission of user or system data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill is presented as an information-search tool, but the documentation also instructs persistent storage of an API key in a local file. Persisting secrets expands the data-handling scope beyond simple search and creates a credential exposure risk if the workspace, logs, backups, or other tools can access that file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This markdown file documents sending a token/API key in request headers, but it does not include any warning to keep the credential secret or avoid sharing it in logs, screenshots, or committed examples. For markdown files, SQP-2 applies when descriptions omit warnings about behaviors that could affect privacy or system integrity, and credential handling is a relevant safety concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
71% confidence
Finding

The file specifies a fixed Chinese parameter value (MyClaw模式) and uses Chinese-only example queries and category labels, but does not explain that the API is intentionally Chinese-language or region-specific. Under SQP-3, forcing a specific language or locale without opt-in or clear justification can be a natural-language policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.