Back to skill

Security audit

Mysteel_ReportWrite

Security checks for vulnerabilities and agentic risk

Overview

This skill is coherent for Mysteel-backed report generation, but it persists an API key in a local skill file and can send report prompts to Mysteel without clear user consent boundaries.

Review before installing. Use this skill only if you are comfortable sending report requests to Mysteel and storing a Mysteel API key locally. Prefer modifying it to use an environment variable or secret manager, require confirmation before each external call, and avoid including confidential client or trading information in prompts.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/call_mysteel_api.py:40
Finding

Plaintext API Credential Storage in the Project Directory

Content
View full analysis

Vulnerability Details

File Location: scripts/call_mysteel_api.py:40-61; related instructions in SKILL.md:23-25, 58-59, 177
Vulnerability Type: Plaintext sensitive-data storage
Risk Level: Medium

Vulnerable Code

python
# API密钥文件路径
api_key_file = os.path.join(skill_root, 'references', 'api_key.md')

# 检查文件是否存在
if not os.path.exists(api_key_file):
    return ''

try:
    with open(api_key_file, 'r', encoding='utf-8') as f:
        lines = [line.strip() for line in f.readlines() if line.strip()]

    # 文件至少需要2行(注释行+密钥行)
    if len(lines) < 2:
        return ''

    # 第二行为api_key
    api_key = lines[1]

    # 检查是否为占位符
    if api_key == 'YOUR_API_KEY_HERE' or not api_key:
        return ''

    return api_key

The associated Skill instructions explicitly require the credential to be written to this file:

text
配置方式:在 `references/api_key.md` 文件中配置(将 `YOUR_API_KEY_HERE` 替换为实际的API密钥)
text
用户输入密钥 → 智能体更新`references/api_key.md`文件

Technical Analysis

The Skill requires a live Mysteel API credential to be persisted as plaintext in references/api_key.md, inside the project directory. The implementation reads that credential directly without checking file ownership or permissions, and the project does not provide controls preventing the credential file from being committed, archived, copied, or exposed to other local processes.

Sending the credential in the token header to the declared Mysteel HTTPS endpoint is necessary for authenticated API access and is not itself an unauthorized transmission. The security weakness is the unnecessary persistence of that credential in a source-tree file. Environment variables, a credential manager, or an external permission-restricted configuration location would provide the required authentication capability with less exposure.

Exploitation requires an attacker or process to obtain read access to the project dir ...[truncated 1284 chars]

Remediation
View remediation

Remediation Suggestions

  1. Read the API key from an environment variable or operating-system secret manager rather than a file in the Skill directory.
  2. Remove the instruction requiring the Agent to write user-provided credentials into references/api_key.md.
  3. If file-based configuration must remain available, place the secret outside the repository and accept its path through a secure configuration mechanism.
  4. Enforce owner-only permissions before reading a credential file and reject files accessible by other users where the platform supports permission checks.
  5. Add all local secret-file patterns to .gitignore and provide only a placeholder template such as api_key.md.example.
  6. Avoid printing, serializing, or including the credential in diagnostic output or exceptions.
  7. Document credential revocation and rotation procedures for users who may already have stored or committed a live key.
  8. Prefer short-lived, narrowly scoped API tokens so disclosure grants only the minimum permissions and duration necessary for report generation.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared purpose understates important behavior: the skill reads a local API key file, sends user report requests to an external service, and actually depends on an outline-generation API rather than fully local report generation. This mismatch can mislead operators and users about data flow and trust boundaries, causing unintentional disclosure of sensitive prompts or credentials usage under incomplete oversight.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill performs sensitive capabilities—reading a local credential file and making external network requests—but declares no explicit tool scope or permissions. This weakens reviewability and consent boundaries, increasing the chance the agent can access files or exfiltrate user/request data without a clear declaration to users or policy enforcement.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger phrases are broad and overlap with ordinary analytical requests such as market analysis or price trends, which can cause the skill to activate in cases where the user did not intend use of an external API. In this context, ambiguous invocation is more dangerous because activation leads to credential use, local file access, and prompt transmission to a third party.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill does not clearly warn users that their prompts and report requests will be transmitted to an external API. This creates a privacy and compliance risk, especially if users include proprietary market views, client information, or other sensitive business context in the report request.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The code comment and stdout/stderr wrapping explicitly optimize for Chinese output, and all user-facing messages, CLI help text, and docstrings are hardcoded in Chinese. For a general-purpose skill file, this imposes a specific language/locale without user opt-in, which matches the natural-language policy violation criteria.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The script sends the user-supplied query and an API token to an external third-party service. In a skill context, this creates a real data exfiltration boundary: sensitive user prompts, proprietary report requests, or internal business context could be transmitted off-platform without validation, minimization, or explicit user consent.

Content

Scanner excerpt · scripts/call_mysteel_api.py (reported line 137)May include surrounding context.

python
try:
        # 2. 发送请求(超时2分钟)
        response = requests.post(
            url,
            headers=headers,
            json=payload,

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The heading is written entirely in Chinese, and there is no indication that users may choose another language or that the file is intentionally limited to a Chinese-specific audience. This creates a natural-language locale policy concern under the rule for language or locale policy violations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.