Back to skill

Security audit

可以通过NPL自然语言和轻云API接口进行对话,调试轻云API不再那么困惑

Security checks for vulnerabilities and agentic risk

Overview

The skill is a Qingyun API guide, but it needs review because it handles secrets and can delete or modify business records without strong safeguards.

Review before installing. Use only a trusted, verified package source, avoid pasting real secrets into chat or shell history, prefer secure environment variables or a secret manager, redact tokens from output, and require an explicit confirmation with exact record IDs before any delete or update operation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:17
Finding

Unauthenticated Skill Download from an Unspecified Remote Source

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:155
Finding

Access Tokens Exposed Through URL Query Parameters

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (36)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: lightcloud-api
description: Integrate with Qingyun/Lightcloud (轻云) API to manage form documents - fetch access tokens, retrieve, create, update, and delete form data. Use this skill when users request to interact with Qingyun/Lightcloud API, get access tokens, retrieve/create/update/delete form data, or work with Qingyun documents. Triggers include mentions of "轻云", "yunzhijia", "qingyun", "lightcloud", or requests to fetch/create/update/delete form data, access tokens, or document operations from Qingyun platform.
---

# Lightcloud API Integration

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

Verify Installation

After installation, test with natural language:

text
"获取轻云的access token"
"从轻云获取表单数据"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

Verify Installation

After installation, test with natural language:

text
"获取轻云的access token"
"从轻云获取表单数据"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 319)May include surrounding context.

Verify Installation

After installation, test with natural language:

text
"获取轻云的access token"
"从轻云获取表单数据"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 323)May include surrounding context.

Verify Installation

After installation, test with natural language:

text
"获取轻云的access token"
"从轻云获取表单数据"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 329)May include surrounding context.

Verify Installation

After installation, test with natural language:

text
"获取轻云的access token"
"从轻云获取表单数据"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 447)May include surrounding context.

Verify Installation

After installation, test with natural language:

text
"获取轻云的access token"
"从轻云获取表单数据"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

To remove the skill:

bash
rm ~/.claude/skills/lightcloud-api.skill
# Or on Windows:
del %USERPROFILE%\.claude\skills\lightcloud-api.skill

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 428)May include surrounding context.

To remove the skill:

bash
rm ~/.claude/skills/lightcloud-api.skill
# Or on Windows:
del %USERPROFILE%\.claude\skills\lightcloud-api.skill

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

The access-token acquisition workflow explicitly asks for appId, eid, and secret and shows users how to transmit them, but it does not warn about the sensitivity of these values or the exposure risks of putting them directly into commands. This can lead to credential leakage through chat transcripts, shell history, logs, or local process inspection.

Content

Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

md
## Quick Start

### 1. Get Access Token

#### Bash/Mac/Linux (curl)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 182)May include surrounding context.

text

**Required parameters:**
- `accessToken`: Access token from step 1 (in URL query parameter)
- `eid`: Workspace eid (工作圈eid)
- `formCodeId`: Form code ID (表单codeId)
- `formInstIds`: Array of form instance IDs (单据id数组)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 222)May include surrounding context.

text

**Required parameters:**
- `accessToken`: Access token from step 1 (in URL query parameter)
- `eid`: Workspace eid (工作圈eid)
- `formCodeId`: Form code ID (表单codeId)
- `formInstIds`: Array of form instance IDs (单据id数组)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 300)May include surrounding context.

text

**Required parameters:**
- `accessToken`: Access token from step 1 (in URL query parameter)
- `eid`: Workspace eid (工作圈eid)
- `formCodeId`: Form code ID (表单codeId)
- `formInstIds`: Array of form instance IDs (单据id数组)

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The workflow explicitly says to collect credentials from the user and then obtain and parse an access token, but it provides no constraints on how those secrets should be requested, stored, or displayed. In an agent setting, instructing collection of secrets without guardrails significantly increases risk of credential exposure and misuse.

Content

Scanner excerpt · SKILL.md (reported line 345)May include surrounding context.

md
1. **Identify platform**: Detect if user is on Bash/Mac/Linux or Windows PowerShell
2. **Collect credentials**: Ask user for appId, eid, and secret if not provided
3. **Generate timestamp**: Create current timestamp in milliseconds
4. **Get access token**: Execute appropriate command for platform
5. **Parse token**: Extract accessToken from response
6. **Fetch form data**: Use token to retrieve documents
7. **Present results**: Display data in user-friendly format

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 355)May include surrounding context.

md
- **No Python required**: Uses native curl (Bash/Mac/Linux) or Invoke-RestMethod (PowerShell)
- **Cross-platform**: Works on Windows, Mac, and Linux
- **Timestamp validity**: Must be within 3 minutes or request will be rejected
- **Token expiration**: Access tokens expire based on `expireIn` field (typically 7200 seconds)
- **Batch retrieval**: formInstIds accepts array for multiple forms
- **Error handling**: Check `success` field in response

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

The one-line token command encourages users to inline appId, eid, and secret directly into a shell command. This is dangerous because such secrets may be retained in shell history, visible to local monitoring tools, copied into support logs, or accidentally shared.

Content

Scanner excerpt · SKILL.md (reported line 363)May include surrounding context.

For quick execution, use these complete one-liners:

Get Access Token (Bash)

bash
curl -X POST "https://www.yunzhijia.com/gateway/oauth2/token/getAccessToken" -H "Content-Type: application/json" -d '{"appId":"YOUR_APP_ID","eid":"YOUR_EID","secret":"YOUR_SECRET","timestamp":'$(($(date +%s) * 1000))',"scope":"team"}'

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

The PowerShell one-liner similarly embeds sensitive credentials directly in command text, creating exposure through console history, transcripts, copy/paste artifacts, and potential logging. The concise format makes unsafe execution especially likely because users may run it verbatim after substitution.

Content

Scanner excerpt · SKILL.md (reported line 368)May include surrounding context.

curl -X POST "https://www.yunzhijia.com/gateway/oauth2/token/getAccessToken" -H "Content-Type: application/json" -d '{"appId":"YOUR_APP_ID","eid":"YOUR_EID","secret":"YOUR_SECRET","timestamp":'$(($(date +%s) * 1000))',"scope":"team"}'

text

### Get Access Token (PowerShell)
```powershell
$body = @{appId="YOUR_APP_ID";eid="YOUR_EID";secret="YOUR_SECRET";timestamp=[int64](Get-Date -UFormat %s)*1000;scope="team"} | ConvertTo-Json; Invoke-RestMethod -Uri "https://www.yunzhijia.com/gateway/oauth2/token/getAccessToken" -Method POST -Headers @{"Content-Type"="application/json"} -Body $body

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/api_reference.md (reported line 6)May include surrounding context.

md
## API概览

轻云开放API提供四个主要接口:
1. 获取访问令牌(Access Token)
2. 批量获取单据数据
3. 批量删除单据数据
4. 新增或更新多条无流程单据

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/api_reference.md (reported line 11)May include surrounding context.

md
## API概览

轻云开放API提供四个主要接口:
1. 获取访问令牌(Access Token)
2. 批量获取单据数据
3. 批量删除单据数据
4. 新增或更新多条无流程单据

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/api_reference.md (reported line 138)May include surrounding context.

md
## API概览

轻云开放API提供四个主要接口:
1. 获取访问令牌(Access Token)
2. 批量获取单据数据
3. 批量删除单据数据
4. 新增或更新多条无流程单据

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger scope is broad enough to activate on generic requests related to forms, documents, or tokens, which can cause the skill to surface credential-handling and destructive API instructions in contexts the user did not specifically intend. In an agent environment, overbroad routing increases the chance of accidental secret solicitation or unintended operational guidance.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

Method 1: Command Line Installation (Recommended)

Using curl

bash
# Download and install the skill
curl -L -o lightcloud-api.skill https://your-domain.com/skills/lightcloud-api.skill

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs users to provide appId, eid, secret, and access tokens and to place sensitive values directly into commands, but it does not include any guidance on secure handling, redaction, shell history exposure, or avoiding credential leakage. This is dangerous because secrets may be copied into chats, terminals, logs, process lists, or screenshots.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 155)May include surrounding context.

Bash/Mac/Linux (curl)

bash
curl -X POST "https://www.yunzhijia.com/gateway/lightcloud/data/list?accessToken=YOUR_ACCESS_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "eid": "YOUR_EID",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill provides ready-to-run deletion commands for batch document removal without an explicit warning that the action is destructive and may be irreversible. In agent-assisted workflows, this raises the risk of users executing data-deleting commands without sufficient confirmation or understanding.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.