T08 · Insecure Dependencies
- Location
SKILL.md:17- Finding
Unauthenticated Skill Download from an Unspecified Remote Source
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a Qingyun API guide, but it needs review because it handles secrets and can delete or modify business records without strong safeguards.
Review before installing. Use only a trusted, verified package source, avoid pasting real secrets into chat or shell history, prefer secure environment variables or a secret manager, redact tokens from output, and require an explicit confirmation with exact record IDs before any delete or update operation.
SKILL.md:17Unauthenticated Skill Download from an Unspecified Remote Source
SKILL.md:155Access Tokens Exposed Through URL Query Parameters
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
---
name: lightcloud-api
description: Integrate with Qingyun/Lightcloud (轻云) API to manage form documents - fetch access tokens, retrieve, create, update, and delete form data. Use this skill when users request to interact with Qingyun/Lightcloud API, get access tokens, retrieve/create/update/delete form data, or work with Qingyun documents. Triggers include mentions of "轻云", "yunzhijia", "qingyun", "lightcloud", or requests to fetch/create/update/delete form data, access tokens, or document operations from Qingyun platform.
---
# Lightcloud API Integration
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
After installation, test with natural language:
"获取轻云的access token"
"从轻云获取表单数据"
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
After installation, test with natural language:
"获取轻云的access token"
"从轻云获取表单数据"
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
After installation, test with natural language:
"获取轻云的access token"
"从轻云获取表单数据"
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
After installation, test with natural language:
"获取轻云的access token"
"从轻云获取表单数据"
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
After installation, test with natural language:
"获取轻云的access token"
"从轻云获取表单数据"
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
After installation, test with natural language:
"获取轻云的access token"
"从轻云获取表单数据"
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
To remove the skill:
rm ~/.claude/skills/lightcloud-api.skill
# Or on Windows:
del %USERPROFILE%\.claude\skills\lightcloud-api.skill
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
To remove the skill:
rm ~/.claude/skills/lightcloud-api.skill
# Or on Windows:
del %USERPROFILE%\.claude\skills\lightcloud-api.skill
The access-token acquisition workflow explicitly asks for appId, eid, and secret and shows users how to transmit them, but it does not warn about the sensitivity of these values or the exposure risks of putting them directly into commands. This can lead to credential leakage through chat transcripts, shell history, logs, or local process inspection.
## Quick Start
### 1. Get Access Token
#### Bash/Mac/Linux (curl)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
**Required parameters:**
- `accessToken`: Access token from step 1 (in URL query parameter)
- `eid`: Workspace eid (工作圈eid)
- `formCodeId`: Form code ID (表单codeId)
- `formInstIds`: Array of form instance IDs (单据id数组)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
**Required parameters:**
- `accessToken`: Access token from step 1 (in URL query parameter)
- `eid`: Workspace eid (工作圈eid)
- `formCodeId`: Form code ID (表单codeId)
- `formInstIds`: Array of form instance IDs (单据id数组)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
**Required parameters:**
- `accessToken`: Access token from step 1 (in URL query parameter)
- `eid`: Workspace eid (工作圈eid)
- `formCodeId`: Form code ID (表单codeId)
- `formInstIds`: Array of form instance IDs (单据id数组)
The workflow explicitly says to collect credentials from the user and then obtain and parse an access token, but it provides no constraints on how those secrets should be requested, stored, or displayed. In an agent setting, instructing collection of secrets without guardrails significantly increases risk of credential exposure and misuse.
1. **Identify platform**: Detect if user is on Bash/Mac/Linux or Windows PowerShell
2. **Collect credentials**: Ask user for appId, eid, and secret if not provided
3. **Generate timestamp**: Create current timestamp in milliseconds
4. **Get access token**: Execute appropriate command for platform
5. **Parse token**: Extract accessToken from response
6. **Fetch form data**: Use token to retrieve documents
7. **Present results**: Display data in user-friendly format
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
- **No Python required**: Uses native curl (Bash/Mac/Linux) or Invoke-RestMethod (PowerShell)
- **Cross-platform**: Works on Windows, Mac, and Linux
- **Timestamp validity**: Must be within 3 minutes or request will be rejected
- **Token expiration**: Access tokens expire based on `expireIn` field (typically 7200 seconds)
- **Batch retrieval**: formInstIds accepts array for multiple forms
- **Error handling**: Check `success` field in response
The one-line token command encourages users to inline appId, eid, and secret directly into a shell command. This is dangerous because such secrets may be retained in shell history, visible to local monitoring tools, copied into support logs, or accidentally shared.
For quick execution, use these complete one-liners:
curl -X POST "https://www.yunzhijia.com/gateway/oauth2/token/getAccessToken" -H "Content-Type: application/json" -d '{"appId":"YOUR_APP_ID","eid":"YOUR_EID","secret":"YOUR_SECRET","timestamp":'$(($(date +%s) * 1000))',"scope":"team"}'
The PowerShell one-liner similarly embeds sensitive credentials directly in command text, creating exposure through console history, transcripts, copy/paste artifacts, and potential logging. The concise format makes unsafe execution especially likely because users may run it verbatim after substitution.
curl -X POST "https://www.yunzhijia.com/gateway/oauth2/token/getAccessToken" -H "Content-Type: application/json" -d '{"appId":"YOUR_APP_ID","eid":"YOUR_EID","secret":"YOUR_SECRET","timestamp":'$(($(date +%s) * 1000))',"scope":"team"}'
### Get Access Token (PowerShell)
```powershell
$body = @{appId="YOUR_APP_ID";eid="YOUR_EID";secret="YOUR_SECRET";timestamp=[int64](Get-Date -UFormat %s)*1000;scope="team"} | ConvertTo-Json; Invoke-RestMethod -Uri "https://www.yunzhijia.com/gateway/oauth2/token/getAccessToken" -Method POST -Headers @{"Content-Type"="application/json"} -Body $body
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
## API概览
轻云开放API提供四个主要接口:
1. 获取访问令牌(Access Token)
2. 批量获取单据数据
3. 批量删除单据数据
4. 新增或更新多条无流程单据
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
## API概览
轻云开放API提供四个主要接口:
1. 获取访问令牌(Access Token)
2. 批量获取单据数据
3. 批量删除单据数据
4. 新增或更新多条无流程单据
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
## API概览
轻云开放API提供四个主要接口:
1. 获取访问令牌(Access Token)
2. 批量获取单据数据
3. 批量删除单据数据
4. 新增或更新多条无流程单据
The trigger scope is broad enough to activate on generic requests related to forms, documents, or tokens, which can cause the skill to surface credential-handling and destructive API instructions in contexts the user did not specifically intend. In an agent environment, overbroad routing increases the chance of accidental secret solicitation or unintended operational guidance.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Download and install the skill
curl -L -o lightcloud-api.skill https://your-domain.com/skills/lightcloud-api.skill
The skill instructs users to provide appId, eid, secret, and access tokens and to place sensitive values directly into commands, but it does not include any guidance on secure handling, redaction, shell history exposure, or avoiding credential leakage. This is dangerous because secrets may be copied into chats, terminals, logs, process lists, or screenshots.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl -X POST "https://www.yunzhijia.com/gateway/lightcloud/data/list?accessToken=YOUR_ACCESS_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"eid": "YOUR_EID",
The skill provides ready-to-run deletion commands for batch document removal without an explicit warning that the action is destructive and may be irreversible. In agent-assisted workflows, this raises the risk of users executing data-deleting commands without sufficient confirmation or understanding.
No suspicious patterns detected.