Back to skill

Security audit

橙子通API自动化

Security checks for vulnerabilities and agentic risk

Overview

This skill is an inventory automation guide, but it exposes session/signing details and enables business-record changes across Orange Office and DingTalk without clear safeguards.

Review before installing. Use this only in a trusted internal context, rotate or remove exposed signing/configuration values if it was distributed broadly, and require explicit human approval before any stock-out update/delete or DingTalk write. Prefer loading session cookies, table IDs, and personnel mappings from protected runtime configuration rather than publishing them in the skill.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:15
Finding

Hard-Coded API Signing Material and Weak Request-Signing Construction

Content
View full analysis
str: return hashlib.md5((SALT + data).encode()).digest().hex() ``` The same hard-coded value is documented as the API signing salt: ```text Signing Salt: 68756c61 ``` ### Technical Analysis The Skill distributes the fixed value used to produce API request signatures and documents the complete signing algorithm. Anyone with access to the Skill can consequently generate the expected `sign` header for an arbitrary JSON request body. The construction `MD5(salt || message)` is not a modern message-authentication mechanism. The fixed salt is shared across installations, has no confidentiality after distribution, and provides no demonstrated key separation, timestamp validation, nonce, or replay protection. The documented session cookie remains an additional authentication requirement, so knowledge of the signing value alone does not establish an authenticated session. Nevertheless, disclosure of the signing construction removes one security layer and makes a stolen or otherwise exposed session substantially easier to use for forged inventory requests. ### Attack Path 1. Obtain a copy of the publicly distributed or otherwise accessible Skill. 2. Extract the hard-coded value `68756c61` and the documented MD5 signing procedure. 3. Obtain a valid `ASP.NET_SessionId` through a separate compromise, such as session leakage, endpoint exposure, or theft from an authorized user. 4. Construct an arbitrary inventory API request body, including a stock-out creation, update, or deletion request. 5. Serialize the body using the documented compact JSON format. 6. Calculate the expected signature using `MD5("68756c61" || serialized_body)`. 7. Submit the forged request with the stolen session cookie and calculated `sign` header. 8. If the serv ...[truncated 873 chars]
Remediation
View remediation

other

Note
Location
SKILL.md:96
Finding

Exposure of Personnel and Internal Inventory Resource Mappings

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation embeds static signing material and session-cookie usage guidance, which are effectively sensitive authentication components. Even if the salt is not a full secret by itself, publishing reusable signing and session-handling details lowers the barrier to forging requests or reusing authenticated context against the inventory system.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documents destructive inventory operations such as update and delete for stock-out orders without any confirmation, authorization, or rollback guidance. In an automation context, this can lead to accidental or unauthorized alteration of inventory records with direct business and accounting consequences.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill’s declared purpose is Orange Office inventory API automation, but the documentation also includes DingTalk table read/write procedures, identifiers, and business-specific field mappings. This expands the effective capability boundary from inventory operations into a second system that can modify operational records, increasing the risk of unauthorized cross-system data access or tampering.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill gives prescriptive instructions for writing inventory snapshots into DingTalk tables, including field mappings and backfill logic, but provides no warning about modifying business data or preventing duplicate/incorrect writes. Because these writes affect operational records in another system, mistakes or abuse could corrupt reporting and downstream decisions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.