T09 · Insecure Skill Coding Practices
- Location
invoice-verify-hsy.py:14- Finding
Unrestricted API Endpoint Allows Credential and Invoice Data Exfiltration
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This invoice-checking skill appears legitimate, but it can send invoice and credential data to any API URL configured in the environment, so it needs careful review before use.
Install only if you trust HuiSuiYun and the publisher, and ensure HSY_API_URL is unset or fixed to the intended HTTPS HuiSuiYun host. Treat HSY_AK and HSY_SK as sensitive credentials, avoid running this in environments where untrusted users can change environment variables, and expect invoice numbers, dates, amounts, check codes, and possible tax identifiers to be sent to the remote service.
invoice-verify-hsy.py:14Unrestricted API Endpoint Allows Credential and Invoice Data Exfiltration
The destination URL is derived from the HSY_API_URL environment variable and then used for requests that include invoice contents and authentication headers, including the access token. If an attacker can influence the environment or deployment configuration, they can redirect traffic to an attacker-controlled endpoint and exfiltrate sensitive invoice data and tokens. In a skill context, this is more dangerous because the tool is explicitly designed to send sensitive tax/invoice information to a remote service.
check_url = f"{api_url}/api/v2/agent/cdk/invoice/check"
try:
response = requests.post(check_url, json=data, headers=headers)
return response.json()
except Exception as e:
return {"error": str(e)}
The skill declares runtime requirements indicating access to environment variables and outbound networking, but it does not declare an explicit tool scope such as permissions or allowed-tools. This creates a transparency and least-privilege problem: an agent or user may invoke a skill that can access secrets and send data externally without clear policy constraints.
The documentation instructs sending invoice details and taxpayer-identifying information to a third-party API, but it does not clearly warn users that sensitive business and tax data will leave the local environment. This can lead to unintended disclosure of regulated or confidential data, especially because the sample response includes seller and purchaser names, tax numbers, and invoice line items.
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
invoiceList 数组中每个对象的字段:
| 字段名 | 类型 | 必填 | 说明 |
|-----------------|------------|------|-------------------------------------------------------------------------------------------------------|
| invoiceNo | String | 是 | 发票号码,如:00517731 |
| drewDate | String | 是 | 开票日期,格式:YYYY-MM-DD,如:2021-06-22 |
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
| 字段名 | 类型 | 必填 | 说明 |
|-----------------|------------|------|-------------------------------------------------------------------------------------------------------|
| invoiceNo | String | 是 | 发票号码,如:00517731 |
| drewDate | String | 是 | 开票日期,格式:YYYY-MM-DD,如:2021-06-22 |
| invoiceCode | String | 否 | 发票代码,如:3300201130(全电发票无需传入) |
| invoiceType | String | 否 | 发票类型:01-增值税专用发票,08-增值税专用发票(电子),04-增值税普通发票,10-增值税普通发票(电子),09-数电发票(增值税专用发票),90-数电发票(普通发票)等 |
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
| amount | BigDecimal | 否 | 金额:专票(01、08、85)传入不含税金额,数电发票(09、90、51、61)传入价税合计 |
| checkCode | String | 否 | 校验码后六位,普票(04、10、11、14、86)必传 |
| originFileFlag | Integer | 否 | 是否获取版式文件:1-是,0-否 |
| exten1-10 | String | 否 | 扩展字段1-10 |
### 返回结果示例(verify)
Multiple docstrings and user-visible messages are written only in Chinese, including configuration and error guidance. This can enforce a specific language experience without user opt-in or any alternative locale handling.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
}
try:
response = requests.post(token_url, json=payload)
result = response.json()
if result.get("code") == "200":
return result["data"]
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
check_url = f"{api_url}/api/v2/agent/cdk/invoice/check"
try:
response = requests.post(check_url, json=data, headers=headers)
return response.json()
except Exception as e:
return {"error": str(e)}
The code sends the provided invoice payload to a remote API via an HTTP POST request, which can transmit user or business data off-host. Although there are internal comments, there is no confirmation prompt, user-facing log/print, or docstring warning that invoice data will be sent to an external service.
Nearly all user-facing instructions and descriptions in this skill are presented only in Chinese, which effectively forces a specific language for operation and comprehension. The file does not offer an alternative language, user opt-in, or a documented justification that the skill is intended only for a Chinese-language or region-specific audience.
The skill accesses HSY_AK and HSY_SK from environment variables to authenticate with the external service. While missing configuration is reported to the user, there is no warning or documentation in this file that the skill consumes sensitive credentials from the environment.
No suspicious patterns detected.