Back to skill

Security audit

China company search fengniao

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its company-search purpose, but it needs user review because it sends business/person lookup data and API credentials to Riskbird, including private API keys in URL parameters.

Install only if you are comfortable sending company names, person names, entids, and due-diligence queries to Riskbird. Prefer the built-in shared key for low-sensitivity testing; if you configure a private FN_API_KEY, understand that this skill sends it in URL parameters and avoid printing it in shared terminals or logs. Review generated due-diligence reports before relying on or redistributing personal or corporate risk data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Warning
Location
references/due_diligence_report.md:19
Finding

Mandatory Promotional Content Injected into Agent Reports

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/client.mjs:162
Finding

Private API Keys Transmitted in URL Query Parameters

Content
View full analysis
{ if (value != null) { url.searchParams.set(key, String(value)); } }); } else { options.headers["Content-Type"] = "application/json"; options.body = JSON.stringify(requestParams); } const res = await fetch(url.toString(), options); ``` ### Technical Analysis The implementation retrieves either the shared API key or a user-supplied `FN_API_KEY` and inserts it into the request URL as the `apikey` query parameter. TLS protects the URL while it is transmitted over the network, but it does not prevent the complete URL from being recorded at request endpoints or within local and intermediary infrastructure. Query strings are commonly retained by: - Reverse-proxy and web-server access logs. - API gateway logs. - Application performance monitoring systems. - Debugging and exception telemetry. - Network security products. - Request tracing and observability platforms. A user may configure a private paid API key under the documented assumption that the Skill will use it securely. Every API call then exposes that key to any component that records the request URL. ### Attack Path 1. A user stores a private credential in the `FN_API_KEY` environment variable. 2. `getApiKey()` returns the private key to `call()`. 3. `call()` inserts the key into `url.searchParams`. 4. `fetch(url.toString(), options)` sends a URL containing the complete credential. 5. The destination service, reverse proxy, API gateway, ...[truncated 954 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/env.mjs:1
Finding

Shared API Credential Hardcoded in the Distributed Package

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (20)

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
70% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · SETUP.md (reported line 62)May include surrounding context.

macOS / Linux

bash
printenv FN_API_KEY

Windows PowerShell

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The setup guide explicitly instructs users to print the API key to the terminal in order to verify configuration, but does not warn that this reveals the credential on screen and may persist in terminal scrollback, screen recordings, shared sessions, or operational logs. While this is framed as troubleshooting guidance rather than credential theft, it increases the chance of accidental secret exposure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill is configured with auto_invoke and very broad enterprise-query keywords/examples, which increases the chance it activates on loosely related prompts without a clear user request. In this context, unintended activation can send company or person names to an external due-diligence service, creating avoidable privacy leakage and surprising external lookups.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill documentation says it is 'out of the box' and uses a built-in shared API key, but it does not clearly warn users that their company/person queries are transmitted to an external third-party service. Because the built-in key is shared, users may also not realize their requests are being made under a communal credential, which raises privacy, auditability, and consent concerns.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The guidance instructs the agent to compile and present a detailed due diligence report including company identifiers, legal representative, shareholders, senior staff, enforcement history, and other risk data, but provides no guardrails on privacy, data minimization, accuracy caveats, or appropriate downstream use. In a due-diligence context this can facilitate profiling and redistribution of sensitive corporate and personal information, especially when the report is presented as authoritative without limitations or warnings.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Line L095 states that English search is invalid and users 'must pass Chinese', which imposes a language constraint in natural-language documentation. The file does not offer a user opt-in, alternative language handling, or a documented regional/compliance justification for this restriction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code appends the API key to the request URL and sends request parameters to a remote API via fetch, but there is no confirmation prompt, logging, print statement, or explanatory comment disclosing this network transmission to the user. Because these requests may include user-provided data and credentials, they fall under safety-relevant network operations lacking visible warning in this file.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file hardcodes a shared API credential and automatically falls back to it whenever a user key is not provided. Publishing embedded credentials in a distributable skill allows anyone with access to the package to extract and reuse the key, which can lead to unauthorized API consumption, quota exhaustion, billing abuse, and loss of control over the upstream account.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill silently uses an embedded API key without informing the user, which hides the fact that requests are being authenticated under a publisher-controlled shared credential. This reduces transparency, prevents informed consent about service usage and limits, and increases the risk of unnoticed abuse or service disruption when the shared key is revoked or exhausted.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The aliases in this range include broad, everyday business terms such as supplier-, contract-, boss-, and interview-related phrases that are not uniquely indicative of an intent to run a company-risk search skill. This can cause unintended invocation, leaking user intent into an external enterprise lookup workflow or triggering data retrieval the user did not explicitly request. In a due-diligence skill that may access sensitive corporate risk data, ambiguous triggers make accidental activation more concerning than in a low-impact utility skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The tool set defines very broad trigger keywords such as generic enterprise/company search terms that can match many ordinary user requests and cause unintended invocation of sensitive company-intelligence lookups. Because these tools return business identity, shareholder, executive, litigation, and penalty data, over-broad routing increases the chance of unnecessary data access and privacy-impacting enrichment beyond the user's explicit intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The description states "英文搜索无效,必须传中文名称" and the parameter description repeats that the query "必须是中文". This is a natural-language locale restriction with no user choice or opt-in, which can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

SQP-3 applies to all file types and covers language policy violations when a skill forces a specific language without user opt-in. This document presents all operational instructions exclusively in Chinese, with no indication of optional locale support or a documented region-specific justification in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The description states this is a China enterprise-query skill and line 129 requires enterprise names to always be output using the full registered Chinese company name, but there is no mention of offering users a language or locale choice. This imposes a locale-specific output convention even though the examples include English-language prompts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The instructions and required output template mandate Chinese-language report generation, but the file does not state that the skill is China-specific or provide any user opt-in for language/locale. Under the policy, forcing a specific language without choice or clear justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This markdown file presents all instructions and field definitions only in Chinese, with no user opt-in, alternative language, or justification that the skill is limited to a Chinese-language or China-specific audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The file title and all field descriptions are written in Chinese, but the document does not state that the skill is China-specific or that language selection is optional. Under the language/locale policy rule, a fixed language can be a policy issue when no opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The thrown error strings are written only in Chinese, which imposes a specific language on user-visible output without any language selection or opt-in mechanism. This is a natural-language policy concern because the skill does not indicate that it is region- or language-specific, nor does it offer alternatives.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The user-facing help text and examples are entirely oriented around Chinese-language queries and Chinese company lookup, including example input like "企业股东信息". This can be read as a locale/language constraint, but the file does not explicitly state that the tool is region-specific or that other languages may also be used.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The natural-language configuration hard-codes activation terms in specific languages/locales, including many Chinese-only triggers and some English transliterations. Because the file provides no indication that users can choose language behavior or that the locale restriction is intentional and documented, it may violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.