other
- Location
SKILL.md:15- Finding
Uncontrolled Disclosure of Queried IP Indicators to a Third-Party Service
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 15–30 and 35–43
Vulnerability Type: Third-Party Data Disclosure
Risk Level: MediumVulnerable Code Snippet
markdown ## API information - **Base URL**: `https://ai2api.top/api/v1/security/ip-intelligence` - **Authentication**: Header `X-API-Key` - **Average response**: < 50ms ## Authentication configuration Configure the following environment variable before use:IP_INTELLIGENCE_API_KEY=<your-api-key>
text Pass it through a request header:X-API-Key: ${IP_INTELLIGENCE_API_KEY}
text markdown ### 1. Query IP security intelligence **Method**: POST **Endpoint**: `/api/v1/security/ip-intelligence` **Request body**: ```json { "ip": "1.13.246.134", "fields": ["all"] }text ### Technical Analysis The Skill instructs the Agent to send each queried IP address and an API credential to `ai2api.top`. Although this network communication supports the advertised IP-intelligence function, it crosses an external trust boundary. The project does not document the service provider's ownership, privacy policy, data-retention policy, or security assurances. It also does not require informed user consent, warn against submitting private or sensitive infrastructure indicators, or provide an option to use an approved or self-hosted endpoint. HTTPS protects the request in transit under normal conditions, but it does not prevent the service operator from retaining or correlating submitted indicators. The provider also necessarily receives the API key and request metadata. No evidence establishes malicious behavior by the provider; the issue is the uncontrolled disclosure risk created by the Skill's instructions. ### Attack Path 1. A user asks the Agent to investigate an internal, customer-related, or incident-sensitive IP address. 2. The Agent follows `SKILL.md` and sends a POST request to `ht ...[truncated 1242 chars]- Remediation
View remediation
Remediation Suggestions
- Verify and document the provider's ownership, privacy policy, data-retention period, breach-response process, and security controls before use.
- Require explicit user approval before transmitting indicators to the third-party endpoint.
- Clearly warn users not to submit private, regulated, customer-sensitive, or incident-confidential indicators unless disclosure is authorized.
- Add an approved endpoint allowlist and support a trusted or self-hosted intelligence service.
- Minimize transmitted data by requesting only necessary fields instead of
"fields": ["all"]. - Use scoped, revocable, and regularly rotated API keys with the minimum permissions and quotas required.
- Ensure the API key is never included in generated reports, application logs, error messages, command histories, or telemetry.
- Define retention and deletion requirements for query history and generated reports.
- Document transport-security requirements, including strict TLS certificate validation and rejection of redirects to unapproved hosts.
- Redact or aggregate sensitive indicators before incorporating external-service results into reports.
