Back to skill

Security audit

ip-intelligence

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward IP threat-intelligence/reporting helper that discloses its external API use and does not include code, persistence, or hidden privilege behavior.

Install only if you trust the ai2api.top service and are authorized to send the IP indicators you query. Use a scoped, revocable API key, avoid hardcoding it, and do not submit private, customer-sensitive, or incident-confidential IP data unless disclosure to that provider is approved.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

other

Warning
Location
SKILL.md:15
Finding

Uncontrolled Disclosure of Queried IP Indicators to a Third-Party Service

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 15–30 and 35–43
Vulnerability Type: Third-Party Data Disclosure
Risk Level: Medium

Vulnerable Code Snippet

markdown
## API information

- **Base URL**: `https://ai2api.top/api/v1/security/ip-intelligence`
- **Authentication**: Header `X-API-Key`
- **Average response**: < 50ms

## Authentication configuration

Configure the following environment variable before use:

IP_INTELLIGENCE_API_KEY=<your-api-key>

text

Pass it through a request header:

X-API-Key: ${IP_INTELLIGENCE_API_KEY}

text
markdown
### 1. Query IP security intelligence

**Method**: POST  
**Endpoint**: `/api/v1/security/ip-intelligence`

**Request body**:
```json
{
  "ip": "1.13.246.134",
  "fields": ["all"]
}
text

### Technical Analysis

The Skill instructs the Agent to send each queried IP address and an API credential to `ai2api.top`. Although this network communication supports the advertised IP-intelligence function, it crosses an external trust boundary.

The project does not document the service provider's ownership, privacy policy, data-retention policy, or security assurances. It also does not require informed user consent, warn against submitting private or sensitive infrastructure indicators, or provide an option to use an approved or self-hosted endpoint.

HTTPS protects the request in transit under normal conditions, but it does not prevent the service operator from retaining or correlating submitted indicators. The provider also necessarily receives the API key and request metadata. No evidence establishes malicious behavior by the provider; the issue is the uncontrolled disclosure risk created by the Skill's instructions.

### Attack Path

1. A user asks the Agent to investigate an internal, customer-related, or incident-sensitive IP address.
2. The Agent follows `SKILL.md` and sends a POST request to `ht
...[truncated 1242 chars]
Remediation
View remediation

Remediation Suggestions

  1. Verify and document the provider's ownership, privacy policy, data-retention period, breach-response process, and security controls before use.
  2. Require explicit user approval before transmitting indicators to the third-party endpoint.
  3. Clearly warn users not to submit private, regulated, customer-sensitive, or incident-confidential indicators unless disclosure is authorized.
  4. Add an approved endpoint allowlist and support a trusted or self-hosted intelligence service.
  5. Minimize transmitted data by requesting only necessary fields instead of "fields": ["all"].
  6. Use scoped, revocable, and regularly rotated API keys with the minimum permissions and quotas required.
  7. Ensure the API key is never included in generated reports, application logs, error messages, command histories, or telemetry.
  8. Define retention and deletion requirements for query history and generated reports.
  9. Document transport-security requirements, including strict TLS certificate validation and rejection of redirects to unapproved hosts.
  10. Redact or aggregate sensitive indicators before incorporating external-service results into reports.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest description is entirely in Chinese and specifies the skill's usage and trigger phrases only in Chinese, which implies a fixed language/locale for invocation and operation. The file does not offer multilingual use, user opt-in, or a clear justification that the skill is restricted to a Chinese-only regional compliance context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.