Back to skill

Security audit

影刀

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Yingdao RPA API wrapper, but it can start real automation jobs and uses sensitive API secrets in a way users should review carefully.

Review before installing. Use a dedicated least-privileged Yingdao credential, avoid production task starts without explicit human approval, rotate keys if URLs may be logged, and prefer a pinned or locked dependency install. The artifact does not show deception or local persistence, but its external automation and credential-handling behavior are high impact.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
yingdao_api.py:47
Finding

Long-Lived API Secret Transmitted in a URL Query String

Content
View full analysis

Vulnerability Details

File Location: yingdao_api.py:47-52
Vulnerability Type: Sensitive credential exposure through URL parameters
Risk Level: Medium

Vulnerable Code

python
params = {
    "accessKeyId": self.access_key_id,
    "accessKeySecret": self.access_key_secret
}
resp = requests.get(self.AUTH_ENDPOINT, params=params, timeout=30)

Technical Analysis

The authentication request includes accessKeySecret as a GET query parameter. Although the endpoint uses HTTPS and therefore encrypts the request in transit, URL query strings are commonly retained in web-server access logs, reverse-proxy logs, monitoring systems, debugging output, and request traces.

Additionally, network exceptions generated by the HTTP client may contain the requested URL. Since the surrounding exception handler incorporates the exception text into a new YingdaoError, credential-bearing URL information could be exposed to application logs if callers record that exception.

The access key secret is a long-lived credential used to obtain bearer tokens. It therefore requires stronger protection than a temporary access token.

Attack Path

  1. A user configures valid YINGDAO_ACCESS_KEY_ID and YINGDAO_ACCESS_KEY_SECRET credentials.
  2. The client calls _refresh_token() to authenticate.
  3. The HTTP client serializes both credentials into the request URL.
  4. An API gateway, reverse proxy, observability platform, debug logger, or error-reporting system records the complete URL.
  5. An attacker or unauthorized operator with access to those records extracts the access key ID and secret.
  6. The attacker submits the credentials to the Yingdao authentication endpoint and obtains an access token.
  7. Using the resulting token, the attacker invokes business APIs within the permissions assigned to the compromised Yingdao credentials.

Impact Assessment

Successful exploitation exposes the Yingdao access key pair. An attacker could authenticate as the affect ...[truncated 486 chars]

Remediation
View remediation

Remediation Suggestions

  1. Prefer an authentication mechanism that transmits the secret in an authorization header or POST body rather than in the URL, if the Yingdao API supports one.
  2. If the upstream API mandates GET query parameters:
    • Configure clients, proxies, gateways, and servers to redact accessKeyId and accessKeySecret.
    • Disable request URL logging for the authentication endpoint.
    • Ensure application performance monitoring and error-reporting systems do not capture query strings.
    • Restrict access to operational logs and define short retention periods.
  3. Avoid returning raw requests exception text when a request may contain credentials. Raise a sanitized error that omits URLs and query parameters.
  4. Store credentials in an approved secret manager where possible and rotate the access key immediately if URL-bearing logs may already have been retained.
  5. Use a dedicated, least-privileged Yingdao credential so that exposure does not grant unnecessary task or administrative capabilities.

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Non-Reproducible and Unbounded Third-Party Dependency

Content
View full analysis

Vulnerability Details

File Location: requirements.txt:1
Vulnerability Type: Unbounded dependency version and missing package integrity verification
Risk Level: Low

Vulnerable Code

text
requests>=2.28.0

Technical Analysis

The dependency declaration specifies only a minimum version and permits any later release of requests. It also provides no package hashes or lock file. Consequently, two installations of the same Skill can resolve to different dependency versions, including future releases that were not reviewed with this project.

The package name is legitimate and the audit found no evidence of typosquatting, dependency confusion, or a currently malicious release. The risk arises from the unrestricted resolution policy and lack of integrity controls: a compromised future release, repository compromise, or incompatible dependency update could be installed automatically during a fresh deployment.

Attack Path

  1. A user installs the Skill and runs pip install -r requirements.txt.
  2. The package resolver selects the newest available release satisfying the minimum-version constraint.
  3. If a future matching release or its distribution channel is compromised, the resolver downloads the affected artifact because no upper bound, lock file, or expected hash prevents it.
  4. Installation or subsequent import of the dependency executes the compromised package code in the Python environment.
  5. That code receives the privileges of the process running or importing the Skill and may access data available to that process, including configured environment variables.

This is a prospective supply-chain path; the reviewed project does not establish that the currently available requests package is malicious.

Impact Assessment

A compromised dependency would execute with the same operating-system privileges as the Python process using this Skill. It could potentially access Skill inputs, network traffic, environment variables ...[truncated 227 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin requests to a reviewed release or use a narrowly bounded, tested version range.
  2. Generate and commit a lock file that records all transitive dependency versions.
  3. Use hash-verified installation, such as a requirements file generated with hashes and installed using pip --require-hashes.
  4. Update dependencies through a controlled review process that includes automated vulnerability scanning and compatibility tests.
  5. Install packages only from trusted indexes over authenticated TLS connections.
  6. Rebuild and review the lock file regularly so that security updates can be adopted without silently accepting arbitrary future releases.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill clearly requires environment credentials and communicates with external network endpoints, but it does not declare an explicit tool scope such as permissions or allowed-tools. This creates an authorization and transparency gap: a host agent or user may not realize the skill can read secrets from the environment and make outbound API calls, increasing the chance of unintended credential use or external actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation advertises starting RPA tasks and querying results but does not warn that task execution can cause real automated actions in external systems, potentially modifying data, triggering workflows, or operating on production environments. Without a clear warning, users or higher-level agents may invoke the skill assuming it is read-only, leading to unsafe or unintended side effects.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · yingdao_api.py (reported line 22)May include surrounding context.

python
"""影刀 RPA API 客户端"""

    # API 端点
    AUTH_ENDPOINT = "https://api.yingdao.com/oapi/token/v2/token/create"
    BUSINESS_ENDPOINT = "https://api.winrobot360.com/oapi"

    def __init__(self, access_key_id: Optional[str] = None, access_key_secret: Optional[str] = None):

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · yingdao_api.py (reported line 23)May include surrounding context.

python
# API 端点
    AUTH_ENDPOINT = "https://api.yingdao.com/oapi/token/v2/token/create"
    BUSINESS_ENDPOINT = "https://api.winrobot360.com/oapi"

    def __init__(self, access_key_id: Optional[str] = None, access_key_secret: Optional[str] = None):
        """

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The authentication flow sends the long-lived access key ID and secret as URL query parameters in a GET request. Even though HTTPS is used, query strings are commonly captured by client logs, proxies, monitoring systems, browser/history equivalents, and upstream infrastructure, which increases the chance of credential leakage beyond the intended recipient.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The module docstring is written entirely in Chinese and provides no indication that other languages are supported. Under the policy, natural-language content that forces a specific language without user opt-in can be a locale/language policy violation.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
90% confidence
Finding

The dependency is specified as requests>=2.28.0, which allows any future version and does not guarantee reproducible installs. This increases supply-chain risk because different environments may resolve different versions, including newly introduced vulnerable or incompatible releases.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests>=2.28.0

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
84% confidence
Finding

The manifest does not pin requests, so it is impossible to determine whether deployments will use a version affected by known advisories. In a skill that handles API authentication credentials, unresolved dependency versions are more concerning because vulnerable HTTP client behavior could expose secrets or weaken transport security assumptions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

Docstrings, comments, and error messages throughout the file are written exclusively in Chinese, with no indication of language choice or locale scope. Under the stated policy, forcing a specific language without opt-in can be a natural-language policy violation unless clearly documented as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.