Back to skill

Security audit

小分子研发分析(Small-Molecule R&D Analysis)

Security checks for vulnerabilities and agentic risk

Overview

This skill needs review because it exposes a reusable API key in its instructions and routes chemistry queries to an external service without enough disclosure.

Review before installing. The skill appears purpose-aligned for molecule intelligence, but the publisher should remove and rotate the exposed API key and provide clear disclosure about what data is sent to the external MCP service, especially for proprietary or pre-publication compounds.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:11
Finding

Hardcoded MCP API Credential Exposed in Skill Documentation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 11 and 41
Vulnerability Type: Hardcoded API credential in a URL query parameter
Risk Level: High

Vulnerable Code

Line 11:

markdown
通过集成 MCP 工具(`https://connect.zhihuiya.com/713886/logic-mcp?apikey=sk-3F0NsY7KOt2ZyO72XkgwUIwD80xSfBjCNKp7juA92d0HWpKu`)访问智慧芽化学分子数据库

Line 41:

markdown
**MCP 端点**:`https://connect.zhihuiya.com/713886/logic-mcp?apikey=sk-3F0NsY7KOt2ZyO72XkgwUIwD80xSfBjCNKp7juA92d0HWpKu`

Technical Analysis

A reusable MCP API credential is embedded directly in the version-controlled Skill documentation. Any party with access to the package, repository, distributed artifact, backups, or source history can recover the credential without additional privileges.

The secret is also supplied through the URL query string. Query parameters commonly appear in HTTP access logs, reverse-proxy logs, observability platforms, error reports, browser history, and other monitoring records. This creates additional disclosure paths beyond direct access to the project files.

The same credential appears twice, increasing the likelihood that partial remediation will leave one exposed copy. Although the audit cannot verify the credential's current validity or exact server-side permissions, it must be treated as compromised.

Attack Path

  1. An attacker obtains read access to the Skill package, a repository clone, an archived artifact, or exposed repository history.
  2. The attacker reads SKILL.md and extracts the value of the apikey query parameter.
  3. The attacker submits requests to the declared MCP endpoint using the exposed key.
  4. If the credential remains valid, the endpoint attributes those requests to the compromised credential.
  5. The attacker can continue making requests within the permissions and limits assigned to that key until it is revoked, rotated, or otherwise disabled.

A secondary disclosure route exists if legitimate users invoke the URL as written: in ...[truncated 912 chars]

Remediation
View remediation

Remediation Suggestions

  1. Revoke the exposed API key immediately and issue a replacement; assume the existing key has already been copied.

  2. Remove every plaintext occurrence from the current files and repository history. Confirm that both lines 11 and 41, along with prior commits, release archives, caches, and generated artifacts, are sanitized.

  3. Store the replacement credential in an approved secret manager or protected runtime environment variable rather than in Skill text or source control.

  4. Publish only a credential-free endpoint, for example:

    text
    https://connect.zhihuiya.com/713886/logic-mcp
    
  5. Where supported, transmit the credential in an authorization header rather than a query parameter:

    http
    Authorization: Bearer ${ZHIHUIYA_MCP_API_KEY}
    
  6. Restrict the replacement key to the minimum required API operations, datasets, environments, and usage limits. Apply network or tenant restrictions where supported.

  7. Enable automated secret scanning in pre-commit hooks and CI pipelines to block future credential commits.

  8. Review API, proxy, application, and telemetry logs for use of the exposed key. Rotate or purge credentials from logs where feasible and investigate anomalous requests.

  9. Add documented credential-expiration and rotation procedures so future exposure has a limited impact window.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill documentation embeds a plaintext API key directly in the MCP endpoint URL, exposing a live credential to anyone who can view the file and increasing the chance the model, logs, or downstream tooling will echo it. Because this skill is designed to trigger external tool use, the exposed key can be reused for unauthorized access, quota abuse, or data exfiltration against the backing service.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill exposes and operationalizes an API key in a user-accessible endpoint without any warning about credential handling, meaning users and systems may unknowingly transmit sensitive inputs to a third-party service while also inheriting a leaked credential. This combines secret exposure with opaque external processing, making unauthorized use and unintended data disclosure more likely.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

A live API credential is embedded in plain text inside user-accessible skill instructions, which is a direct secret-management failure. Any viewer, log pipeline, model output, or prompt-injection chain that surfaces the file can leak the credential, enabling unauthorized service access and making downstream incidents difficult to contain.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The MCP configuration section repeats the same hard-coded API key, creating a second disclosure point and increasing the likelihood of accidental exposure through prompts, UI rendering, indexing, or model reproduction. Repetition materially worsens risk because even partial redaction elsewhere can leave another copy available for abuse.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Repeating the plaintext credential in natural-language configuration guidance increases the chance the model will quote or paraphrase it during normal operation, troubleshooting, or summarization. In this skill's context, the repeated exposure is especially dangerous because the agent is explicitly told to activate and use the external MCP tool, making the secret both visible and functionally actionable.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs the agent to use an external MCP endpoint but does not clearly warn users that their compound identifiers, structures, or related research inputs may be transmitted to a third party for processing. In a chemistry R&D context, those inputs can be proprietary or pre-publication, so the lack of transparency raises privacy, confidentiality, and compliance risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.