Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md node scripts/bundle.cjs task.json
Security audit
Security checks for vulnerabilities and agentic risk
This looks like a real Alibaba Cloud conversation-analysis skill, but it needs Review because it sends sensitive call data to a third party while also using under-scoped credential loading and background polling.
Install only if you are comfortable sending the selected conversation text or publicly reachable audio URL to Alibaba Cloud CCAI and paying for those API calls. Use least-privilege Alibaba credentials, avoid placing unrelated secrets in parent .env files, prefer short-lived private or signed recording URLs, and approve any background polling only with a clear stop condition.
Referenced artifact was not completely inspected
node scripts/bundle.cjs task.json
Referenced artifact was not completely inspected
node scripts/bundle.cjs task.json
Referenced artifact was not completely inspected
node scripts/bundle.cjs task.json
Code accesses a cloud instance metadata endpoint (e.g. 169.254.169.254). A single request can return temporary IAM credentials, making this a high-value SSRF target for credential theft.
var utils = __importStar(require_utils());
var http_1 = require_http();
var config_1 = __importDefault(require_config());
var SECURITY_CRED_URL = "http://100.100.100.200/latest/meta-data/ram/security-credentials/";
var RsaKeyPairCredential = class extends session_credential_1.default {
constructor(publicKeyId, privateKeyFile) {
if (!publicKeyId) {
Code accesses a cloud instance metadata endpoint (e.g. 169.254.169.254). A single request can return temporary IAM credentials, making this a high-value SSRF target for credential theft.
var utils = __importStar(require_utils());
var http_1 = require_http();
var config_1 = __importDefault(require_config());
var SECURITY_CRED_URL = "http://100.100.100.200/latest/meta-data/ram/security-credentials/";
var RsaKeyPairCredential = class extends session_credential_1.default {
constructor(publicKeyId, privateKeyFile) {
if (!publicKeyId) {
Code accesses a cloud instance metadata endpoint (e.g. 169.254.169.254). A single request can return temporary IAM credentials, making this a high-value SSRF target for credential theft.
var utils = __importStar(require_utils());
var http_1 = require_http();
var config_1 = __importDefault(require_config());
var SECURITY_CRED_URL = "http://100.100.100.200/latest/meta-data/ram/security-credentials/";
var RsaKeyPairCredential = class extends session_credential_1.default {
constructor(publicKeyId, privateKeyFile) {
if (!publicKeyId) {
Code accesses a cloud instance metadata endpoint (e.g. 169.254.169.254). A single request can return temporary IAM credentials, making this a high-value SSRF target for credential theft.
var utils = __importStar(require_utils());
var http_1 = require_http();
var config_1 = __importDefault(require_config());
var SECURITY_CRED_URL = "http://100.100.100.200/latest/meta-data/ram/security-credentials/";
var RsaKeyPairCredential = class extends session_credential_1.default {
constructor(publicKeyId, privateKeyFile) {
if (!publicKeyId) {
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
module2.exports = {
name: "dotenv",
version: "17.3.1",
description: "Loads environment variables from .env file",
main: "lib/main.js",
types: "lib/main.d.ts",
exports: {
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
module2.exports = {
name: "dotenv",
version: "17.3.1",
description: "Loads environment variables from .env file",
main: "lib/main.js",
types: "lib/main.d.ts",
exports: {
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
module2.exports = {
name: "dotenv",
version: "17.3.1",
description: "Loads environment variables from .env file",
main: "lib/main.js",
types: "lib/main.d.ts",
exports: {
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
module2.exports = {
name: "dotenv",
version: "17.3.1",
description: "Loads environment variables from .env file",
main: "lib/main.js",
types: "lib/main.d.ts",
exports: {
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
module2.exports = {
name: "dotenv",
version: "17.3.1",
description: "Loads environment variables from .env file",
main: "lib/main.js",
types: "lib/main.d.ts",
exports: {
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
keywords: [
"dotenv",
"env",
".env",
"environment",
"variables",
"config",
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
keywords: [
"dotenv",
"env",
".env",
"environment",
"variables",
"config",
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"\u26A1\uFE0F secrets for agents: https://dotenvx.com/as2",
"\u{1F6E1}\uFE0F auth for agents: https://vestauth.com",
"\u{1F6E0}\uFE0F run anywhere with `dotenvx run -- yourcommand`",
"\u2699\uFE0F specify custom .env file path with { path: '/custom/path/.env' }",
"\u2699\uFE0F enable debug logging with { debug: true }",
"\u2699\uFE0F override existing env vars with { override: true }",
"\u2699\uFE0F suppress all logs with { quiet: true }",
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"\u26A1\uFE0F secrets for agents: https://dotenvx.com/as2",
"\u{1F6E1}\uFE0F auth for agents: https://vestauth.com",
"\u{1F6E0}\uFE0F run anywhere with `dotenvx run -- yourcommand`",
"\u2699\uFE0F specify custom .env file path with { path: '/custom/path/.env' }",
"\u2699\uFE0F enable debug logging with { debug: true }",
"\u2699\uFE0F override existing env vars with { override: true }",
"\u2699\uFE0F suppress all logs with { quiet: true }",
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"\u2699\uFE0F override existing env vars with { override: true }",
"\u2699\uFE0F suppress all logs with { quiet: true }",
"\u2699\uFE0F write to custom object with { processEnv: myObject }",
"\u2699\uFE0F load multiple .env files with { path: ['.env.local', '.env'] }"
];
function _getRandomTip() {
return TIPS[Math.floor(Math.random() * TIPS.length)];
This is skill-owned code that defines a list of .env paths and then loads whichever exists first. That behavior enables implicit secret access from the working directory and parent directories, which is dangerous in shared or multi-project environments because unrelated secrets may be consumed without operator awareness.
var path = __toESM(require("path"));
var fs = __toESM(require("fs"));
var envPaths = [
path.resolve(process.cwd(), ".env"),
path.resolve(__dirname, "../../.env"),
path.resolve(__dirname, "../../../.env")
];
This parent-directory .env search path broadens the set of local secrets the skill may access beyond its own directory. In agent environments, that can accidentally pull in higher-level repository or workspace secrets and then use them for outbound API calls.
var fs = __toESM(require("fs"));
var envPaths = [
path.resolve(process.cwd(), ".env"),
path.resolve(__dirname, "../../.env"),
path.resolve(__dirname, "../../../.env")
];
for (const envPath of envPaths) {
The third fallback .env location further expands secret discovery to an even higher-level directory, increasing the chance of unintended credential ingestion. Because the skill subsequently uses loaded credentials for network actions, this is a meaningful secret-boundary violation.
var envPaths = [
path.resolve(process.cwd(), ".env"),
path.resolve(__dirname, "../../.env"),
path.resolve(__dirname, "../../../.env")
];
for (const envPath of envPaths) {
if (fs.existsSync(envPath)) {
This code submits conversation text, audio URLs, and potentially image URLs to Alibaba Cloud APIs, but provides no explicit warning or consent flow about external transmission of potentially sensitive customer data. In a customer-service analysis skill, that omission is especially risky because inputs may contain PII, call content, and compliance-sensitive material.
The skill requires access to environment variables containing cloud credentials and instructs outbound access to Alibaba Cloud, but it declares no explicit tool scope or permission boundary. This creates a hidden capability gap where an agent may access secrets or use network operations without transparent, least-privilege constraints, increasing the risk of unintended credential exposure or unauthorized external calls.
The skill’s natural-language description and operating instructions are entirely in Chinese, and there is no indication that users may interact in another language or choose their preferred locale. Under the policy, forcing a specific language without opt-in is a reportable locale/language violation unless clearly justified as region-specific.
The skill instructs the agent to create cron jobs that persist beyond the immediate user interaction to poll results and proactively notify the user. This expands the skill from one-shot conversation analysis into autonomous background execution, which can lead to unbounded follow-up actions, unexpected data handling over time, and abuse of scheduler capabilities not obviously necessary for the core task.
The document instructs users to supply a publicly accessible audio URL for call recordings but does not warn about privacy, consent, or third-party data transfer risks. In this skill’s context, the audio may contain sensitive customer-service conversations and personal data, so encouraging public exposure or upload without safeguards can lead to unintended disclosure and compliance violations.
No suspicious patterns detected.