Back to skill

Security audit

智能会话分析

Security checks for vulnerabilities and agentic risk

Overview

This looks like a real Alibaba Cloud conversation-analysis skill, but it needs Review because it sends sensitive call data to a third party while also using under-scoped credential loading and background polling.

Install only if you are comfortable sending the selected conversation text or publicly reachable audio URL to Alibaba Cloud CCAI and paying for those API calls. Use least-privilege Alibaba credentials, avoid placing unrelated secrets in parent .env files, prefer short-lived private or signed recording URLs, and approve any background polling only with a clear stop condition.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (34)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 117)May include surrounding context.

md
node scripts/bundle.cjs task.json

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 127)May include surrounding context.

md
node scripts/bundle.cjs task.json

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 136)May include surrounding context.

md
node scripts/bundle.cjs task.json

Cloud Metadata Access

High
Category
Server-Side Request Forgery
Confidence
85% confidence
Finding

Code accesses a cloud instance metadata endpoint (e.g. 169.254.169.254). A single request can return temporary IAM credentials, making this a high-value SSRF target for credential theft.

Content

Scanner excerpt · scripts/bundle.cjs (reported line 20354)May include surrounding context.

js
var utils = __importStar(require_utils());
    var http_1 = require_http();
    var config_1 = __importDefault(require_config());
    var SECURITY_CRED_URL = "http://100.100.100.200/latest/meta-data/ram/security-credentials/";
    var RsaKeyPairCredential = class extends session_credential_1.default {
      constructor(publicKeyId, privateKeyFile) {
        if (!publicKeyId) {

Cloud Metadata Access

High
Category
Server-Side Request Forgery
Confidence
85% confidence
Finding

Code accesses a cloud instance metadata endpoint (e.g. 169.254.169.254). A single request can return temporary IAM credentials, making this a high-value SSRF target for credential theft.

Content

Scanner excerpt · scripts/bundle.cjs (reported line 21411)May include surrounding context.

js
var utils = __importStar(require_utils());
    var http_1 = require_http();
    var config_1 = __importDefault(require_config());
    var SECURITY_CRED_URL = "http://100.100.100.200/latest/meta-data/ram/security-credentials/";
    var RsaKeyPairCredential = class extends session_credential_1.default {
      constructor(publicKeyId, privateKeyFile) {
        if (!publicKeyId) {

Cloud Metadata Access

High
Category
Server-Side Request Forgery
Confidence
85% confidence
Finding

Code accesses a cloud instance metadata endpoint (e.g. 169.254.169.254). A single request can return temporary IAM credentials, making this a high-value SSRF target for credential theft.

Content

Scanner excerpt · scripts/bundle.cjs (reported line 21428)May include surrounding context.

js
var utils = __importStar(require_utils());
    var http_1 = require_http();
    var config_1 = __importDefault(require_config());
    var SECURITY_CRED_URL = "http://100.100.100.200/latest/meta-data/ram/security-credentials/";
    var RsaKeyPairCredential = class extends session_credential_1.default {
      constructor(publicKeyId, privateKeyFile) {
        if (!publicKeyId) {

Cloud Metadata Access

High
Category
Server-Side Request Forgery
Confidence
85% confidence
Finding

Code accesses a cloud instance metadata endpoint (e.g. 169.254.169.254). A single request can return temporary IAM credentials, making this a high-value SSRF target for credential theft.

Content

Scanner excerpt · scripts/bundle.cjs (reported line 21447)May include surrounding context.

js
var utils = __importStar(require_utils());
    var http_1 = require_http();
    var config_1 = __importDefault(require_config());
    var SECURITY_CRED_URL = "http://100.100.100.200/latest/meta-data/ram/security-credentials/";
    var RsaKeyPairCredential = class extends session_credential_1.default {
      constructor(publicKeyId, privateKeyFile) {
        if (!publicKeyId) {

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/bundle.cjs (reported line 33497)May include surrounding context.

js
module2.exports = {
      name: "dotenv",
      version: "17.3.1",
      description: "Loads environment variables from .env file",
      main: "lib/main.js",
      types: "lib/main.d.ts",
      exports: {

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/bundle.cjs (reported line 33570)May include surrounding context.

js
module2.exports = {
      name: "dotenv",
      version: "17.3.1",
      description: "Loads environment variables from .env file",
      main: "lib/main.js",
      types: "lib/main.d.ts",
      exports: {

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/bundle.cjs (reported line 33571)May include surrounding context.

js
module2.exports = {
      name: "dotenv",
      version: "17.3.1",
      description: "Loads environment variables from .env file",
      main: "lib/main.js",
      types: "lib/main.d.ts",
      exports: {

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/bundle.cjs (reported line 33576)May include surrounding context.

js
module2.exports = {
      name: "dotenv",
      version: "17.3.1",
      description: "Loads environment variables from .env file",
      main: "lib/main.js",
      types: "lib/main.d.ts",
      exports: {

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/bundle.cjs (reported line 33581)May include surrounding context.

js
module2.exports = {
      name: "dotenv",
      version: "17.3.1",
      description: "Loads environment variables from .env file",
      main: "lib/main.js",
      types: "lib/main.d.ts",
      exports: {

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/bundle.cjs (reported line 33532)May include surrounding context.

js
keywords: [
        "dotenv",
        "env",
        ".env",
        "environment",
        "variables",
        "config",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/bundle.cjs (reported line 33734)May include surrounding context.

js
keywords: [
        "dotenv",
        "env",
        ".env",
        "environment",
        "variables",
        "config",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/bundle.cjs (reported line 33576)May include surrounding context.

js
"\u26A1\uFE0F secrets for agents: https://dotenvx.com/as2",
      "\u{1F6E1}\uFE0F auth for agents: https://vestauth.com",
      "\u{1F6E0}\uFE0F  run anywhere with `dotenvx run -- yourcommand`",
      "\u2699\uFE0F  specify custom .env file path with { path: '/custom/path/.env' }",
      "\u2699\uFE0F  enable debug logging with { debug: true }",
      "\u2699\uFE0F  override existing env vars with { override: true }",
      "\u2699\uFE0F  suppress all logs with { quiet: true }",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/bundle.cjs (reported line 33581)May include surrounding context.

js
"\u26A1\uFE0F secrets for agents: https://dotenvx.com/as2",
      "\u{1F6E1}\uFE0F auth for agents: https://vestauth.com",
      "\u{1F6E0}\uFE0F  run anywhere with `dotenvx run -- yourcommand`",
      "\u2699\uFE0F  specify custom .env file path with { path: '/custom/path/.env' }",
      "\u2699\uFE0F  enable debug logging with { debug: true }",
      "\u2699\uFE0F  override existing env vars with { override: true }",
      "\u2699\uFE0F  suppress all logs with { quiet: true }",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/bundle.cjs (reported line 33581)May include surrounding context.

js
"\u2699\uFE0F  override existing env vars with { override: true }",
      "\u2699\uFE0F  suppress all logs with { quiet: true }",
      "\u2699\uFE0F  write to custom object with { processEnv: myObject }",
      "\u2699\uFE0F  load multiple .env files with { path: ['.env.local', '.env'] }"
    ];
    function _getRandomTip() {
      return TIPS[Math.floor(Math.random() * TIPS.length)];

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

This is skill-owned code that defines a list of .env paths and then loads whichever exists first. That behavior enables implicit secret access from the working directory and parent directories, which is dangerous in shared or multi-project environments because unrelated secrets may be consumed without operator awareness.

Content

Scanner excerpt · scripts/bundle.cjs (reported line 33902)May include surrounding context.

js
var path = __toESM(require("path"));
var fs = __toESM(require("fs"));
var envPaths = [
  path.resolve(process.cwd(), ".env"),
  path.resolve(__dirname, "../../.env"),
  path.resolve(__dirname, "../../../.env")
];

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

This parent-directory .env search path broadens the set of local secrets the skill may access beyond its own directory. In agent environments, that can accidentally pull in higher-level repository or workspace secrets and then use them for outbound API calls.

Content

Scanner excerpt · scripts/bundle.cjs (reported line 33903)May include surrounding context.

js
var fs = __toESM(require("fs"));
var envPaths = [
  path.resolve(process.cwd(), ".env"),
  path.resolve(__dirname, "../../.env"),
  path.resolve(__dirname, "../../../.env")
];
for (const envPath of envPaths) {

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

The third fallback .env location further expands secret discovery to an even higher-level directory, increasing the chance of unintended credential ingestion. Because the skill subsequently uses loaded credentials for network actions, this is a meaningful secret-boundary violation.

Content

Scanner excerpt · scripts/bundle.cjs (reported line 33904)May include surrounding context.

js
var envPaths = [
  path.resolve(process.cwd(), ".env"),
  path.resolve(__dirname, "../../.env"),
  path.resolve(__dirname, "../../../.env")
];
for (const envPath of envPaths) {
  if (fs.existsSync(envPath)) {

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This code submits conversation text, audio URLs, and potentially image URLs to Alibaba Cloud APIs, but provides no explicit warning or consent flow about external transmission of potentially sensitive customer data. In a customer-service analysis skill, that omission is especially risky because inputs may contain PII, call content, and compliance-sensitive material.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill requires access to environment variables containing cloud credentials and instructs outbound access to Alibaba Cloud, but it declares no explicit tool scope or permission boundary. This creates a hidden capability gap where an agent may access secrets or use network operations without transparent, least-privilege constraints, increasing the risk of unintended credential exposure or unauthorized external calls.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill’s natural-language description and operating instructions are entirely in Chinese, and there is no indication that users may interact in another language or choose their preferred locale. Under the policy, forcing a specific language without opt-in is a reportable locale/language violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs the agent to create cron jobs that persist beyond the immediate user interaction to poll results and proactively notify the user. This expands the skill from one-shot conversation analysis into autonomous background execution, which can lead to unbounded follow-up actions, unexpected data handling over time, and abuse of scheduler capabilities not obviously necessary for the core task.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document instructs users to supply a publicly accessible audio URL for call recordings but does not warn about privacy, consent, or third-party data transfer risks. In this skill’s context, the audio may contain sensitive customer-service conversations and personal data, so encouraging public exposure or upload without safeguards can lead to unintended disclosure and compliance violations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.