Back to skill

Security audit

支付宝支付异步通知助手

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says, but it routes payment notification data and relay credentials through a hard-coded unencrypted HTTP relay and stores local credentials weakly.

Install only if you are comfortable sending Alipay sandbox or test notification payloads through this third-party relay. Do not use it for production or real customer payment data unless the relay is moved to HTTPS and you trust the operator. Keep .alipay-notify.json out of source control, restrict its file permissions, and rotate relay credentials if they may have been exposed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/cli.py:145
Finding

Payment notification data and bearer credentials are transmitted over unencrypted HTTP

Content
View full analysis

Vulnerability Details

File Location: scripts/cli.py:145-154; insecure default endpoint documented at SKILL.md:66 and README.md:29
Vulnerability Type: Cleartext transmission of sensitive information
Risk Level: High

Vulnerable Code

python
def api_get(cfg, path, params=None):
    url = cfg["server_url"] + path
    if params:
        url += "?" + urllib.parse.urlencode({k: v for k, v in params.items() if v})
    return http_request("GET", url, headers={"Authorization": f"Bearer {cfg['api_key']}"})


def api_post(cfg, path, body=None):
    url = cfg["server_url"] + path
    return http_request("POST", url, headers={"Authorization": f"Bearer {cfg['api_key']}"}, body=body)

The Skill directs users to the following default endpoint:

bash
python3 "$SKILL_DIR/scripts/cli.py" register --server http://8.136.213.223:9010 --name <developer-name>

Technical Analysis

The API client attaches the relay API key as a bearer credential to requests constructed directly from server_url. The implementation does not require HTTPS or reject cleartext HTTP endpoints. The documented default is http://8.136.213.223:9010, causing the bearer credential to be transmitted without transport encryption.

The same cleartext server is used for registration, notification retrieval, SSE streaming, and acknowledgement requests. The generated Alipay callback URL also uses HTTP. Consequently, sensitive callback contents can cross the network in plaintext, including order numbers, Alipay transaction numbers, payment amounts, application IDs, notification identifiers, signatures, and the complete raw callback body.

Although sending notification data to a relay is necessary for the declared functionality, sending it over unencrypted HTTP is not necessary and violates least-exposure principles.

Attack Path

  1. A victim follows the documented registration command and connects to the HTTP relay. 2 ...[truncated 1244 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require https:// for registration, API access, SSE streaming, and generated callback URLs.
  2. Reject HTTP server URLs before sending registration details or credentials.
  3. If local development requires HTTP, permit it only for loopback addresses through an explicit opt-in flag with a prominent warning.
  4. Replace the bare IP default with a trusted DNS hostname backed by a valid TLS certificate.
  5. Continue using Python's default certificate and hostname verification, and do not add certificate-bypass options.
  6. Rotate existing API keys and notification tokens because credentials previously sent over HTTP should be considered potentially exposed.
  7. Document the categories of payment data processed by the relay and obtain explicit user confirmation before directing callbacks through a third-party service.
  8. Consider short-lived credentials and a server-side credential revocation mechanism to reduce the impact of interception.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/cli.py:87
Finding

Relay credentials are stored without enforced restrictive file permissions

Content
View full analysis

Vulnerability Details

File Location: scripts/cli.py:87-93
Vulnerability Type: Insecure local storage of authentication credentials
Risk Level: Medium

Vulnerable Code

python
def save_config(cfg):
    """Save configuration to .alipay-notify.json in the current directory."""
    path = os.path.join(os.getcwd(), CONFIG_FILENAME)
    save_data = {k: v for k, v in cfg.items() if not k.startswith("_")}
    with open(path, "w", encoding="utf-8") as f:
        json.dump(save_data, f, indent=2, ensure_ascii=False)
    return path

The object passed to this function includes the authentication material:

python
new_cfg = {
    "server_url": server_url,
    "api_key": api_key,
    "notify_token": data["notify_token"],
    "notify_url": notify_url,
}

Technical Analysis

The configuration file is created with Python's ordinary open() function and inherits permissions from the process umask. The code neither creates the file with mode 0600 nor validates and corrects the permissions of an existing file.

On systems with permissive umasks, the resulting file may be readable by other local users or processes. Storing the file in the current project directory also raises the likelihood that it will be accidentally committed to source control, included in build artifacts, synchronized to shared storage, or exposed to project-scanning tools.

The file contains the relay API key and notification token. These are authentication secrets even though the CLI masks them when displaying configuration.

Attack Path

  1. A developer registers with the relay from a project directory.
  2. The CLI writes .alipay-notify.json using permissions determined solely by the current umask.
  3. Another local user or process reads the file if permissions allow it. Alternatively, the file is accidentally committed, archived, or uploaded with the project.
  4. The attacker extracts server_url, `api ...[truncated 734 chars]
Remediation
View remediation

Remediation Suggestions

  1. Create new configuration files atomically with owner-only permissions, such as mode 0600.
  2. Before replacing an existing file, verify its ownership and reject symbolic links or other unsafe file types.
  3. Apply os.chmod(path, 0o600) to existing configuration files after validating ownership.
  4. Prefer a dedicated per-user configuration directory rather than the current project directory.
  5. Add .alipay-notify.json to the repository's .gitignore and document that it contains secrets.
  6. Warn when the configuration file is tracked by Git or readable by group and other users.
  7. Provide a credential-rotation and revocation workflow for files that may have been disclosed.
  8. Where available, consider storing API credentials in an operating-system credential manager rather than a plaintext JSON file.

T08 · Insecure Dependencies

Note
Location
SKILL.md:54
Finding

Optional cryptography dependency is installed without version or integrity constraints

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:54
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Low

Vulnerable Instruction

bash
pip install cryptography

The same unpinned installation guidance also appears in README.md.

Technical Analysis

The Skill recommends installing cryptography without a version constraint, lock file, or package hash. The named dependency is a legitimate package and the project does not specify a suspicious package source. Nevertheless, the installation is not reproducible and delegates selection of executable third-party code to the package index state and the user's package-manager configuration at installation time.

If the upstream account, package index, configured mirror, or local package-manager configuration is compromised, a malicious or substituted release could execute code during installation or runtime. An incompatible future release could also change verification behavior or break the CLI.

Attack Path

  1. A user or Agent follows the Skill's optional verification setup instructions.
  2. The command resolves cryptography from the currently configured Python package index or mirror.
  3. A compromised index, mirror, upstream release process, or malicious package-manager configuration supplies an unsafe release.
  4. The package is installed and any installation-time or imported runtime code executes with the privileges of the user running pip.
  5. The malicious dependency can access files, environment variables, and network resources available to that user.

Impact Assessment

The maximum theoretical impact is arbitrary code execution with the privileges of the user performing the installation. Practical likelihood is reduced because cryptography is a well-known package and no evidence of an actively malicious dependency or source was found in the audited project.

The dependency is optional and only needed for ...[truncated 76 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin a reviewed version or narrowly bounded compatible version of cryptography.
  2. Provide a requirements or lock file containing cryptographic hashes for approved distributions.
  3. Install the dependency in an isolated virtual environment rather than the user's global Python environment.
  4. Use a trusted package index explicitly and avoid unreviewed mirrors.
  5. Establish a process for regularly reviewing and updating the pinned version to receive security fixes.
  6. Document the supported Python and dependency versions and verify them in automated tests.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README encourages a natural-language trigger phrase, “帮我接收支付宝异步通知”, that is broad enough to overlap with ordinary user requests about Alipay callback debugging. In an agent environment, this can cause the skill to activate implicitly and perform networked actions such as registration, listening, and handling payment notifications without a sufficiently explicit user opt-in to the third-party relay workflow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The AI Agent usage section tells users the agent will automatically complete registration, obtain a notify_url, listen, and verify signatures, but it does not prominently warn at that point that Alipay asynchronous notifications are transmitted to and stored on a third-party cloud relay. Because these payloads may contain sensitive transaction metadata, users could unknowingly expose payment data outside their local environment.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 93)May include surrounding context.

bash
# Claude Code
mkdir -p .claude/skills
git clone https://github.com/zhangke091/alipay-notify .claude/skills/alipay-notify

# Cursor

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
97% confidence
Finding

The skill instructs the agent to execute a local Python CLI, write configuration into the user's working directory, read/export notification contents, and connect to a hard-coded external relay service, yet it declares no explicit tool scope or permission boundaries. This creates an overbroad trust surface where an agent may perform network, file read, file write, and environment-dependent actions without user-visible authorization, increasing the chance of unintended data exposure or unsafe execution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest description forces a specific language/locale for the skill's instructions and user-facing behavior, and the rest of the document continues exclusively in Chinese. The policy explicitly says to flag language or locale constraints when the skill does not offer the user a language choice or opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and command descriptions are entirely in Chinese, and the same language-only behavior continues throughout help text and runtime prompts. This creates a language/locale policy concern because the skill imposes a specific language on all users without opt-in, fallback, or justification that it is limited to a Chinese-only audience.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest says the skill '仅依赖 Python 3' and advertises an automatic end-to-end flow including '本地验签'. However, the verify path imports the external cryptography package and explicitly tells the user to install it when missing, so the advertised verification workflow is not actually self-contained with only Python 3.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The argparse description, examples, and subcommand help strings are all presented only in Chinese. Because this is the primary interaction surface of the CLI, it effectively forces one locale without user choice or an explicitly documented regional limitation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.