Back to skill

Security audit

ziniao-sso-doc

Security checks for vulnerabilities and agentic risk

Overview

This documentation-only skill is coherent for Ziniao SSO integration, but it needs review because it normalizes sensitive SSO tokens in URLs and command arguments without adequate safety guidance.

Review this before installing or using it in an agent workflow. Treat API_Key, appAuthToken, and openapiToken as secrets; do not log full Schema URLs, paste them into shared channels, store them in command history, screenshots, support bundles, or analytics, and prefer the documented no-token local-login path where available. Require explicit user/admin approval before using debug ports, forced download paths, or no-prompt download behavior, and handle returned employee/account data as sensitive business data.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
reference/account-auth.md:123
Finding

Authentication Token Exposure Through Custom URLs and Process Arguments

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (9)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description is written as an instruction in Chinese and does not indicate that other languages are supported or that the user may choose a preferred language. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file includes example requests that transmit Authorization: Bearer {API_Key} and later describes retrieval of a user login token, but it does not warn readers that these credentials are sensitive secrets that should not be logged, shared, or embedded insecurely. Because the document directly instructs users how to obtain and use auth tokens, a user-facing warning about credential handling is expected under the missing-warning criteria for markdown files.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · reference/account-auth.md (reported line 41)May include surrounding context.

请求示例

bash
curl --location 'https://sbappstoreapi.ziniao.com/openapi-router/auth/get_app_token' \
--header 'Authorization: Bearer {API_Key}' \
--header 'Content-Type: application/json' \
--data-raw ''

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · reference/account-auth.md (reported line 101)May include surrounding context.

请求示例

bash
curl --location 'https://sbappstoreapi.ziniao.com/openapi-router/superbrowser/rest/v1/token/user-login' \
--header 'Authorization: Bearer {API_Key}' \
--header 'Content-Type: application/json' \
--data-raw '{"companyId":"15393571083459","userId":"15393571087094"}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This document describes APIs that enumerate employees, user IDs, phone numbers, account names, device IPs, and platform login identifiers, but provides no privacy, data-minimization, or access-control handling guidance. In an agent skill context, this can normalize collection and propagation of sensitive organizational data and increase the risk of unauthorized querying or mishandling by downstream users or agents.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · reference/account-crud.md (reported line 105)May include surrounding context.

请求示例

bash
curl --location 'https://sbappstoreapi.ziniao.com/openapi-router/superbrowser/rest/v1/erp/staff/list' \
--header 'Authorization: Bearer {API_Key}' \
--header 'Content-Type: application/json' \
--data-raw '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · reference/account-crud.md (reported line 176)May include surrounding context.

请求示例

bash
curl --location 'https://sbappstoreapi.ziniao.com/openapi-router/superbrowser/rest/v1/erp/store/list' \
--header 'Authorization: Bearer {API_Key}' \
--header 'Content-Type: application/json' \
--data-raw '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · reference/account-crud.md (reported line 245)May include surrounding context.

请求示例

bash
curl --location 'https://sbappstoreapi.ziniao.com/openapi-router/superbrowser/rest/v1/erp/user/stores' \
--header 'Authorization: Bearer {API_Key}' \
--header 'Content-Type: application/json' \
--data-raw '{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation explicitly describes a mode that suppresses the download path prompt and can force files into a specified directory. In an agent-consumable skill, this lowers user visibility and consent around filesystem writes, which can enable silent download behavior if an integrator or downstream automation uses these parameters without additional safeguards.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.