Back to skill

Security audit

超能文献-AI文档翻译

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Suppr document-translation API reference; it sends documents or document URLs to Suppr as expected for translation, with no hidden code or persistence.

Install only if you are comfortable sending documents, document URLs, and task metadata to Suppr's API. Do not submit confidential files, internal URLs, or URLs containing access tokens unless you have approval and understand the provider's retention and privacy terms. Keep the bearer API key scoped and protected.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (9)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly sends user-provided documents or document URLs to a third-party translation service, but the description does not warn users that their files and links will leave the local environment. This creates a meaningful privacy and data-handling risk, especially for sensitive or proprietary documents, because users may invoke the skill without informed consent about external transmission.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The file-upload endpoint sends document contents directly to an external service over the network. Although this is expected for a translation integration, it is dangerous when handling sensitive files because entire document contents may be disclosed to a third-party provider.

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

1. 创建翻译任务(文件上传)

text
POST https://api.suppr.wilddata.cn/v1/translations
Content-Type: multipart/form-data
Authorization: Bearer <your_api_key>

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The JSON task-creation endpoint accepts a file_url, causing the third-party service to retrieve or process a user-specified document from an external location. This can disclose private document URLs, access tokens embedded in URLs, or internal resource references to the provider.

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

仅支持 file_url 模式。

text
POST https://api.suppr.wilddata.cn/v1/translations
Content-Type: application/json
Authorization: Bearer <your_api_key>

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

3. 获取翻译任务详情

text
GET https://api.suppr.wilddata.cn/v1/translations/{task_id}
Authorization: Bearer <your_api_key>

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

3. 获取翻译任务详情

text
GET https://api.suppr.wilddata.cn/v1/translations/{task_id}
Authorization: Bearer <your_api_key>

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 84)May include surrounding context.

3. 获取翻译任务详情

text
GET https://api.suppr.wilddata.cn/v1/translations/{task_id}
Authorization: Bearer <your_api_key>

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 156)May include surrounding context.

3. 获取翻译任务详情

text
GET https://api.suppr.wilddata.cn/v1/translations/{task_id}
Authorization: Bearer <your_api_key>

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The curl example visibly instructs users to submit a remote document URL to the external API, reinforcing the external transmission behavior without accompanying privacy guidance. This increases the chance that users share confidential document locations or contents unknowingly.

Content

Scanner excerpt · SKILL.md (reported line 150)May include surrounding context.

bash
# 步骤 1:创建任务
curl -X POST https://api.suppr.wilddata.cn/v1/translations \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"file_url": "https://example.com/paper.pdf", "from_lang": "en", "to_lang": "zh-cn"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The curl example visibly instructs users to submit a remote document URL to the external API, reinforcing the external transmission behavior without accompanying privacy guidance. This increases the chance that users share confidential document locations or contents unknowingly.

Content

Scanner excerpt · SKILL.md (reported line 150)May include surrounding context.

bash
# 步骤 1:创建任务
curl -X POST https://api.suppr.wilddata.cn/v1/translations \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"file_url": "https://example.com/paper.pdf", "from_lang": "en", "to_lang": "zh-cn"}'

Static analysis

No suspicious patterns detected.