扫描报告
65 /100
maxianer
中华术数推演系统(八字/紫微/六爻/梅花/奇门/称骨/铁板/解梦)
Undeclared external data transmission to a hardcoded IP address sends users' birth dates, gender, names, and locations to 34.84.114.113 without any disclosure in SKILL.md.
不要安装此技能
Remove the hardcoded IP address. Document all external API calls and data transmitted. Use environment-based configuration exclusively. Do not send PII (names, birth dates, locations) to external servers without explicit disclosure.
攻击链 3 步
◎
入口 User invokes skill for fortune-telling with birth date, time, gender, name, location
SKILL.md:1⬡
提权 Script sends all PII (birthDate, birthHour, gender, birthPlace, name) as JSON POST body to external IP
scripts/maxianer-call.mjs:47◉
影响 Personal data (names, birth dates, locations, gender) transmitted to hardcoded IP
34.84.114.113 without user disclosure scripts/maxianer-call.mjs:47安全发现 4 项
| 严重性 | 安全发现 | 位置 |
|---|---|---|
| 高危 | Undeclared external data transmission 数据外泄 | scripts/maxianer-call.mjs:47 |
| 高危 | Doc-to-code mismatch — external network behavior not declared 文档欺骗 | SKILL.md:1 |
| 中危 | Hardcoded IP address with no DNS or config fallback 敏感访问 | scripts/maxianer-call.mjs:13 |
| 低危 | Embedded default API key in source 凭证窃取 | scripts/maxianer-call.mjs:14 |
| 资源类型 | 声明权限 | 推断权限 | 状态 | 证据 |
|---|---|---|---|---|
| 网络访问 | NONE | WRITE | ✗ 越权 | scripts/maxianer-call.mjs:47 |
1 高危 2 项发现
高危 IP 地址 硬编码 IP 地址
34.84.114.113 scripts/maxianer-call.mjs:13 中危 外部 URL 外部 URL
http://34.84.114.113:3333 scripts/maxianer-call.mjs:13 目录结构
2 文件 · 6.9 KB · 181 行 Markdown 1f · 107L
JavaScript 1f · 74L
├─
▾
scripts
│ └─
maxianer-call.mjs
JavaScript
└─
SKILL.md
Markdown
安全亮点
✓ No reverse shell, RCE, or arbitrary code execution patterns detected
✓ No base64/encoded payload execution found
✓ No credential harvesting from ~/.ssh, ~/.aws, or .env files
✓ No supply-chain risk from external dependencies (no package.json or dependencies)
✓ JSON inputs are validated before use