Low Risk — Risk Score 20/100
Last scan:2 days ago Rescan
20 /100
company-information
企业舆情监测与风险预警技能 - Enterprise sentiment monitoring and risk early warning skill
Legitimate enterprise sentiment monitoring skill with minor concerns about hardcoded IP address and broad API endpoint documentation.
Skill Namecompany-information
Duration33.8s
Enginepi
Safe to install
Consider using domain name instead of hardcoded IP for API endpoint. Verify FEEDAX API provider legitimacy before production use.

Findings 2 items

Severity Finding Location
Medium
Hardcoded IP Address
API endpoint uses hardcoded IP address (221.6.15.90:18011) instead of domain name. This is unusual for commercial APIs and could indicate non-reputable service.
FEEDAX_BASE_URL = "http://221.6.15.90:18011"
→ Use domain name for API endpoint. Verify FEEDAX service legitimacy before deployment.
scripts/query_company_information.py:33
Low
API Key Configuration Flexibility
Script accepts API key from multiple sources (env var, config file, CLI arg) which increases attack surface slightly.
Multiple API key configuration methods
→ Document security guidelines for API key handling in production environments.
scripts/query_company_information.py:340
ResourceDeclaredInferredStatusEvidence
Network READ READ ✓ Aligned requests.post() to FEEDAX API
Filesystem WRITE WRITE ✓ Aligned generate_csv() and generate_description() functions write CSV/MD files
Shell WRITE WRITE ✓ Aligned SKILL.md documents CLI usage with python3 scripts/
Environment READ READ ✓ Aligned os.environ.get('FEEDAX_API_KEY') - only reads provided API key
Skill Invoke NONE NONE No skill invocation detected
1 High 8 findings
📡
High IP Address 硬编码 IP 地址
221.6.15.90
README.md:225
🔗
Medium External URL 外部 URL
https://blog.gitee.com
README.en.md:32
🔗
Medium External URL 外部 URL
https://gitee.com/explore
README.en.md:33
🔗
Medium External URL 外部 URL
https://gitee.com/gvp
README.en.md:34
🔗
Medium External URL 外部 URL
https://gitee.com/help
README.en.md:35
🔗
Medium External URL 外部 URL
https://gitee.com/gitee-stars/
README.en.md:36
🔗
Medium External URL 外部 URL
https://www.feedax.cn
README.md:21
🔗
Medium External URL 外部 URL
http://221.6.15.90:18011
scripts/query_company_information.py:35

File Tree

4 files · 43.2 KB · 1358 lines
Markdown 3f · 843L Python 1f · 515L
├─ 📁 scripts
│ └─ 🐍 query_company_information.py Python 515L · 19.8 KB
├─ 📝 README.en.md Markdown 36L · 963 B
├─ 📝 README.md Markdown 237L · 6.4 KB
└─ 📝 SKILL.md Markdown 570L · 16.1 KB

Dependencies 1 items

PackageVersionSourceKnown VulnsNotes
requests * pip No Version not pinned - consider pinning for reproducibility

Security Positives

✓ Code is readable and matches documented functionality
✓ No credential exfiltration - API keys only used for authentication
✓ No reverse shell, C2, or data theft patterns detected
✓ Filesystem access limited to output directory (CSV/MD files)
✓ No hidden functionality or suspicious code patterns
✓ Uses standard requests library for HTTP calls
✓ Proper error handling with timeout and exception management