T09 · Insecure Skill Coding Practices
- Location
scripts/_shared.mjs:25- Finding
Bearer Credentials and Sensitive Personal Data Can Be Transmitted over Plaintext HTTP
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill matches its paid report purpose, but it needs review because it can send very sensitive personal data and bearer credentials to a configurable endpoint that may use plaintext HTTP.
Install only in a controlled environment with an operator-approved HTTPS Life Book endpoint. Do not pass API keys or task tokens on the command line; use a protected secret mechanism where possible. Before running report creation, make sure the user explicitly understands what sensitive personal data will be sent, where it will be sent, and that a paid task or payment-confirmation workflow may begin.
scripts/_shared.mjs:25Bearer Credentials and Sensitive Personal Data Can Be Transmitted over Plaintext HTTP
scripts/_shared.mjs:48Secret-Bearing Command-Line Arguments Can Leak through Process Inspection and Execution Logs
Referenced artifact was not completely inspected
node scripts/check-health.mjs
Referenced artifact was not completely inspected
node scripts/create-report-task.mjs \
Referenced artifact was not completely inspected
node scripts/confirm-manual-payment.mjs \
Referenced artifact was not completely inspected
node scripts/get-report-task.mjs \
Referenced artifact was not completely inspected
node scripts/get-report-result.mjs \
Referenced artifact was not completely inspected
node scripts/wait-report-result.mjs \
Referenced artifact was not completely inspected
- `create-intake.mjs`
Referenced artifact was not completely inspected
- `create-order.mjs`
Referenced artifact was not completely inspected
- `get-order.mjs`
The README explicitly instructs the agent to collect and transmit highly sensitive personal data, including birth details, geolocation, life history, and core personal problems, but does not present any privacy warning, data-handling notice, minimization guidance, or consent language specific to sensitive-data transmission. In the context of a paid report-generation workflow, this increases the chance that operators or end users will submit intimate personal data without understanding retention, sharing, or exposure risks, which can lead to privacy harm and regulatory issues if the service or integration is compromised or misused.
The skill description is broad enough to trigger on general requests to 'buy' or 'generate' a Life Book report, which can cause the agent to enter a payment-oriented workflow without clear user intent confirmation. In a skill that can create paid tasks and handle payment state, overbroad activation increases the risk of unintended commercial actions and unnecessary collection of sensitive intake data.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
Use `--channel wechat` or `--channel evm` when appropriate.
This only marks the order as awaiting operator review. It does not auto-confirm receipt.
### 6. Check Task Status
The instruction 'Speak Chinese unless the user asks otherwise' sets a default language policy that forces a specific language absent user consent. This is a natural-language policy issue because the skill does not first offer a language choice or require locale-specific context.
The default prompt encourages invoking the skill whenever a user wants to create or retrieve a Life Book report, but it does not define clear eligibility, consent, billing, or confirmation boundaries. In a paid task-generation context, broad implicit triggering can cause unintended purchases, premature task creation, or disclosure/retrieval of sensitive generated reports without sufficiently explicit user intent.
This example data uses Chinese text throughout and fixes the timezone to Asia/Shanghai, which implies a specific language/locale context without any visible opt-in or alternative. The policy forbids forcing a specific language or locale unless the constraint is explicitly documented and justified.
This code sends the user-provided intake JSON to a remote API endpoint via an HTTP POST request. In this file there is no confirmation prompt, user-facing log/print, or explanatory comment/docstring warning that supplied data will be transmitted over the network.
This script performs a network call and transmits a task bearer token in the Authorization header. In this file there is no confirmation prompt, visible user-facing notice, or explanatory comment/docstring disclosing that credential-backed polling of a remote endpoint occurs.
The natural-language instructions throughout the README are presented only in Chinese, which effectively forces a specific language for users of the skill. The file does not offer an alternative language, opt-in language selection, or a documented justification that the skill is intended only for a Chinese-language audience.
The short description is in Chinese while the default prompt is in English, but the manifest does not indicate whether language selection is based on user preference or locale. This can create a language-policy ambiguity because the skill appears to impose or assume language behavior without explicit opt-in.
No suspicious patterns detected.