T09 · Insecure Skill Coding Practices
- Location
scripts/fuzzy-match.mjs:144- Finding
Path Traversal Through Unvalidated Plan Filenames
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This planning skill is mostly coherent, but it needs review because it combines persistent reminders, external fund lookups, and local file mutation with weak scoping.
Install only if you want a Chinese-language planning assistant that stores durable plan state, runs heartbeat-style checks, and may send fund codes to a third-party market-data service. Review or fix the filename validation and require confirmation before bulk task completion or automatic trigger setup.
scripts/fuzzy-match.mjs:144Path Traversal Through Unvalidated Plan Filenames
The skill describes behaviors that require network access and likely environment/runtime capabilities (cron registration, external fund API fetches, heartbeat processing) but does not declare any explicit tool scope or allowed-tools boundary. This creates a permission ambiguity where an agent may perform external calls or automation beyond what the user clearly authorized, increasing the chance of unintended data exposure or unsafe side effects.
The skill advertises broad activation phrases like '今天计划任务' and '列出所有计划', which are common conversational expressions and could cause the skill to activate in situations where the user did not intend to invoke it. Accidental invocation is more dangerous here because the skill can read/write plan files and register reminders, so a trigger mismatch can lead to persistent state changes.
The workflow states that creating a plan will automatically generate files, register triggers to cron, and update indexes, but the skill does not present a clear up-front warning that these persistent modifications and automations will occur. Users may believe they are only drafting a plan, while the skill actually enables background reminders and writes durable state, which undermines informed consent.
The asset-tracking logic performs external fund API calls to retrieve NAV data, but the skill does not provide a privacy notice or explain what identifiers may be transmitted externally. Even if only fund codes are sent, usage timing and tracked holdings can reveal sensitive financial interests and behavioral patterns, especially when combined with heartbeat automation.
The natural-language completion feature allows commands like '所有/全部' to mark all pending tasks complete, which is an overly broad bulk action from ambiguous user text. In this skill's context, fuzzy matching plus batch completion can silently corrupt planning records, phase progress, and downstream review/automation logic based on task status.
The script performs outbound network requests to a third-party fund data service during heartbeat-driven snapshot updates, but this behavior is not disclosed in the skill description. Undisclosed external fetching can expose sensitive portfolio metadata through request timing/content, create unexpected data egress, and introduce integrity/availability risks if the remote endpoint is manipulated or unavailable.
Comments, examples, segmentation logic, trigger phrases, and CLI usage all assume Chinese text, and the matching behavior is built around Chinese-language phrases. This imposes a specific language/locale constraint without user opt-in or an explicit documented justification in the file.
The function modifies plan files on disk based solely on a text match and performs no built-in confirmation, authorization, or dry-run step before persisting changes. In this skill’s context, fuzzy matching can misidentify a task and silently mark the wrong task complete, causing integrity loss in long-term plans and potentially triggering downstream workflow decisions based on incorrect state.
This code file contains natural-language documentation and operational messages only in Chinese, including the module description and invocation instructions. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless clearly justified as region-specific.
The file’s natural-language content, including header comments, conflict reports, and CLI usage/output strings, is entirely in Chinese. This imposes a specific language on users without any opt-in, fallback, or documentation that the skill is intentionally region-specific, which matches the language/locale policy violation criteria.
The file's user-facing CLI output and descriptive comments are entirely in Chinese, including usage and alert messages, with no indication that another language is supported or that the Chinese-only constraint is intentional and justified. Under the policy, forcing a specific language without user opt-in can be a locale-policy violation.
The file defines and later uses a third-party market-data endpoint that is not evident from the stated long-term planning/reminder skill description. Hidden or undocumented network access expands the skill’s trust boundary, can leak user-linked financial interests such as fund codes, and introduces dependency on an external service without clear consent or disclosure.
This code performs outbound requests to a third-party financial API during trigger evaluation, giving the skill an undeclared external communication capability. Even if only fund codes are sent, those identifiers can reveal user holdings or watchlists, and the external dependency could be abused for tracking, reliability issues, or future scope creep.
This file contains natural-language comments and CLI strings entirely in Chinese, including the usage/help output shown to users. The skill does not provide any opt-in, alternative locale, or justification that it is intentionally region-specific, which conflicts with the language/locale policy for all file types.
The usage line defines broad natural-language triggers such as “开一个长期计划”, “今天计划任务”, and “列出所有计划”, which are generic phrases likely to overlap with ordinary user requests outside this specific skill. This can cause unintended invocation, leading the agent to expose or manipulate long-term-plan data when the user may have intended a normal planning conversation.
The skill description and command phrases are presented only in Chinese, with no indication that the user can choose another language or locale. Under the stated policy, language constraints should be opt-in or clearly justified, and no such choice or justification is provided here.
This code includes natural-language comments and CLI output entirely in Chinese, such as the module description and completion/status messages. Under the policy, forcing a specific language without user opt-in can be a locale-policy violation when no choice or justification is provided.
The request URL embeds a user-provided fund code and sends it to an external service without any disclosure in this file. While the data volume is small, fund codes may still expose sensitive investment preferences or holdings context, making this a privacy issue rather than a direct code-execution flaw.
All user-facing instructions and templates in the file are presented in Chinese, and there is no natural-language statement offering alternative languages or confirming that Chinese is required for a region-specific purpose. Under the stated policy, forcing a specific language without user opt-in can be a locale-policy violation.
No suspicious patterns detected.