T09 · Insecure Skill Coding Practices
- Location
SKILL.md:14- Finding
Operational Portal Access Uses Unencrypted HTTP
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a straightforward carrier logistics analysis helper, but users should avoid using its plaintext HTTP portal links for sensitive operational data.
Install only if you intend the agent to read the specific spreadsheet you provide and use the listed Jingwe/JDL portal pages for carrier analysis. Prefer verified HTTPS access to the portal, confirm the destination before downloading anomaly details, and avoid exposing sensitive carrier or operational data over plaintext HTTP.
SKILL.md:14Operational Portal Access Uses Unencrypted HTTP
The activation condition is overly broad: any query about a carrier's logistics index score could trigger the skill without clearly constraining required inputs, scope, or safety checks. In a skill that reads local files and initiates web/download actions, ambiguous invocation increases the chance of unintended file access, accidental external navigation, or execution in the wrong user context.
The skill instructs the agent to read local Excel/CSV files, access external websites, and trigger downloads, but it does not present explicit user warnings, consent boundaries, or restrictions on what files/URLs may be touched. This creates a real risk of unauthorized local data exposure, unintended network access, and downloading sensitive operational details, especially because the skill also references anomaly-detail exports tied to carrier and date filters.
No suspicious patterns detected.