T09 · Insecure Skill Coding Practices
- Location
src/config.js:8- Finding
API key may be transmitted to an untrusted or plaintext endpoint
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This stock-analysis skill is mostly coherent, but it needs review because it sends an API key to a configurable server and can mutate or delete remote presets without strong URL and identifier validation.
Install only if you trust the configured API server and can use a narrowly scoped, revocable API key. Prefer HTTPS for any remote API endpoint, avoid using this with untrusted prompts or pasted identifiers, and confirm any hot-factor create/update/sort/delete action before letting the agent run it.
src/config.js:8API key may be transmitted to an untrusted or plaintext endpoint
src/tools.js:30Unencoded path identifiers allow authenticated API route manipulation
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
export STOCK_API_TIMEOUT="30"
### 方式二:.env 文件
```bash
cp .env.example .env
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
export STOCK_API_TIMEOUT="30"
### 方式二:.env 文件
```bash
cp .env.example .env
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
cp .env.example .env
# 编辑 .env 填写实际配置
Referenced artifact was not completely inspected
node src/main.js <tool_name> '<JSON 参数>'
Referenced artifact was not completely inspected
node src/main.js <tool_name> '<JSON 参数>'
Referenced artifact was not completely inspected
node src/main.js <tool_name> '<JSON 参数>'
Referenced artifact was not completely inspected
node src/main.js <tool_name> '<JSON 参数>'
Referenced artifact was not completely inspected
node src/main.js <tool_name> '<JSON 参数>'
Referenced artifact was not completely inspected
node src/main.js <tool_name> '<JSON 参数>'
Referenced artifact was not completely inspected
node src/main.js <tool_name> '<JSON 参数>'
Referenced artifact was not completely inspected
node src/main.js <tool_name> '<JSON 参数>'
Referenced artifact was not completely inspected
node src/main.js <tool_name> '<JSON 参数>'
Referenced artifact was not completely inspected
node src/main.js <tool_name> '<JSON 参数>'
Referenced artifact was not completely inspected
node src/main.js <tool_name> '<JSON 参数>'
Referenced artifact was not completely inspected
node src/main.js <tool_name> '<JSON 参数>'
Referenced artifact was not completely inspected
node src/main.js <tool_name> '<JSON 参数>'
Referenced artifact was not completely inspected
node src/main.js <tool_name> '<JSON 参数>'
Referenced artifact was not completely inspected
node src/main.js <tool_name> '<JSON 参数>'
Referenced artifact was not completely inspected
node src/main.js <tool_name> '<JSON 参数>'
Referenced artifact was not completely inspected
node src/main.js <tool_name> '<JSON 参数>'
Referenced artifact was not completely inspected
node src/main.js <tool_name> '<JSON 参数>'
Referenced artifact was not completely inspected
node src/main.js <tool_name> '<JSON 参数>'
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
import { fileURLToPath } from "url";
const __dirname = dirname(fileURLToPath(import.meta.url));
loadDotenv({ path: resolve(__dirname, "..", ".env") });
export const API_BASE_URL = (process.env.STOCK_API_BASE_URL || "").replace(/\/+$/, "");
export const API_KEY = process.env.STOCK_API_KEY || "";
The README states that mentioning broad trigger phrases like “股票筛选”, “热门因子”, “股票分析”, or “抖音热点” will cause the agent to automatically invoke tools. Overly broad natural-language triggers can cause unintended tool execution from casual conversation, quoted text, or adversarial prompt content, increasing the risk of data access or outbound API calls without clear user intent.
The skill explicitly requires environment variables and invokes a Node CLI that will make outbound API requests, but it does not declare any explicit tool scope such as permissions or allowed-tools. This weakens containment and reviewability: an agent may invoke a network-capable skill with access to secrets without a clearly documented or enforced boundary, increasing the chance of unintended data access or transmission.
No suspicious patterns detected.