T09 · Insecure Skill Coding Practices
- Location
SKILL.md:95- Finding
Mandatory Collection and Plaintext Storage of Website Credentials
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This teaching-materials skill is useful in scope, but it asks for website passwords, stores them locally in plaintext, and automatically reuses them, which is too sensitive for a document-generation helper.
Install only if you are comfortable auditing and changing the credential workflow. Do not give the agent reusable website passwords or allow plaintext `accounts.json` storage; use manual login, browser sessions, or a secure credential manager instead. Also review external downloads, screenshots, and generated file locations before letting the skill fetch or save resources.
SKILL.md:95Mandatory Collection and Plaintext Storage of Website Credentials
integration_demo.md:90Unpinned Third-Party Package Execution Through npx
The skill instructs the agent to ask for users' third-party site usernames and passwords and save them to a local JSON file. Collecting raw credentials for unrelated external services is highly sensitive, materially expands the attack surface, and can lead to credential theft, reuse compromise, or unauthorized account access if the file is exposed or mishandled.
The skill directs users to provide usernames and passwords for external websites and store them locally, but does not present an adequate risk warning or safe secret-handling model. Users may be induced to disclose reusable credentials to the agent for a non-essential feature, creating a serious credential exposure risk.
The skill explicitly instructs the agent to request, store, and automatically use users' website credentials later. That is a direct secret-handling anti-pattern: it enables credential collection and reuse by the agent, which is dangerous even if framed as local-only because compromise of the host, logs, or files could expose the accounts.
The manifest description is entirely framed as a Chinese primary/secondary teaching document tool, which implies a fixed language/locale experience. The file does not state that the user may choose another language or that the Chinese-only scope is an intentional region-specific constraint.
The skill expands from document generation into automatic web search, downloading, and local persistence of third-party content. That creates unnecessary network and filesystem side effects, increases copyright/compliance risk, and can cause the agent to fetch and store untrusted external data without explicit per-action user consent.
The skill describes automatic search, download, and local saving of external resources without a clear, prominent warning that it will transmit queries externally and modify the filesystem. Lack of disclosure reduces informed user consent and makes unintended data transfer or storage more likely.
The skill claims the credentials are only for download automation, but it also directs persistent storage and later automatic reuse. This contradiction masks ongoing secret handling risk and normalizes repeated autonomous use of stored credentials, increasing the chance of silent misuse or compromise.
The skill mandates scraping, screenshot capture, and content extraction from arbitrary educational websites as part of normal operation. This broadens the agent's privileges beyond document generation and may lead to unsafe handling of untrusted content, policy violations, or unintended collection of protected material.
The manifest describes this skill as a tool for generating teaching documents such as PPTs, lesson plans, and student worksheets. This file documents additional behavior where the skill analyzes content, decides when a mind map is needed, and invokes a separate diagram-generator skill to produce diagram artifacts, which is broader than the stated document-generation scope.
The workflow states that PPT and diagram files are saved automatically, but does not present this as a user-consented filesystem write. Silent local file creation can surprise users, overwrite existing content, or leave sensitive educational materials on disk in locations they did not intend.
The documentation references user-local MCP configuration and a separate skill, which implies this skill may rely on local environment details and cross-skill resources outside its core teaching-material scope. That can enable unintended capability discovery, environment probing, or dependency on local configuration without clear user consent, increasing attack surface if the referenced tool or config is manipulated.
Referencing a concrete local skill path reveals the existence and naming of another installed skill, which is a form of environment and capability enumeration. In isolation this is limited, but combined with other behaviors it can help an attacker map local tooling and target cross-skill abuse or dependency confusion.
- 思维导图使用指南: `references/mindmap_guide.md`
- 课件制作指南: `references/ppt_guide.md`
- diagram-generator 技能文档: `~/.workbuddy/skills/diagram-generator/SKILL.md`
## 常见问题
The entire skill content is written exclusively in Chinese and does not offer any language or locale choice. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is explicitly documented and justified.
The resource acquisition section encourages direct download, web clipping, screenshots, and content extraction from third-party platforms without any warning about copyright, consent, privacy, or site restrictions. This omission makes risky behavior seem endorsed and increases the chance that users or downstream agents will collect and reuse protected or sensitive material improperly.
The guidance explicitly recommends acquiring third-party educational content through screenshot capture and using scrape_url to save external pages, which can facilitate bypassing normal download controls and copying content outside intended platform workflows. In a document-generation skill, this expands the skill from creating original teaching materials into potentially unauthorized content acquisition, creating copyright, terms-of-service, and data-handling risk.
The guide instructs the skill to go beyond document generation by invoking an external MCP diagram service and writing generated artifacts to disk. This expands the trust boundary: user-controlled lesson content may be sent to another service and persisted locally without clear authorization, validation, or data-handling constraints, creating privacy, integrity, and unintended side-effect risks.
The document title and all instructions are written in Chinese, and the guidance uses mandatory language such as '必须使用' without indicating that other languages/locales are optional. This can violate language/locale policy when a skill forces a specific language without user opt-in or documented regional justification.
SQP-3 applies to natural-language policy issues in any file. This document consistently presents the skill experience in Chinese and all example requests are Chinese-only, with no indication that other languages are supported or that Chinese is an optional locale choice.
The manifest focuses on generating teaching documents like PPTs, lesson plans, and guides. Here the skill is documented as outputting extra diagram files such as .md and .excalidraw artifacts, which are separate deliverables not mentioned in the manifest description.
Specifying a default local save directory without a clear warning or opt-in normalizes automatic storage of generated output on the user's machine. While lower severity than arbitrary writes, it still creates privacy and clutter risks and may expose student or teacher content in predictable locations.
This markdown file is entirely presented in Chinese and does not indicate that other languages are supported or that Chinese is optional. Under the policy rule for language or locale constraints, this can be a natural-language policy issue when no user opt-in or justification is provided.
Using a fixed local path for generated diagrams introduces an unnecessary filesystem side effect and can expose data to other local users/processes, overwrite existing files, or fail unpredictably across environments. Even if intended for convenience, hardcoded output locations reduce user control and increase the chance of accidental data leakage or unsafe file handling.
The entire template is written in Chinese and presented as a universal teaching-design template, with no indication that language selection is optional. Under the policy criteria, this can be a natural-language locale constraint because it effectively enforces a specific language without user opt-in or a documented region-specific justification.
No suspicious patterns detected.