T09 · Insecure Skill Coding Practices
- Location
README.md:85- Finding
API keys may be exposed through chat history, shell history, and process arguments
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a coherent DataQuant API connector, with the main caution that its docs encourage API-key handling methods that can leak the key into chat or shell history.
Install only if you trust DataQuant and need this data connector. Prefer setting DATAQUANT_API_KEY through a protected environment variable or secret store; avoid pasting real API keys into chat or passing them with --api-key. Review any generated backtest code before allowing an agent to run it, and consider using a virtual environment with pinned dependencies.
README.md:85API keys may be exposed through chat history, shell history, and process arguments
SKILL.md:19Third-party dependency installation is not version-pinned or integrity-verified
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
def _request(endpoint, params=None, api_key=None):
key = api_key or get_api_key()
url = f"{BASE_URL}{endpoint}"
resp = requests.get(url, params=params, headers={"X-API-Key": key}, timeout=30)
resp.raise_for_status()
return resp.json()
Referenced artifact was not completely inspected
| `SKILL.md` | ✅ |
The README states that the AI will automatically read the skill definition, create directory structures, write files, and later handle script generation and execution, but it provides no trust boundary warning, review step, or consent checkpoint. This can normalize letting an agent write and run code from remotely supplied content, which increases the risk of unsafe file modifications, execution of unreviewed code, or supply-chain abuse if the skill source is tampered with. Because this skill is specifically framed as an automated backtesting pipeline, the context makes the missing warnings more dangerous, not less.
The README explicitly instructs users to paste their DataQuant API key directly into an AI assistant. That encourages disclosure of a reusable secret into a conversational system that may log, retain, or further expose credentials across tools, transcripts, or downstream integrations. In this skill context, the risk is elevated because the assistant is also positioned to automate data retrieval and execution workflows, increasing the chance the key is propagated beyond the user's intent.
The skill documents capabilities that require environment access and outbound network access, but it does not declare an explicit tool scope such as permissions or allowed-tools. That creates a governance gap: an agent platform may over-grant or ambiguously grant access, increasing the chance of unintended secret access or network egress beyond what users expect.
The examples repeatedly pass the API key directly on the command line via --api-key KEY, which can expose credentials through shell history, process listings, logs, transcripts, or agent telemetry. In a skill specifically designed for API-backed data retrieval, this context makes the issue more dangerous because users are likely to copy-paste the examples verbatim with real secrets.
The title and surrounding documentation are written entirely in Chinese, which signals a fixed language choice in the skill's natural-language materials. There is no indication that users may select another language or that the Chinese-only requirement is justified by a region-specific compliance need.
This code file contains user-facing help strings in Chinese for the --adj and --date options while the rest of the CLI description and help text is in English. That imposes a locale/language choice on users without opt-in or documentation that the tool is intended for Chinese-speaking users only.
No suspicious patterns detected.