T09 · Insecure Skill Coding Practices
- Location
scripts/publish.py:11- Finding
Directory Packaging Follows File Symlinks and May Upload Files Outside the Source Directory
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly does what it says, but its packaging and upload tool can unexpectedly send files outside the chosen prototype folder and can send API credentials over non-local HTTP.
Install only if you trust the prototype directories and server configuration. Avoid publishing untrusted folders or folders containing symlinks, review contents before upload, use HTTPS for any non-local ProtoHub URL, and confirm the prototype ID before updates because updates overwrite remote content.
scripts/publish.py:11Directory Packaging Follows File Symlinks and May Upload Files Outside the Source Directory
scripts/publish.py:34API Credentials and Prototype Data Can Be Transmitted over Plaintext HTTP
The skill advertises capabilities that read environment variables, access local files, and perform network operations, but it does not declare any explicit tool scope such as permissions or allowed-tools. That creates an authorization and transparency gap: an agent may invoke sensitive capabilities without clear least-privilege constraints or user-visible boundaries.
The usage guidance instructs the agent to publish and overwrite remote prototypes, including updating an existing prototype by ID, but does not prominently warn that these operations modify remote state. In an agent setting, insufficient disclosure around destructive or state-changing actions increases the risk of unintended overwrites, data loss, or changes to the wrong remote resource.
The manifest description is written in Chinese while the rest of the skill documentation is in English, and there is no indication that the user can choose their preferred language. This can violate language/locale policy when a skill implicitly forces or assumes a language without explicit opt-in or documented justification.
The script’s user-facing docstrings, CLI descriptions, status messages, and error output are written in Chinese throughout, including the main command description and runtime messages. This imposes a specific language on all users without offering a locale choice or documenting a justified regional restriction, which matches the natural-language locale policy concern.
No suspicious patterns detected.