T09 · Insecure Skill Coding Practices
- Location
SKILL.md:14- Finding
Execution of an Unreviewable External Binary with Access to Sensitive Credentials
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill has a coherent GA4 analytics purpose, but it tells the agent to run an unbundled absolute-path executable that would receive Google Analytics credential access.
Review this before installing. Only use it if you already trust the exact ga4-analytics executable at that path, can verify its integrity, and provide a least-privilege read-only Google service account limited to the intended GA4 property. Prefer a package that includes auditable source or a pinned, hash-checked binary.
SKILL.md:14Execution of an Unreviewable External Binary with Access to Sensitive Credentials
The manifest description and the entire usage guidance are written exclusively in German, including directive phrases for when to use the skill. This creates a natural-language locale constraint without any opt-in or documented justification that the skill is intentionally German-only.
No suspicious patterns detected.