Back to skill

Security audit

Agent Migration Pack Template

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent agent-migration template, but it exposes a real-looking upload token and includes/exports sensitive private data in ways users should review before installing.

Do not install this version without reviewing it carefully. The publisher should rotate and remove the exposed upload token, replace real private examples with synthetic data, and make sensitive exports opt-in. If you use it locally, do not run the upload command, inspect generated packages before sharing, and remove raw memory, personal schedules, contact details, and _extracted_content fields.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL-INFO.md:159
Finding

Hardcoded Bearer Credential in an External Upload Command

Content
View full analysis

Vulnerability Details

File Location: SKILL-INFO.md, lines 159-163
Vulnerability Type: Hardcoded authentication credential
Risk Level: High

Vulnerable Code

bash
curl -X POST "https://xiaping.coze.site/api/upload" \
  -H "Authorization: Bearer agent-world-e4a41c3dd47b88c55af0729dbb98cff4d98efd3cbce461b0" \
  -F "file=@agent-migration-pack.zip" \
  -F "skill_id=c7363f71-212f-4b34-9551-f72bf5d47044" \
  -F "changelog=v1.0.5更新内容"

Technical Analysis

The documentation contains a plaintext bearer token that appears to authenticate requests to an external upload API. Anyone with read access to the repository, distributed skill package, generated documentation, logs, or cached audit output can recover and attempt to reuse this credential.

Bearer credentials grant access based solely on possession. Unlike an illustrative placeholder, this value has the structure of a concrete credential and is directly embedded in an executable command. The project also supplies the associated API endpoint and skill identifier, making attempted reuse straightforward.

Whether the credential is currently valid cannot be established through static analysis. Nevertheless, publishing a potentially active secret is itself an insecure credential-management practice and requires immediate revocation.

Attack Path

  1. An attacker obtains a copy of the public or internally distributed skill package.
  2. The attacker extracts the bearer token, endpoint, and skill identifier from SKILL-INFO.md.
  3. The attacker prepares a modified or malicious archive named agent-migration-pack.zip.
  4. The attacker reproduces the documented curl request with the exposed credential.
  5. If the API accepts the token and does not independently enforce ownership or artifact signing, the attacker uploads or replaces content associated with the referenced skill.
  6. Downstream users may then receive unauthorized content under the identit ...[truncated 607 chars]
Remediation
View remediation

Remediation Suggestions

  1. Revoke and rotate the exposed token immediately; deleting it from the current revision is insufficient because it may remain in repository history, caches, and released packages.

  2. Review external API audit logs for uploads or other requests made with this credential.

  3. Replace the literal value with a non-secret placeholder, such as:

    bash
    curl -X POST "https://xiaping.coze.site/api/upload" \
      -H "Authorization: Bearer ${XIAPING_UPLOAD_TOKEN}" \
      -F "file=@agent-migration-pack.zip" \
      -F "skill_id=${SKILL_ID}" \
      -F "changelog=${CHANGELOG}"
    
  4. Obtain the token at runtime from an approved secret manager or protected environment variable. Never store it in documentation, templates, examples, archives, or source control.

  5. Configure a short expiration period, minimum required scope, per-publisher authorization, and artifact-signing checks on the server.

  6. Add automated secret scanning to pre-commit hooks and CI, including repository-history scanning.

  7. Purge the credential from prior commits and released archives after rotation.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate-pack.py:115
Finding

Automatic Export of Agent Memory Without Secret or Privacy Filtering

Content
View full analysis

Vulnerability Details

File Location: scripts/generate-pack.py, lines 115-132
Vulnerability Type: Unfiltered sensitive-data export
Risk Level: Medium

Vulnerable Code

python
memory_file = self.find_file("MEMORY.md")

memory = {
    "template_version": self.VERSION,
    "file_type": "memory",
    "extracted_at": self.timestamp,
    "source_files": [],
    "data": {}
}

if memory_file:
    memory["source_files"].append(str(memory_file))
    # Try to parse the MEMORY.md structure
    content = self.read_text_file(memory_file)
    # More complex parsing logic could be added here
    memory["data"]["_extracted_content"] = content[:500] + "..." if len(content) > 500 else content
else:
    memory["data"]["_note"] = "MEMORY.md was not found; complete it manually using MIGRATION-GUIDE.md"

Technical Analysis

The generator automatically locates MEMORY.md, reads its contents, and copies up to the first 500 characters into MEMORY/core-memory.json. It also records the source path. No consent prompt, field-level allowlist, secret detection, redaction, or sensitivity review occurs before the output is written.

Agent memory commonly contains personal details, conversation-derived information, internal project context, access tokens, or prompt material. A 500-character limit is not a security control: credentials and personally identifiable information are often short and frequently appear near the beginning of a file.

The broader workflow tells users to package and upload the generated output. Although the generated README advises users to inspect temporary fields, the script produces the sensitive field before that review and does not prevent accidental packaging or sharing. Documentation-only warnings do not reliably enforce data minimization.

Attack Path

  1. Sensitive information or a credential is present near the beginning of a workspace MEMORY.md.
  2. A user runs `python ...[truncated 1277 chars]
Remediation
View remediation

Remediation Suggestions

  1. Do not export raw memory content by default. Generate an empty structured template and require explicit user selection of fields.
  2. Add an interactive confirmation that displays the source file, destination, sensitivity classification, and exact fields selected for export.
  3. Parse memory into a strict allowlisted schema rather than copying arbitrary text.
  4. Scan selected content for common secret formats, authorization headers, private keys, tokens, passwords, email addresses, and other sensitive identifiers. Fail closed when a likely secret is detected.
  5. Apply deterministic redaction before writing any output and avoid recording unnecessary absolute or workspace-specific source paths.
  6. Mark generated sensitive files with restrictive permissions, such as owner-only access where supported.
  7. Add a mandatory pre-package privacy validation step. Packaging should fail until temporary fields such as _extracted_content are removed or explicitly approved.
  8. Add tests proving that representative API keys, bearer tokens, private keys, and personal data are not copied into generated packages.

T09 · Insecure Skill Coding Practices

Warning
Location
EXAMPLES/xiaoyi-example/owner.json:1
Finding

Private Personal and Schedule Information Included in the Distributed Example

Content
View full analysis

Vulnerability Details

File Location: EXAMPLES/xiaoyi-example/owner.json, lines 1-33
Vulnerability Type: Plaintext sensitive-data exposure
Risk Level: Medium

Vulnerable Code

json
{
  "file_type": "owner",
  "sensitivity": "private",
  "name": "林锋",
  "location": "珠海",
  "profession": "工程管理/信息化项目建设",
  "interests": ["网球", "高尔夫", "AI", "科技"],
  "education": "计算机科学与技术",
  "family": {
    "spouse_location": "美国",
    "spouse_business": "二手奢侈品生意"
  },
  "schedule": {
    "周一晚上": "陪小孩阅读",
    "周三晚上": "陪小孩阅读",
    "周四晚上": "陪小孩学数学",
    "周二周五周日20:30": "运动时间"
  },
  "preferences": {
    "style": "简洁直接,结构化数据,明确建议",
    "notification": "重要消息及时,日常不打扰",
    "decision": "提供选项对比,不替做决定"
  },
  "key_business": {
    "type": "二手奢侈品跨境套利",
    "model": "中国买→美国卖",
    "brands": ["LV", "Chanel", "Dior", "Gucci", "YSL", "Prada", "Loewe"],
    "price_min": {"LV_Chanel_Dior": 200, "Gucci_YSL_Prada_Loewe": 150},
    "verification": "优先验货宝,>1000元必须验"
  },
  "investment_interests": ["A股科技股", "港股期权", "原油期货", "三星原油ETF"],
  "learning_platform": "EntroCamp"
}

Technical Analysis

A file explicitly marked with "sensitivity": "private" is included in the distributed example tree. It contains a named person's location, profession, education, family circumstances, recurring family and exercise schedule, business model, transaction thresholds, and investment interests.

Static analysis cannot determine whether the example represents a real person or synthetic test data. However, the package presents the information as a concrete owner profile rather than clearly anonymized placeholder content. Distributing private-profile data creates an avoidable privacy risk and conflicts with the project's own sensitivity labeling and guidance to review private information before sharing.

The migration packer's includes the entire EXAMPLES/ directory recursively, so this file is incorporate ...[truncated 1305 chars]

Remediation
View remediation

Remediation Suggestions

  1. Confirm whether every person represented in example files is fictional or has provided explicit, informed consent for this exact distribution.
  2. Replace names and all potentially identifying details with unmistakably synthetic values, such as Example User, Example City, and non-actionable sample schedules.
  3. Remove recurring schedule details, family locations, business thresholds, and investment profiles from public examples unless strictly necessary.
  4. Add a prominent declaration that examples are synthetic and must never be populated with real personal data.
  5. Exclude sensitive example profiles from release archives by default. Maintain a minimal sanitized fixture for format demonstration.
  6. Add automated privacy checks that reject release artifacts containing files labeled private or sensitive unless they are explicitly approved synthetic fixtures.
  7. If the data is real, remove it from repository history and prior release archives, then assess notification obligations under applicable privacy policies and law.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (31)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The documentation embeds what appears to be a live Bearer token directly in a curl example, which is a credential exposure issue. Anyone who reads or copies this file may reuse the token to upload or modify skill content, and the surrounding privacy guidance makes the contradiction especially risky because users may trust the document as security-conscious.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Including an upload command with an embedded bearer token without any warning about credential handling encourages unsafe copy-paste behavior and normalizes secret leakage. In this skill context, the command targets a real upload endpoint for agent migration artifacts, so leaked credentials could enable unauthorized uploads, tampering, or account misuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This manifest contains natural-language fields such as "source" and "description" in Chinese, which imposes a specific language on users reading or operating from the catalog. The file does not indicate that the catalog is intentionally Chinese-only, region-specific, or that alternative language support is available.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Multiple user-facing descriptions in the skills list are written only in Chinese, but the manifest gives no indication that this is a justified locale-specific catalog. Without an explicit opt-in or documented locale scope, this is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

This identity manifest uses Chinese for the name, meaning, role, personality traits, principles, and decision rules, which implies a fixed language/locale behavior. The file does not indicate that users can opt into another language or that the Chinese-only identity is required for a documented region-specific purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The file stores its description, team mode, business context, schedules, and social memory entirely in Chinese, with no indication that language selection is optional or that the skill is explicitly limited to a Chinese-language context. Under the policy, a skill should not impose a specific language or locale without user opt-in or clear justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The style file explicitly sets the assistant tone to Chinese conversational output ('口语化,微信聊天风格') without any indication that the user's preferred language should be detected or respected. This can cause unintended language switching, reduce usability, and in sensitive contexts may lead to misunderstanding of important information, though it does not by itself introduce code execution or data exfiltration risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The guide title and all operational instructions are written exclusively in Chinese, with no indication that other languages are supported or that the Chinese-only constraint is optional. This can violate language/locale policy when a skill or its instructions impose a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

文件标题及全文均以中文编写,且未说明该技能是否仅面向中文用户,也未提供其他语言选项或用户选择机制。根据规则,未经用户选择而强制特定语言/locale 属于自然语言政策风险。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation explicitly requires Chinese field names and discourages mixing languages, which imposes a language/locale constraint. There is no user opt-in, alternative locale option, or explanation that this is required for a region-specific compliance or interoperability reason.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly encourages packaging and migrating sensitive data such as identity details, owner information, memories, relationships, contact information, and communication history, but provides no privacy warning, consent guidance, minimization advice, or handling safeguards. In an agent-migration context, this increases the risk of over-collection, unauthorized transfer, and exposure of personal or relational data across platforms.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This identity template is written entirely in Chinese and includes Chinese-only examples and instructions, which imposes a specific language/locale in the skill definition. The file does not offer any language choice or explain that the template is intended only for a Chinese-language or region-specific deployment.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The template instructs users to populate sensitive memory from broad sources such as conversation history, Feishu/email, and AgentLink without defining purpose limits, trust boundaries, or data-minimization rules. In a sensitive memory file, this can lead to over-collection, accidental ingestion of personal or confidential data, and propagation of unverified third-party content into long-lived agent memory.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The user-facing descriptive fields are written only in Chinese, including the description and time estimate, with no indication that language choice is optional or region-specific. This creates a natural-language locale constraint in a manifest file, which can violate organizational language policy when no opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The template’s natural-language descriptions and example values are entirely in Chinese, including the main description, boundary notes, migration log reasons, compatibility notes, and rollback guidance. This imposes a single language on users without any visible opt-in, alternative locale, or justification that the template is region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This manifest/template uses Chinese throughout its descriptions and instructions, which effectively constrains interaction and data entry to a specific language. The file does not offer a language choice or explain a justified region-specific requirement, so it appears to force a locale without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language description and time estimate are written only in Chinese, and the rest of the template instructions and field descriptions likewise assume Chinese usage. There is no indication that language choice is optional or that this is a documented region-specific template, which can violate a language/locale policy requiring user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This manifest-style JSON file is entirely described in Chinese, including the top-level description and all user-facing field descriptions/examples. That imposes a specific language/locale on the skill data format without any indication that Chinese is optional or that the template is intentionally region-specific, which matches the language-policy violation criteria.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · TEMPLATE/session-state.template.json (reported line 63)May include surrounding context.

json
"schedule": "09:00-11:00, 17:00",
        "next_run": "2026-04-14T09:00:00+08:00",
        "last_result": "success",
        "auto_execute": true
      }
    ],
    "value": []

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JSON template uses Chinese-only natural-language descriptions and instructions throughout, such as the top-level description and the filling instructions, with no indication that other languages are allowed. That can violate language/locale policy when a skill template is expected to be usable generally unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown template is written entirely in Chinese and structures the skill's communication-style guidance around Chinese-language interaction, but it does not offer any language choice or explain that the skill is intended only for a Chinese-speaking context. The policy requires flagging language or locale constraints when they are imposed without user opt-in or clear justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest’s human-facing comments and description are entirely in Chinese, including the primary description field at L08. Because this is natural-language guidance embedded in the skill metadata and no opt-in or locale justification is provided, it can violate a language/locale policy requiring user choice or explicit scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script reads MEMORY.md and exports up to 500 characters into core-memory.json without any consent prompt, redaction, or explicit warning that potentially sensitive memory/user data is being copied into a new package. In an agent migration context, memory files are especially likely to contain personal, confidential, or operational data, so silent export increases the chance of accidental leakage when the package is shared or backed up.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script advertises --include-skills as an opt-in control, but generate_pack() always calls extract_skills() and always writes SKILLS/catalog.json. This creates a security/privacy footgun: operators may believe skill inventory data will be excluded when the flag is not set, leading to unintended disclosure of installed skill names and paths in generated migration packages.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring, help text, and interactive guidance are written entirely in Chinese, which imposes a specific language on all users of the skill. There is no opt-in, language selection, or stated region-specific justification, so this appears to violate the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL-INFO.md:160