T09 · Insecure Skill Coding Practices
- Location
references/credential-setup-guide.md:44- Finding
Unsafe Plaintext Credential Persistence and Shell Command Injection
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This SOP-to-skill generator is coherent in purpose, but it would create persistent automations that may install software, read local agent configuration, and store credentials with too little scoping and consent.
Review before installing. Do not let generated skills automatically install packages, write secrets into shell profiles or plaintext .env files, or read local agent configuration without explicit approval. Use a secret manager or scoped app tokens, redact sensitive documents and screenshots, and require human confirmation before saving generated skills or running workflows that affect finance, HR, approvals, or business systems.
references/credential-setup-guide.md:44Unsafe Plaintext Credential Persistence and Shell Command Injection
references/skill-template.md:29Automatic Installation of Unpinned Third-Party Dependencies
references/tool-discovery-guide.md:71Unnecessary Inspection of Local Agent Configuration and Skill Inventory
Referenced artifact was not completely inspected
**语言**:对用户说"工作流程文档",不说"SKILL.md";说"8 步里 5 步 AI 可以帮你做",不说"自动化率 62%"。
The file instructs modifying shell profiles and .env files to persist secrets, including replacement commands that write credential values directly into user-controlled config files. Persisting secrets in plaintext across broadly loaded environment files increases exposure to local compromise, accidental disclosure, process inheritance, backups, and version-control mistakes; this is especially unjustified for a skill whose stated purpose is SOP extraction.
The template explicitly tells the agent to trigger even on a vague scenario, which encourages over-broad activation and increases the chance the skill runs outside its intended context. In an agent system, this can cause unintended workflow execution, incorrect tool use, or accidental handling of sensitive data when the user did not clearly request this skill.
The description claims the skill applies to 'any岗位' and 'any可标准化的重复性工作' across sensitive business domains, but it does not define clear activation boundaries, exclusions, or required user confirmation before processing potentially sensitive workflows. This can lead to overbroad use in high-risk contexts such as HR or finance, where the skill may solicit or normalize disclosure of confidential process details without adequate guardrails.
The description presents the skill entirely in Chinese and does not indicate that language choice is configurable or based on user preference. While not directly enabling code execution or privilege abuse, this can cause user misunderstanding about prompts, consent, or handling of extracted procedures, especially in multilingual environments where clarity of workflow instructions matters.
The manifest description is written as a Chinese-only interaction description and frames the skill in Chinese without indicating that users may choose another language. Under the policy rule, language constraints should either be optional or explicitly justified; neither appears here.
The listed trigger phrase "帮我把工作变成Skill" is natural conversational language that could plausibly appear in ordinary discussion, making activation scope too broad. The file does not provide exclusion conditions or narrower context limits to reduce unintended invocation.
The guide explicitly instructs the skill to request external service credentials, accept user-provided secrets, store them, and verify them. For an SOP-extraction skill, this materially expands capability beyond extracting workflow knowledge and creates a path for unnecessary secret collection and handling, increasing the chance of credential exposure or misuse.
The guide tells the user to provide credentials and then write them into persistent environment variables, but it does not clearly warn that this is plaintext storage with associated risks. Users may be led to expose SMTP passwords, webhook URLs, or database credentials without understanding the confidentiality and persistence implications.
The trigger examples include very generic natural-language phrases such as asking the agent to help with reimbursement, which can overlap with ordinary conversation and unintentionally activate or route into this skill. In a skill that saves reusable workflows and may later automate business actions, ambiguous invocation increases the risk of accidental execution, misrouting, or unauthorized use in the wrong context.
The placeholder trigger format '[触发词]' does not constrain what final trigger will be registered, leaving room for unsafe, overly broad, or conflicting phrases to be chosen later. Because this skill is intended to create reusable automations from dialogue, unspecified trigger scope can propagate insecure defaults into generated skills and cause collisions with unrelated user requests.
The trigger conditions are broad enough to match common, ambiguous user phrases such as asking how to handle an invoice or requesting help with reimbursement. This can cause the skill to activate when the user only wants general advice, leading to unintended workflow execution, confusion, or premature handling of sensitive finance processes.
This markdown file presents all guidance, examples, and instructions exclusively in Chinese, which can amount to a language/locale policy violation when no user opt-in or justification is provided. The file does not indicate that the skill is region-specific or that users may select another language.
The template normalizes automatic dependency checks and package installation during execution without requiring user notice or approval. This is dangerous because installing tools at runtime can introduce supply-chain risk, alter the execution environment unexpectedly, and execute package-install scripts without the operator making an informed decision.
The credential setup flow instructs the agent to write user-provided secrets into environment variables and continue, but it omits warnings about persistence, shell history, process exposure, logs, and least-privilege handling. In a skill generator context, this omission is risky because generated skills may replicate insecure secret-handling patterns across many downstream workflows.
The guide explicitly instructs the agent to access Feishu/DingTalk document links via API or browser, but gives no requirement to verify authorization, obtain user consent, or warn that linked documents may expose private or internal data. In a document-extraction skill, this can normalize broad retrieval of enterprise content and increase the risk of over-collection or accidental access to sensitive information.
整份技能参考文档仅以中文编写,并以指令式语气规定操作流程,但没有提供用户语言选择,也未说明该技能仅面向中文团队或特定区域。根据语言/locale 政策,若技能强制单一语言而无用户 opt-in 或合理限定,属于自然语言层面的合规问题。
All dialogue templates and user-facing instructions in this file are presented solely in Chinese, with no indication that the user may choose another language or that the skill is intentionally limited to a Chinese-language context. This can violate language/locale policy when no opt-in or justification is provided.
The guide tells the agent to process images/screenshots with vision capabilities without warning that screenshots often contain sensitive information such as personal data, credentials, internal dashboards, or confidential business context. Even without malicious intent, this omission can cause users to submit more data than necessary and lead to unnecessary exposure during analysis.
This markdown file contains user-facing instructional content exclusively in Chinese, and nowhere indicates that the skill is intended only for Chinese-speaking users or a China-specific environment. Under the language/locale policy rule, forcing a specific language without opt-in or justification is a natural-language policy concern.
No suspicious patterns detected.