T09 · Insecure Skill Coding Practices
- Location
scripts/fetch_mall_trade_data.py:16- Finding
Hardcoded API Signing Secret Enables Application Impersonation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is coherent for generating marketplace reports, but it embeds a reusable API signing value and directly renders untrusted marketplace text into Markdown.
Review before installing. The market-reporting behavior is understandable, but the publisher should remove or replace the embedded signing value and escape externally sourced marketplace text before returning Markdown reports. Users should treat listing text and links in reports as untrusted marketplace data, not as agent instructions or verified recommendations.
scripts/fetch_mall_trade_data.py:16Hardcoded API Signing Secret Enables Application Impersonation
scripts/generate_market_overview.py:39Untrusted Marketplace Content Is Rendered as Unsanitized Markdown
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
python3 scripts/generate_market_overview.py /tmp/mall-market-overview.json
## Output rules
- Return the generated Markdown report directly.
- Do not paste raw JSON unless the user explicitly asks.
The skill instructs the agent to run local scripts that read files and perform network access, but it does not declare any explicit tool scope or permission boundary. That creates an authorization gap where the agent may invoke broader capabilities than the skill metadata makes visible, increasing the chance of unintended data access or outbound requests if the skill or its bundled code changes.
No suspicious patterns detected.