T09 · Insecure Skill Coding Practices
- Location
SKILL.md:16- Finding
Access Token Exposure Through Chat and Command-Line Arguments
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill coherently fetches GitCode PR review comments, helps apply user-approved local code fixes, and optionally replies or resolves discussions with confirmation, but users should handle tokens and PR context carefully.
Install only if you intend to let the agent work with GitCode PR review comments. Use a narrowly scoped GITCODE_TOKEN through the environment, do not paste tokens into chat or command lines, review the summarized comment list before approving code edits, and confirm any reply or resolve action before it changes the live PR discussion. Treat generated context JSON and terminal logs as potentially confidential PR data.
SKILL.md:16Access Token Exposure Through Chat and Command-Line Arguments
scripts/pr_comment_fix_tool.py:42Private PR Context Is Duplicated to Standard Output and Written Without Explicitly Restrictive Permissions
Referenced artifact was not completely inspected
**SKILL_ROOT**:本 `SKILL.md` 所在目录。
The manifest says the skill is for modifying code according to GitCode PR review comments, implying code changes are its primary behavior. The implementation and module docstring show only PR comment retrieval, discussion replies, and resolution-state updates via API calls, with no code parsing, patch generation, or file modification logic anywhere in the script.
The skill requires access to environment secrets, network calls, shell execution, and file modification, but it does not declare an explicit tool/permission scope. That creates an authorization ambiguity where an agent may use more capability than a reviewer or platform policy expects, especially since the workflow fetches remote PR data and then edits local code based on it.
User-facing descriptions, help text, and error messages throughout the file are all in Chinese, with no indication that the tool is region-specific or that another language is supported. This creates a natural-language policy concern because it imposes a specific language on users without opt-in or documented justification.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
from urllib.parse import quote, urlencode
from urllib.request import Request, urlopen
GITCODE_API_BASE = "https://api.gitcode.com/api/v5"
API_RETRY = 2
API_RETRY_INTERVAL = 2.0
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
if sys.platform == "win32":
for scope in ("User", "Machine"):
try:
out = subprocess.check_output(
[
"powershell",
"-NoProfile",
The tool performs authenticated state-changing actions on PR discussions, including marking threads resolved, without an explicit confirmation step or strong user-facing warning. In an agent context, this increases the risk of unintended workflow manipulation, especially if a user or upstream prompt ambiguously requests review handling.
The README tells users to create and export a GitCode personal access token, but it does not clearly warn that the skill will authenticate to GitCode and perform remote actions such as fetching PR discussion context and optionally posting replies or changing resolution state. This is dangerous because users may provide high-privilege credentials without understanding the scope of remote API access or the consequences of running the tool against a live repository service.
The description hard-codes Chinese phrasing together with English tokens ('Use when 用户要修改 PR 检视意见') and the rest of the skill instructions are written in Chinese, which implies a locale preference without explicit user opt-in. Under the policy rule, language constraints should either be optional or clearly justified.
No suspicious patterns detected.