T09 · Insecure Skill Coding Practices
- Location
scripts/domestic_flight_service.py:114- Finding
API Credential Embedded in Request URL
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The flight-search skill is mostly coherent, but its optional local web server is under-protected and can expose API quota use or local JSON file reads if reachable by others.
Install only if you are comfortable using your own Juhe API key and keeping the HTTP mode local and trusted. Prefer the CLI mode; if you run serve mode, bind it only to 127.0.0.1, do not expose the port to a network, and use a dedicated low-quota Juhe key that you can revoke.
scripts/domestic_flight_service.py:114API Credential Embedded in Request URL
scripts/domestic_flight_service.py:197Unauthenticated HTTP Endpoint Permits Arbitrary Local JSON File Access and API Quota Use
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
If the user wants a round trip, run two one-way queries.
If `JUHE_FLIGHT_API_KEY` is missing, tell the user to apply for a Juhe key and configure it before retrying.
## Output Rules
- Sort results by lowest `ticket_price` first.
- Prefer up to 5 options unless the user asked for more.
The skill invokes a local Python script, requires an environment secret, reads local files for airport/city resolution, and performs outbound network calls, but the manifest does not declare an explicit tool scope or permissions boundary. That increases the chance the runtime grants broader-than-expected capabilities, making review, containment, and policy enforcement harder if the skill is modified or abused.
This Python file contains multiple user-facing error and help strings only in Chinese, such as validation errors and API-key setup guidance. The skill does not offer user opt-in for language/locale selection, and the module description does not clearly justify that it is restricted to Chinese-language users despite being a domestic-flight tool.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
def run_command(*args: str) -> dict:
completed = subprocess.run(
[sys.executable, str(SCRIPT), *args],
check=True,
capture_output=True,
The README states that the skill supports Chinese city names, airport names, and IATA codes, but the example prompts and overall description imply a Chinese-language interaction model without offering any language/locale choice. Under the policy rule, a skill that effectively constrains language/locale should document the constraint or present it as an explicit opt-in.
This manifest-style JSON uses only Chinese-script city names as lookup keys throughout, which imposes a specific language/locale assumption in natural-language data. Because there is no accompanying indication of locale scope or user choice in the file, it can violate the policy against forcing a language without opt-in.
This JSON sample includes natural-language response fields and labels in Chinese, such as the success reason and airline/airport names, with no indication that the skill supports locale selection or that Chinese output is intentional and constrained. For a general-purpose sample/provider response, this can reflect a language-policy issue because it implicitly fixes the user-visible locale.
No suspicious patterns detected.