T09 · Insecure Skill Coding Practices
- Location
example-ai-replenishment-claude.ts:111- Finding
Unsanitized inventory evidence is transmitted to Anthropic
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a disclosed governance integration, but its provider-backed examples send workflow evidence to external LLMs without applying the sanitizer the documentation says to use.
Review provider-backed examples before installing or adapting this skill. Prefer local governance mode unless you need LLM analysis, and when using providers, apply guardEvidence, use explicit evidence allowlists, tokenize or remove PII/PCI and infrastructure secrets, and require human review for real financial or operational decisions.
example-ai-replenishment-claude.ts:111Unsanitized inventory evidence is transmitted to Anthropic
example-infrastructure-change-openai.ts:126Unsanitized infrastructure metadata is transmitted to OpenAI
example-fraud-review-grok.ts:147Unsanitized transaction and cardholder evidence is transmitted to xAI Grok
The documentation asserts that all evidence objects must be guarded before forwarding to external LLM adapters and describes guardEvidence as enforcing PII blocking, prompt-injection stripping, and length limits. However, in this file that protection is only demonstrated as caller guidance and example usage, not as a guaranteed, enforced control in the integration itself. If consumers assume sanitization is automatic and pass raw evidence into provider-backed flows, sensitive data or adversarial prompt content could be transmitted externally.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
*
* Anthropic Claude analyzes inventory data and recommends a reorder.
* A confidence-threshold guard blocks low-confidence recommendations.
* A human-only guard ensures the final approval can't be auto-approved.
*
* Requires: ANTHROPIC_API_KEY environment variable
*
No suspicious patterns detected.