T09 · Insecure Skill Coding Practices
- Location
scripts/config_manager.py:76- Finding
Riot API Key Stored in Plaintext Without Enforced Access Restrictions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill does what it says, but it stores a Riot API key in a local plaintext config file without clear permission protections or adequate warning.
Review this skill before installing if you are not comfortable storing a Riot API key in plaintext under your home directory. Prefer using the RIOT_API_KEY environment variable, avoid passing keys directly in shell commands where history or logs may capture them, and install dependencies in an isolated virtual environment.
scripts/config_manager.py:76Riot API Key Stored in Plaintext Without Enforced Access Restrictions
requirements.txt:1Unbounded Third-Party Dependency Resolution
The description says the skill '支持中文自然语言查询', which presents a language constraint in the skill’s natural-language behavior. Under the policy, forcing or implying a fixed language without offering a choice or documenting opt-in can be a locale/language policy violation.
The skill declares environment-variable use and describes reading/writing local HTML output files, but it does not define any explicit tool scope such as allowed tools or permissions. That omission weakens least-privilege controls and can let the host agent invoke file and environment capabilities more broadly than users would expect.
The manifest includes broad trigger phrases like '英雄联盟', 'LOL数据', and '排位分析', which may match ordinary conversation and cause the skill to activate unexpectedly. Over-broad activation can expose user data to the skill, prompt unwanted API usage, or cause the agent to follow this skill when the user did not intend it.
The file states the skill supports Chinese natural-language queries, and later operational guidance instructs WorkBuddy to interpret results for the user in Chinese. This imposes a specific language behavior without indicating user opt-in or offering an alternative locale choice.
The instruction “用中文给用户解读关键数据” mandates a specific output language in the integration flow. Because no opt-in or locale selection mechanism is provided, this is a natural-language policy concern under the language/locale rule.
The default configuration hard-codes default_language to zh_CN, and the file’s strings and labels are Chinese-only. This imposes a specific language/locale by default without offering user choice or documenting that the tool is intentionally region-specific.
The code persists the Riot API key in plaintext JSON under the user's home directory, which can expose the credential to other local users, backups, sync services, or malware if file permissions are weak. In this skill's context, the secret is an external API credential rather than a harmless preference, so silent local storage increases the chance of unintended disclosure and API abuse.
The module docstring, CLI description, help text, and user-facing messages are all written exclusively in Chinese, which imposes a specific language experience on users. There is no indication that the skill offers language selection, opt-in, or that the locale restriction is required for a region-specific compliance reason.
The generated HTML explicitly sets lang="zh-CN", and the surrounding titles, labels, and content are all hard-coded in Chinese. This enforces a specific language/locale choice in user-facing output without offering a language selection or documenting that the skill is intentionally region-specific.
This HTML template also hard-codes lang="zh-CN" and presents all visible report text in Chinese. That creates a language/locale policy issue unless the user has chosen Chinese or the tool is clearly documented as China-specific.
The analysis report declares lang="zh-CN" and uses Chinese-only UI strings throughout the generated page. This is a user-facing locale restriction that lacks any visible opt-in or clear justification in the file.
The module description and surrounding natural-language text are entirely in Chinese, including the stated purpose of returning Chinese champion names, with no indication that language is configurable or chosen by the user. This can violate language/locale policy when a skill implicitly forces a specific language without offering opt-in or alternatives.
The dependency is specified with a lower bound only (riotwatcher>=3.2.0), allowing future unreviewed versions to be installed. This can introduce supply-chain risk through breaking changes or a newly vulnerable or compromised upstream release, especially because this skill relies on an external API client library.
riotwatcher>=3.2.0
This code makes multiple Riot API requests for summoner, account, match history, match detail, ranked, and mastery data, which transmit user-supplied identifiers and retrieve player data. In this file there is no confirmation prompt, logging/print statement, or comment/docstring warning users that these lookups contact an external service and process player identifiers.
Detected: suspicious.exposed_secret_literal