T09 · Insecure Skill Coding Practices
- Location
scripts/generate_review_report.py:988- Finding
Unconditional Persistent Archival of Sensitive Operational Documents
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears to be a real deployment-plan reviewer, but it persistently stores original operational documents and report evidence, including possible credentials, without enough user control or retention limits.
Review this skill before installing in any environment that handles production deployment plans, inventories, IP lists, hostnames, or credentials. Use it only with a clear local storage policy, redaction of credential evidence, restricted file permissions, and a cleanup process for data/raw, output reports, and the master tracking workbook.
scripts/generate_review_report.py:988Unconditional Persistent Archival of Sensitive Operational Documents
scripts/generate_review_report.py:581Detected Plaintext Credentials Are Reproduced in Persistent Reports
scripts/generate_review_report.py:900Excel Formula Injection Through an Attacker-Controlled Plan Filename
The documented behavior and the actual/prescribed behavior diverge in several security-relevant ways, including undeclared data retention and output generation. When a skill silently archives user files or produces additional artifacts beyond its stated purpose, users and reviewers cannot accurately assess privacy, storage, and operational risk.
The instructions require copying all user-supplied files into a raw archive before any processing, yet no explicit consent or warning is required. This is especially risky because change plans and deployment spreadsheets commonly contain confidential system architecture, network topology, and potentially operational secrets, so compulsory archival materially increases breach impact.
The skill embeds file-writing and persistence behavior but does not declare any explicit tool scope or permissions boundary. That increases the chance the runtime grants broader filesystem access than users expect, making unintended data storage or modification harder to govern and audit.
The manifest description is written to prescribe default output behavior in Chinese context and the rest of the skill consistently assumes Chinese-language interaction, but nowhere offers language selection or states that the skill is intentionally restricted to a Chinese-only audience. This can violate language/locale policy when users have not opted into that language.
The skill states that it will save generated reports and, in the broader instructions, user documents, but does not present a clear user-facing privacy or retention warning. Because the inputs are enterprise change plans and spreadsheets, silent storage can expose sensitive infrastructure details, internal IPs, hostnames, or credentials to later unauthorized access.
The listed keywords include broad phrases such as “帮我审核方案”, “帮我检查方案”, and “帮我审一遍”, which are generic requests that could match many unrelated review tasks rather than this specific deployment-plan skill. The trigger section does not provide negative examples or tighter constraints to prevent unintended invocation.
The skill explicitly mandates retaining raw copies of all uploaded files in a history directory. Persistent storage of original documents increases the attack surface and the blast radius of any local compromise, because sensitive source materials remain available long after the review task completes.
The skill requires keeping all process artifacts, including original uploads and generated reports, in a persistent skill directory. Centralized long-term retention of both inputs and derived outputs creates an attractive repository of sensitive operational data and makes later unauthorized discovery easier.
The manifest claims the review is grounded on templates under /home/deploy_template and that template discovery should prioritize plan filename keywords. This file only uses local skill data/output directories and hardcoded chapter heuristics; it performs no access to /home/deploy_template and no filename-based template resolution.
The manifest describes a conditional requirement: the deployment table is required by default unless the user clearly says they do not want it. The validator and CLI enforce --deploy as mandatory in all cases, with no branch supporting an explicit opt-out.
The code persistently copies raw input plan and spreadsheet files into a local archive directory, even though these documents can contain infrastructure details, host/IP inventories, and explicit credential material the tool already detects. This creates unnecessary long-term retention of sensitive data and increases blast radius if the skill workspace, backups, or neighboring processes are accessed by unauthorized parties.
The skill writes user-supplied documents to disk without clear disclosure, which is especially risky because the reviewed content may include passwords, topology data, and operational procedures. Undisclosed persistence violates data minimization expectations and can surprise users who assume analysis is transient.
The manifest explicitly promises a default concise Markdown response while also saving a Word report. In the implementation, the audit flow generates a Word report, an Excel tracking sheet, and appends to a master Excel workbook, but nowhere constructs or returns Markdown content.
Appending findings into a cumulative master workbook creates cross-run persistence of issue evidence, locations, and potentially sensitive excerpts from customer documents. Over time this centralizes data from multiple reviews into one file, increasing exposure and enabling unintended data mixing between users, projects, or tenants.
Persistently aggregating findings and evidence into a master workbook without clear disclosure creates an undisclosed audit trail containing sensitive operational details. In a shared or multi-user skill context, this is more dangerous because it can expose prior users' review artifacts beyond the immediate task.
This markdown file presents all instructions, examples, and guidance exclusively in Chinese. Under the policy rule for natural-language violations, forcing a specific language without user opt-in or a documented justification can be a locale-policy issue.
The file's natural-language description and user-facing strings are entirely in Chinese, indicating the skill is designed to operate in a single language by default. There is no visible opt-in, locale selection, or documentation that this is a region-specific tool, which can violate language/locale choice policy.
No suspicious patterns detected.