T09 · Insecure Skill Coding Practices
- Location
SKILL.md:24- Finding
Credential Disclosure Through Configuration Check Commands
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly does what it claims, but it includes unsafe credential-check instructions and an unsafe recurring cron setup that users should review before installing.
Install only if you are comfortable granting the skill access to your Jiqizhixin, Feishu, and GetNote accounts. Do not run the documented echo commands that print full secrets; use presence-only checks instead. If scheduling is needed, run it as an unprivileged user, log to a private user-owned file, and keep a clear removal command for the cron entry.
SKILL.md:24Credential Disclosure Through Configuration Check Commands
SKILL.md:85Predictable Shared Temporary Log in a Potentially Privileged Cron Job
scripts/push-news.sh:59Unescaped RSS Content Embedded Directly into a JSON Request
The skill instructs use of shell commands and references executable scripts, but it does not declare any tool scope or allowed-tools boundary. That makes the capability surface implicit rather than constrained, increasing the chance an agent can invoke shell access more broadly than intended when handling a seemingly simple news-push task.
整个技能说明与用户触发表达均默认且仅使用中文,没有表明这是面向特定中文用户群的区域性技能,也未提供语言/locale 选择。按组织语言/locale 政策,这种默认强制单一语言而无用户选择可能构成自然语言策略违规。
The trigger phrases are broad enough to overlap with ordinary conversation about daily news or scheduling, which can cause accidental invocation of a skill that uses shell capabilities and touches external services. In this context, mis-triggering is more dangerous because activation may lead to credential checks, script references, or setup instructions with persistence-related effects.
The cron-based setup introduces session persistence by causing recurring execution outside the immediate user request lifecycle. Persistent scheduled execution is security-sensitive because it can continue operating with stored environment credentials, write logs, and repeatedly contact external services even after the original interaction ends.
crontab -e
添加:
The skill says it can configure a cron job for the user, which changes host persistence and execution behavior beyond merely fetching and sending news. Allowing an agent to create scheduled tasks creates a durable execution foothold that could be abused to run unintended commands repeatedly, especially given the referenced absolute path under /root.
The metadata description advertises broad automatic behavior ('每日自动获取…推送…保存…') without clearly constraining when the skill should activate or requiring explicit user confirmation before performing external actions. In an agent environment, this can cause over-triggering and unintended execution that sends data to Feishu or stores content in Get notes without the user meaning to invoke this specific workflow.
This manifest description explains what the skill does but provides no specific invocation phrases, activation conditions, or exclusion context. For manifest files, that ambiguity can lead to unintended invocation because the trigger scope is not clearly bounded.
The script instructs users to place long-lived API tokens and user identifiers directly into ~/.bashrc, which exposes secrets to common risks such as accidental disclosure through dotfile backups, screen sharing, shell debugging, or unsafe workstation sharing. While the script does not print secret values, it normalizes insecure credential storage and gives no warning about safer alternatives or operational handling of those secrets.
The script presents only Chinese trigger phrases for using the skill, which imposes a specific language on the user. There is no opt-in, alternative language wording, or documented justification that the skill is intended only for a Chinese-language environment.
This shell script sends content to Feishu and saves it to an external note service via network calls. Although it logs progress messages, those messages do not disclose the privacy-impacting behavior in a warning or explanatory comment aimed at informing the user that data will be transmitted and stored externally.
The script manually interpolates untrusted external RSS-derived content into a JSON request body without JSON escaping. If a title contains quotes, backslashes, or control characters, the generated payload can become malformed or semantically altered, causing failed note creation or unintended content injection into the saved note; because the source is remote, this makes the workflow brittle and externally influenceable.
JSON
)
RESPONSE=$(curl -s --max-time 30 -X POST "https://openapi.biji.com/open/api/v1/resource/note/save" \
-H "Authorization: $GETNOTE_API_KEY" \
-H "X-Client-ID: $GETNOTE_CLIENT_ID" \
-H "Content-Type: application/json" \
The script's user-facing comments and status messages are entirely in Chinese, and the generated content titles are also fixed in Chinese. Under the language/locale policy, forcing a specific language without opt-in can be a policy violation unless the locale restriction is explicitly justified.
No suspicious patterns detected.