T09 · Insecure Skill Coding Practices
- Location
SKILL.md:27- Finding
JWT Bearer Tokens and FarmOS Data Transmitted Over Plaintext HTTP
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This task-management skill is mostly coherent, but it handles operational task data and write access through insecure or under-protected API patterns that deserve review before installation.
Review this skill carefully before installing. It should only be used on a trusted, isolated FarmOS network, and ideally the API should require authentication for task reads and HTTPS for any request carrying tokens or task details. Users should also watch for overly broad task suggestions from casual comments and require explicit confirmation before writes.
SKILL.md:27JWT Bearer Tokens and FarmOS Data Transmitted Over Plaintext HTTP
SKILL.md:29Task Lists and Full Task Details Exposed Without Authentication
The trigger phrases include very common conversational language such as 'we need to...' and 'someone should...', which can cause the skill to activate on ordinary discussion rather than a clear user request. In a skill that can create and modify tasks, overly broad activation increases the chance of unintended task suggestions or downstream writes after ambiguous confirmations, especially in multi-turn conversations.
The instruction to treat any mention of supply levels as actionable is an unsafe scope expansion because inventory comments may be observational, historical, hypothetical, or informational rather than a request. In this skill, that broad rule can pressure the agent into creating procurement-related tasks from incidental remarks, increasing the risk of false records and unnecessary operational actions.
Stating that almost any vague statement is sufficient input ('We need to do something about field 12' is enough) makes the skill prone to acting on incomplete or ambiguous context. This weakens intent verification and can lead to incorrect task drafting, misassignment, or accidental operational noise in a system that supports authenticated writes.
No suspicious patterns detected.