T09 · Insecure Skill Coding Practices
- Location
scripts/daily-backup.py:91- Finding
Plaintext Email Credentials Are Staged for Cloud Synchronization
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill has a coherent backup-and-restore purpose, but it handles credentials, persistent memory, and cron jobs with too little scoping or user control.
Install only if you are comfortable with a skill that may gather and restore highly sensitive assistant state, email configuration, and scheduled tasks. Before use, remove .msmtprc and unrelated cron data from the backup scope, require explicit approval for every restore target, and avoid restoring cron or behavior-rule files from a Feishu document unless you can verify its provenance and contents.
scripts/daily-backup.py:91Plaintext Email Credentials Are Staged for Cloud Synchronization
scripts/daily-backup.py:75Complete User Crontab Is Collected Beyond the Required Backup Scope
references/recovery-guide.md:15Untrusted Cloud Content Can Replace Persistent Agent Memory and Behavioral Rules
references/recovery-guide.md:45Cloud-Sourced Cron Entries Can Be Restored as Persistent Commands Without Validation
A second behavior mismatch exists because the skill advertises automated Feishu backup, restore, and synchronization capabilities that are not actually implemented, creating deceptive expectations around where data goes and what actions occur. That kind of mismatch undermines informed consent and can conceal sensitive local staging or persistence behavior from the user.
A second behavior mismatch exists because the skill advertises automated Feishu backup, restore, and synchronization capabilities that are not actually implemented, creating deceptive expectations around where data goes and what actions occur. That kind of mismatch undermines informed consent and can conceal sensitive local staging or persistence behavior from the user.
The skill proposes backing up identity, user information, memory, email configuration, and cron data without a prominent user-facing warning about confidentiality and account-security implications. Sensitive credentials and personal data stored in a cloud document or backup artifact materially increase the risk of account compromise and privacy breach.
The skill normalizes backing up highly sensitive user and system data, including memory and email configuration, to an external document store. Even if framed as convenience, centralizing these artifacts creates a concentrated target for exfiltration and can expose credentials, personal history, and operational details.
The restore workflow includes reconstructing files and restoring cron tasks, which can overwrite local state and reintroduce scheduled execution, but it lacks a clear warning about destructive or system-modifying effects. Restoring from an external document without strong warnings and validation can also import stale, tampered, or unsafe configuration.
The recovery flow encourages reading communication-history backups and reconstructing sensitive files from external storage, which normalizes persistent retention and reuse of prior user data. In context, this is especially dangerous because it can rehydrate private information and system configuration into a live environment without strong authenticity, minimization, or consent controls.
The document instructs the agent to overwrite local files and restore cron tasks without any prior warning, diff, or confirmation step. High-impact writes sourced from an external document create a straightforward path to destructive changes, credential replacement, or persistence if the backup is stale, malicious, or misidentified.
The YARA hit is not proof of malware, but it correctly highlights a persistence pattern: appending commands into crontab. In the context of a restore guide that imports remote document content into system scheduling, this is dangerous because the mechanism could be abused to establish unauthorized recurring execution.
�息 | IDENTITY.md | AI 身份定义 | | 二、用户信息 | USER.md | 用户偏好配置 | | 三、灵魂定义 | SOUL.md | AI 行为准则 | | 四、完整记忆内容 | MEMORY.md | 长期记忆 | | 五、邮箱配置 | ~/.msmtprc | 邮箱发信配置 |
从「六、自动化任务」章节提取 cron 任务,逐行添加:
# 添加 cron 任务
(crontab -l 2>/dev/null; echo "0 3 * * * /usr/bin/python3 /path/to/script.py") | crontab -
检查以下文件是否存在且非空:
如果文档中记录了沟通历史备份文档链接:
Collecting .msmtprc is unjustified for a Feishu-based AI state backup and may expose SMTP usernames, passwords, tokens, or server details. Because the skill is framed as assistant-memory synchronization, users are less likely to expect credential material to be swept into backup artifacts, making the data exposure particularly risky.
The stated skill purpose is AI state backup, but the generated backup also includes .msmtprc contents and cron jobs, expanding collection into system and credential-adjacent data without clear necessity. In this skill context, that over-collection is more dangerous because the backup is intended for synchronization/restoration, increasing the chance that secrets and host configuration are replicated into broader storage or later exposed.
The script assembles sensitive identity, user, memory, soul, email, and automation data into a natural-language restoration document designed for later replay. This creates a single highly concentrated artifact that is easy to exfiltrate, sync to third parties, or misuse for impersonation and environment reconstruction; the restore instructions further increase abuse potential by making rehydration straightforward.
The skill describes file reads/writes and shell-driven automation but declares no explicit tool scope or permissions boundaries. That increases the chance an agent can invoke sensitive capabilities implicitly, especially because the skill also handles restoration and cron-related operations that can modify system state.
The trigger phrases are broad enough that ordinary conversation about backup, restore, or sync could invoke a skill that reads and writes highly sensitive state. Because the skill can affect memory, credentials, and system automation, accidental activation materially raises privacy and integrity risk.
Automatic backup conditions like learning a new skill, completing automation, or adding an important contact are vague and can cause background collection without a clear, contemporaneous user request. In this context, that means sensitive memory and system data could be persisted or staged more often than the user expects.
Recommending both state backups and communication-history backups to keep memory complete encourages long-term retention of user interactions beyond what is necessary for normal operation. This increases privacy risk, expands breach impact, and makes overcollection seem like best practice.
The trigger phrases are broad and overlap with normal memory/sync requests, increasing the chance the skill runs when the user did not intend a destructive restore workflow. In this skill, accidental activation is more dangerous because the workflow includes overwriting files and installing cron jobs from remote content.
The recovery guide restores sensitive system-level artifacts beyond conversational state, including ~/.msmtprc and cron entries. Because the content is pulled from a remotely stored Feishu document and then written locally, a tampered backup could implant mail credentials or persistence mechanisms under the guise of state recovery.
Using crontab to append tasks establishes persistent behavior on the host, which is a sensitive capability in an agent skill. Here that persistence is driven by backup document contents, so a malicious or compromised document could cause recurring execution of attacker-controlled commands after the restore completes.
# 添加 cron 任务
(crontab -l 2>/dev/null; echo "0 3 * * * /usr/bin/python3 /path/to/script.py") | crontab -
The script advertises automatic Feishu backup, but it never uploads anything to Feishu and only writes a local backup plus a pending-sync marker. This is dangerous because users may believe they have an off-device recovery backup when in fact sensitive state remains only on the local host, creating a false sense of resilience and possible data-loss during restore scenarios.
The docstring claims automatic backup to a Feishu document, but the implementation only stages local files for future sync. This mismatch can mislead operators into assuming remote persistence and may cause them to handle or delete local state unsafely under the false belief that a remote backup already exists.
Enumerating cron jobs is outside the clearly stated scope of backing up AI assistant memory and can reveal other scheduled tasks, paths, credentials, or operational details unrelated to the skill. In a sync/backup context, this broadens host reconnaissance and leaks system metadata that could aid later targeting.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
def get_cron_jobs():
"""获取当前 cron 任务"""
try:
result = subprocess.run(["crontab", "-l"], capture_output=True, text=True)
if result.returncode == 0:
return result.stdout
return "# 无 cron 任务"
The script serializes sensitive email configuration into backup content without any explicit warning, consent prompt, or redaction step. This increases the likelihood that credential material is silently copied into backup artifacts that may later be synced, shared, or restored in insecure contexts.
The script writes a consolidated backup containing user memory, identity data, and sensitive configuration to disk without prominently disclosing the sensitivity or applying protections such as restrictive permissions or encryption. In this skill context, the file becomes a high-value local aggregation point for private data and credential-adjacent material.
The file's docstring, usage examples, log messages, and CLI output are written entirely in Chinese, which imposes a specific language on users. Under the policy, locale or language restrictions should either be optional or clearly justified as region-specific; neither is present here.
No suspicious patterns detected.