T09 · Insecure Skill Coding Practices
- Location
scripts/bibliotalk_client.py:66- Finding
Authenticated requests can be redirected to an arbitrary server
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a real persona-skill manager, but it needs review because it can write and delete local skill folders and spread API keys without strong safeguards.
Review this before installing. Use it only with a Bibliotalk account/API key you are comfortable storing locally, avoid sending sensitive questions through generated personas, and do not run create/sync/remove with untrusted slugs. The publisher should add strict slug/path containment, deletion confirmation, endpoint validation, and avoid copying live `.env` secrets into generated skills.
scripts/bibliotalk_client.py:66Authenticated requests can be redirected to an arbitrary server
scripts/skill_writer.py:110Plaintext API credentials are replicated into every generated Skill
scripts/skill_writer.py:50Generated personas transmit full user questions to an external service by default
scripts/skill_writer.py:132Untrusted remote profile content is loaded into the Agent’s instruction context
scripts/skill_writer.py:207Unsanitized slug permits path traversal, arbitrary writes, and recursive deletion
The skill claims end-user interaction features like persistent persona routing and enforced reply prefixes, yet those behaviors are not actually implemented in this file, while privileged filesystem/version-management actions are documented instead. That gap can conceal the true operational surface of the skill and cause users to approve it under false assumptions.
The skill claims end-user interaction features like persistent persona routing and enforced reply prefixes, yet those behaviors are not actually implemented in this file, while privileged filesystem/version-management actions are documented instead. That gap can conceal the true operational surface of the skill and cause users to approve it under false assumptions.
The skill claims end-user interaction features like persistent persona routing and enforced reply prefixes, yet those behaviors are not actually implemented in this file, while privileged filesystem/version-management actions are documented instead. That gap can conceal the true operational surface of the skill and cause users to approve it under false assumptions.
Referenced artifact was not completely inspected
5. 确保每个独立技能文件夹里至少包含:`meta.json`、`SKILL.md`、`profile.md`
Referenced artifact was not completely inspected
5. 确保每个独立技能文件夹里至少包含:`meta.json`、`SKILL.md`、`profile.md`
Referenced artifact was not completely inspected
5. 确保每个独立技能文件夹里至少包含:`meta.json`、`SKILL.md`、`profile.md`
Referenced artifact was not completely inspected
5. 确保每个独立技能文件夹里至少包含:`meta.json`、`SKILL.md`、`profile.md`
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
`.env` file. When copied into a generated figure skill, it keeps working with the
same relative layout:
- <skill_dir>/.env
- <skill_dir>/scripts/bibliotalk_client.py
"""
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
DEFAULT_AGENT = "claude"
DEFAULT_GURU_BASE_DIR = None # Reserved for explicit overrides when needed
PROJECT_ROOT = Path(__file__).resolve().parent.parent
SOURCE_ENV_FILE = PROJECT_ROOT / ".env"
SOURCE_CLIENT_SCRIPT = PROJECT_ROOT / "scripts" / "bibliotalk_client.py"
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
DEFAULT_AGENT = "claude"
DEFAULT_GURU_BASE_DIR = None # Reserved for explicit overrides when needed
PROJECT_ROOT = Path(__file__).resolve().parent.parent
SOURCE_ENV_FILE = PROJECT_ROOT / ".env"
SOURCE_CLIENT_SCRIPT = PROJECT_ROOT / "scripts" / "bibliotalk_client.py"
shutil.copy2(SOURCE_ENV_FILE, skill_dir / ".env") duplicates a live credential file into each generated skill, expanding the number of locations where secrets exist. In the context of a tool that mass-generates persona skills, this significantly widens the blast radius of any local compromise, accidental sharing, or malicious modification of generated skill directories.
scripts_dir = skill_dir / "scripts"
scripts_dir.mkdir(parents=True, exist_ok=True)
shutil.copy2(SOURCE_ENV_FILE, skill_dir / ".env")
shutil.copy2(SOURCE_CLIENT_SCRIPT, scripts_dir / "bibliotalk_client.py")
guru_remove permanently deletes the target skill directory using shutil.rmtree, which is a destructive filesystem operation. The code path provides no confirmation prompt and no inline warning describing the irreversible deletion behavior before it executes.
The natural-language instructions, examples, and usage guidance are all presented in Chinese, which effectively forces a specific language for users. The file does not offer an opt-in choice of language or explain that the skill is intended only for a Chinese-speaking or region-specific audience.
The skill instructs the agent to perform network access, read/write local files, and handle secrets in .env, but it does not declare any permissions or allowed-tools scope. That mismatch weakens least-privilege boundaries and makes it easier for a broadly privileged runtime to execute filesystem and network actions the user may not expect.
This duplicate finding reflects the same persistence concern: installation generates long-lived files in agent skill directories, including configuration and executable-support artifacts. If users believe they are only starting a temporary conversation flow, this persistent modification can create ongoing exposure and configuration drift.
执行:
python scripts/skill_writer.py --action guru-create --agent {agent} --slug {slug}
安装后会生成:
This duplicate finding reflects the same persistence concern: installation generates long-lived files in agent skill directories, including configuration and executable-support artifacts. If users believe they are only starting a temporary conversation flow, this persistent modification can create ongoing exposure and configuration drift.
执行:
python scripts/skill_writer.py --action guru-create --agent {agent} --slug {slug}
安装后会生成:
The skill describes deleting local persona directories without any warning, preview, or explicit confirmation requirement. In a skill that manages files under user skill directories, an accidental or ambiguous invocation could permanently remove installed content or customized profiles.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
## 备注
- 工作目录(`pwd`)为 `gurutalk` 技能的目录
- 每个大师作为一个独立的技能安装在对应 agent 的 skills 目录中:`~/.claude/skills/{slug}/`、`~/.openclaw/workspace/skills/{slug}/`、`~/.codex/skills/{slug}/`
- 每个技能目录都应保有自己的 `.env` 与 `scripts/bibliotalk_client.py`
- 一旦进入某个人物对话,后续消息默认继续发给该人物,直到用户发送 `/gurutalk end`,或通过 `/{another-figure} {message}` 直接切换
- 使用 `--agent` 参数指定目标 agent 类型:`claude`、`openclaw` 或 `codex`
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
## 备注
- 工作目录(`pwd`)为 `gurutalk` 技能的目录
- 每个大师作为一个独立的技能安装在对应 agent 的 skills 目录中:`~/.claude/skills/{slug}/`、`~/.openclaw/workspace/skills/{slug}/`、`~/.codex/skills/{slug}/`
- 每个技能目录都应保有自己的 `.env` 与 `scripts/bibliotalk_client.py`
- 一旦进入某个人物对话,后续消息默认继续发给该人物,直到用户发送 `/gurutalk end`,或通过 `/{another-figure} {message}` 直接切换
- 使用 `--agent` 参数指定目标 agent 类型:`claude`、`openclaw` 或 `codex`
The file’s title and all operational instructions are written in Chinese, and the required output format is specified only in Chinese. This imposes a language/locale constraint on the skill without any opt-in, alternative language path, or documented justification for why the skill must operate only in Chinese.
The instruction 语言:中文 mandates a specific language for all outputs. The file does not offer a language choice, user opt-in, or a documented region-specific reason for this constraint, which matches the locale-policy violation criteria.
The entire instruction file is written in Chinese and specifies output behavior in Chinese without offering any language choice or explaining that the skill is intended only for a Chinese-language context. This creates a natural-language locale policy concern because the skill appears to impose a specific language by default.
This code performs an HTTP request that transmits a user email address as a query parameter, but there is no confirmation prompt or user-facing warning at the point of transmission. For code files, network calls that send user data should have some visible disclosure unless the behavior is clearly warned elsewhere.
Several user-facing help texts and error messages are hard-coded in Chinese, which imposes a specific language on all users. The policy allows locale constraints only when opt-in is provided or the restriction is clearly documented and justified, neither of which appears in this file.
The script copies the parent skill's .env file into every generated persona skill directory, propagating API keys and other secrets far beyond their original trust boundary. In a skill ecosystem where generated skills may be inspected, synced, backed up, or modified separately, duplicating secrets materially increases the chance of credential disclosure and misuse.
No suspicious patterns detected.