T09 · Insecure Skill Coding Practices
- Location
SKILL.md:452- Finding
Spoofable Client Identity Allows Rate-Limit Bypass
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a documentation-only backend patterns skill with no executable install steps, persistence, or hidden authority, though a couple of sample snippets should be treated as starting points rather than production-ready security code.
Safe to install as a reference skill. Treat the snippets as architectural examples, not drop-in security-hardened code; tighten rate limiting, logging, authentication, and authorization before using them in production.
SKILL.md:452Spoofable Client Identity Allows Rate-Limit Bypass
SKILL.md:553Raw Exception Messages and Stack Traces May Expose Sensitive Information in Logs
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
POST /api/markets # Create resource
PUT /api/markets/:id # Replace resource
PATCH /api/markets/:id # Update resource
DELETE /api/markets/:id # Delete resource
// ✅ Query parameters for filtering, sorting, pagination
GET /api/markets?status=active&sort=volume&limit=20&offset=0
No suspicious patterns detected.