T09 · Insecure Skill Coding Practices
- Location
references/coder.md:11- Finding
Overbroad Git Staging Can Commit Unrelated or Sensitive Files
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a coherent code-development workflow, but it directs agents to make broad persistent repository and filesystem changes without a clear user approval boundary.
Install only if you want a Chinese-language, highly structured development pipeline and are comfortable supervising its local side effects. Before use, require explicit confirmation before Git commits, avoid `git add .`, review staged files, and revise logging templates so generated code does not store raw personal data.
references/coder.md:11Overbroad Git Staging Can Commit Unrelated or Sensitive Files
references/coder.md:107Logging Templates Encourage Storage of Raw Personal and Attacker-Controlled Data
The skill declares it 'must' be used for very broad triggers like writing code, implementing features, frontend work, or any request with code-quality expectations. This can cause the agent to route many ordinary coding tasks into a rigid multi-step workflow without clear user consent, overriding narrower system behavior and creating an unsafe prompt-scope expansion path. The danger is amplified because the skill is positioned as mandatory and auto-executing, so benign coding requests may be captured unintentionally and processed under adversarial skill instructions.
The skill description and operational instructions are written as mandatory Chinese-language guidance, but there is no indication that the user may choose another language or that the skill is intentionally limited to a Chinese-speaking context. This can violate language/locale policy when a skill implicitly forces a specific language without opt-in.
The manifest description and change notes are entirely in Chinese, with no indication that users can choose another language or that the locale restriction is intentional. This creates a natural-language policy concern because the skill appears to impose a specific language without opt-in or justification.
The title and core instruction are written entirely in Chinese and define the assistant role in Chinese without offering any language choice or opt-in. This creates a natural-language locale constraint that could conflict with organizational language policy for multilingual users.
This markdown skill specifies its role and operating instructions exclusively in Chinese, which effectively forces a specific language on users. The policy allows fixed locale/language only when users are given a choice or the constraint is clearly documented and justified, neither of which appears here.
This markdown skill file uses Chinese as the sole required operating language and does not indicate that users may opt into another language. Under the language/locale policy, forcing a specific language without user choice is a natural-language policy violation unless clearly justified as region-specific.
The skill explicitly requires Git commits for all code changes, which causes persistent repository modification beyond the narrow task of code implementation. In an agent setting, this can create unintended state changes, leak work into commit history, and interfere with user workflows or branch hygiene without explicit consent.
The logging guidance instructs recording user identifiers and email addresses in plaintext logs. This creates unnecessary exposure of personal data in log pipelines, backups, support tooling, and incident artifacts, increasing privacy and compliance risk if logs are accessed or retained broadly.
The example implementation repeats the unsafe pattern by logging user email addresses in both normal request logs and error paths. Because examples are likely to be copied directly into production code, this materially increases the chance of widespread PII leakage across generated applications.
The document is written as mandatory operating instructions in Chinese and defines the coordinator role without indicating that language should follow the user's preference. This creates a language/locale policy issue because the skill appears to force a specific language rather than offering opt-in or user choice.
The skill file is written as a mandatory Chinese-language reviewer instruction and does not offer any user opt-in or alternative locale. Under the policy, forcing a specific language without user choice is a natural-language locale violation.
This markdown skill is written entirely in Chinese and explicitly requires a fixed output format using Chinese status labels like 【通过】 and 【发现bug】. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless the constraint is justified or optional.
The validator instructions hard-code Chinese-only output and do not offer any user language choice or document a legitimate locale restriction. In a general-purpose code development pipeline, this can cause users or downstream reviewers to misunderstand acceptance results, miss blocking issues, or fail to validate whether security and quality requirements were actually met.
The document is written entirely in Chinese and embeds Chinese-only prompt instructions for all roles, with no indication that users may select another language. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy concern unless the locale restriction is documented and justified.
The workflow explicitly persists generated artifacts to the local filesystem and updates a current symlink automatically, but it provides no consent gate, path safety checks, or warning to the user that agent output will modify disk state. In an agent skill used for code generation, this increases risk of unintended file writes, overwrite of prior artifacts, or misuse of attacker-influenced project names/paths if later wired to untrusted input.
The skill mandates repository-changing Git operations without clearly warning the user that it will create commits and modify project history. This reduces informed consent and can surprise users with persistent side effects, especially in shared or regulated repositories.
No suspicious patterns detected.