T09 · Insecure Skill Coding Practices
- Location
scripts/search_cases.py:92- Finding
TLS Certificate and Hostname Verification Disabled in External API Clients
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears purpose-aligned, but it needs review because its legal search scripts can send sensitive queries and API keys to a third-party service without server identity checks.
Review before installing. Do not use this with confidential or privileged matter details until TLS verification is fixed, and redact names, identifiers, account data, trade secrets, and unnecessary facts before any external search. Configure a real API key carefully, rotate it if previously used on untrusted networks, and verify all legal results against official sources.
scripts/search_cases.py:92TLS Certificate and Hostname Verification Disabled in External API Clients
config.json:1Shipped API-Key Placeholder Bypasses Placeholder Validation
SKILL.md:111External Legal Search Can Transmit Identifying or Confidential Case Material Without Mandatory Redaction
声明描述的是一个较完整的案件接案评估能力,核心产出应是结构化案件初评报告,并包含多项分析与预测功能。实际代码的主功能非常单一:接收关键词或长文本,调用外部案例检索 API,返回裁判文书列表并格式化展示。虽然声明中提到“司法裁判检索”,这与代码有部分重合,但这只是声明能力中的一个子环节,且代码没有实现其余关键分析能力。因此主目的和实际行为存在实质性不一致,应判定为 mismatch。
声明描述的是一个综合性的接案评估/案件初评工具,核心能力应包括案件材料分析、风险识别、裁判检索以及结果预测和成本测算。而代码仅实现了“法律法规检索”这一单一功能,且检索对象是法规而非案件、证据或司法裁判。代码中没有任何关于案件信息输入建模、报告生成、评估逻辑、概率/周期/成本计算、争议焦点提炼或补证建议的实现。虽然法规检索可作为案件评估的辅助环节,但当前代码的主要目的与声明的主要用途存在明显且实质性的偏差,因此应判定为描述与实际行为不匹配。
The code explicitly disables hostname verification and certificate validation before sending an authenticated HTTPS request with a bearer API key. This enables man-in-the-middle interception and tampering, allowing an attacker on the network path to steal the API key, read sensitive legal queries, or modify returned case results.
The code explicitly disables both certificate validation and hostname verification before sending an authenticated HTTPS request with a Bearer API key. This enables man-in-the-middle interception or response tampering, allowing an attacker on the network path to steal credentials, alter legal search results, or inject misleading regulatory content into downstream case assessments.
By disabling TLS verification without any warning, the script silently weakens transport security for all users and conceals the risk that API traffic may be intercepted or modified. In a legal-intake context, this is especially sensitive because search terms may reveal confidential dispute facts and poisoned responses could skew legal analysis or case acceptance decisions.
The skill instructs use of local files (config.json, reference docs) and external API-backed scripts, but it declares no explicit tool scope or permission boundaries. Without clear permissions/allowed-tools, an agent runtime may grant broader-than-necessary file and network access, increasing the chance of unintended data exposure or misuse during handling of sensitive legal matter inputs.
The skill is designed to process highly sensitive legal case facts, evidence, identities, and strategy information, and it may transmit search content to an external legal API. Without an explicit privacy/confidentiality warning, data-minimization guidance, or consent step, users may disclose privileged or personal information that is then unnecessarily shared outside the local session.
The file title and instructions are entirely written in Chinese and prescribe a fixed response format for legal assessment outputs, but they do not indicate that language selection is optional. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless clearly justified as region-specific.
The instruction explicitly requires the output to use Chinese ("使用正式、清晰、可供律师复核的中文"). Under the policy, forcing a specific language is a natural-language locale violation unless the skill offers a language choice or clearly documents a justified regional constraint; this file does not provide either within the template.
The document title and all operational guidance are presented exclusively in Chinese, which effectively constrains use of the skill to a specific language/locale. The file does not indicate that the user may choose another language or that the Chinese-only constraint is an explicit, justified regional requirement.
The module docstring and command-line help text are written in Chinese only, which imposes a specific language on users without any opt-in or explanation of a region-specific requirement. This is a natural-language policy issue because the skill does not present an explicit language/locale choice.
The docstring, CLI help text, and user-facing output are presented exclusively in Chinese, with no indication that users can select another language or that the skill is intentionally limited to a Chinese-speaking context. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation.
The manifest describes a skill for generating a案件初步评估报告 based on case facts, evidence, claims, jurisdiction, and related risk/cost/probability analysis. This script instead implements a generic法规检索 client that sends user queries to a third-party legal platform and formats search results, which is a materially distinct end-user capability rather than merely internal report-generation logic.
The description is written to generate reports specifically for '中国大陆' dispute-resolution scenarios, and the skill content consistently mandates that role and output context. While the legal scope is justified, the file provides no explicit user choice on output language/locale, creating a potential locale-policy issue if broader language flexibility is expected.
The formatter docstring and comments describe the API result as using a standard nested body/data structure, with compatibility for an older top-level data format. However, search_cases returns json.loads of the raw HTTP response directly, while error paths return a synthetic object with body as a string, so the documented structure does not consistently match actual function inputs and behavior.
Detected: suspicious.insecure_tls_verification