T09 · Insecure Skill Coding Practices
- Location
scripts/search_cases.py:104- Finding
TLS Certificate and Hostname Verification Disabled
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill’s legal-research purpose is coherent, but its scripts disable TLS verification while sending an API key and potentially sensitive case details to an external legal API.
Review before installing. Use this only if you are comfortable sending legal search terms to DeliLegal, and redact personal or privileged facts. The TLS verification bypass should be fixed before real use, and the API key should preferably be stored in an environment variable or secret store rather than a project-local config file.
scripts/search_cases.py:104TLS Certificate and Hostname Verification Disabled
config.json:1API Key Stored in a Plaintext Project-Local Configuration File
声明描述的是一个较完整的诉讼分析与报告生成型技能,包含案件分析、争议焦点拆解、诉讼策略制定、法条与类案检索等复合能力。但提供的代码只调用单一案例检索 API,返回案例列表并做展示格式化。虽然其中“类案检索”这一子能力与声明部分重合,但代码未体现声明中的核心主功能——自动生成诉讼策略与类案检索报告,也未实现法条检索或庭前准备分析。因此描述明显高于实际行为,属于实质性不匹配。
声明描述的是一个较高层的诉讼分析/策略/类案检索技能,核心应包括基于案情进行争议焦点分析、制定诉讼策略,并结合类案与法条形成报告。但代码仅实现了“法规检索”这一子能力:向法律开放平台发送查询、获取法规列表并格式化展示。虽然声明中提到法条检索,代码确实覆盖该部分,但没有任何案件事实解析、争议焦点提炼、诉讼策略生成、类案检索或报告编排逻辑。因此代码行为只覆盖声明中的一小部分,且与其宣称的主要用途存在实质性偏差,属于描述与实际行为不匹配。
The script explicitly disables TLS certificate validation and hostname verification before sending the API key and user-supplied legal case queries. This enables man-in-the-middle interception or tampering of traffic, exposing credentials and potentially sensitive case facts; in a litigation-analysis skill, the transmitted content may include confidential or highly sensitive legal information, which increases the severity.
The script explicitly disables TLS hostname verification and certificate validation before sending both the legal query and the Bearer API token. This allows a man-in-the-middle attacker with network position or a malicious proxy/root CA environment to intercept or tamper with requests and responses, potentially stealing the API key and altering legal research results.
The skill documents use of file reads and outbound network access to load an API key from config.json and send queries to an external legal API, but it does not declare any explicit tool scope or allowed-tools policy. This weakens least-privilege controls and makes it harder for a host system to constrain or review what resources the skill may access, especially because case facts may contain sensitive personal or litigation information.
The markdown explicitly says to use the skill when the user mentions phrases like "案件分析", "诉讼策略", "类案检索", "法条检索", or "庭前准备", and also lists broad examples such as "打官司方案" and "胜诉率评估". These are common legal-assistance requests rather than narrowly scoped invocation commands, and the file does not provide exclusion conditions or negative examples to clarify when the skill should not activate.
The skill instructs sending search queries and potentially long-form case material to an external legal API, but it does not provide a user-facing notice or consent step about transmitting potentially sensitive case facts. In the litigation context, those facts may include personal data, privileged strategy, or confidential dispute details, so silent transmission creates a meaningful privacy and confidentiality risk.
The guidance includes example case-search queries containing identifiable personal names and a full case number, but it provides no caution about minimizing, anonymizing, or lawfully handling personal and case-identifying data. In a litigation-analysis skill, users are likely to paste real pleadings, party names, IDs, contact details, and case numbers into search commands; normalizing that behavior without privacy guardrails increases the risk of unnecessary disclosure to downstream tools, logs, and third-party data sources.
The script's docstring, CLI descriptions, help text, and output messages are written exclusively in Chinese, which imposes a specific language on users without presenting an opt-in or alternative locale. The policy specifically calls out forced language or locale behavior as a natural-language violation unless choice or clear justification is provided.
This code loads an API key from local configuration and sends the user's query content to a third-party legal platform over HTTP(S), but the CLI flow provides no user-facing notice that their input and credentials will be transmitted externally. For a code file, network transmission of user or system data should have some visible disclosure such as a prompt, print/log message, or explicit warning in the interface.
All user-facing documentation and output strings in this file are written exclusively in Chinese, which effectively imposes a language/locale choice on users without opt-in. The policy allows locale constraints only when clearly documented and justified, or when users are given a choice.
This code performs a POST request to an external legal platform and transmits the user's search query together with an API bearer token, but there is no print/log message, confirmation prompt, or explicit warning near execution that user-entered queries are sent to a third-party service. For a code file, outbound network transmission of user data should have some visible disclosure unless the warning is otherwise provided.
The script reads an API key from config.json and uses it for authenticated requests, but there is no visible runtime disclosure that the skill accesses local credentials. Access to sensitive credentials in code files should include at least a comment, docstring, or user-facing note describing the behavior.
Detected: suspicious.insecure_tls_verification