T09 · Insecure Skill Coding Practices
- Location
config_example.env:4- Finding
Hardcoded Xianyu API Credentials Distributed with the Skill
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent Xianyu API client, but it ships credential-like example secrets for an API that can change shop products and orders, so it should be reviewed before installation.
Install only if you need Xianyu shop automation, use a dedicated low-permission Xianyu application key, avoid the bundled example values, and rotate/revoke any credentials matching the published examples. Treat _unsafe methods as automation-only because they bypass the normal confirmation prompt.
config_example.env:4Hardcoded Xianyu API Credentials Distributed with the Skill
The example .env file contains what appear to be concrete API credentials rather than obvious placeholders. If these are real or accidentally valid secrets, publishing them can enable unauthorized access to the Xianyu Guanjia API, account misuse, data exposure, or abuse of privileged actions; the skill context increases risk because this client interacts with a real external API and supports automation.
# 闲鱼管家API配置示例
# 请将此文件重命名为 .env 并填入您的实际密钥
XIAN_YU_APP_KEY=203413189371893
XIAN_YU_APP_SECRET=o9wl81dncmvby3ijpq7eur456zhgtaxs
The skill requires sensitive environment variables (XIAN_YU_APP_KEY, XIAN_YU_APP_SECRET) but does not declare an explicit tool scope such as permissions or allowed-tools. That creates an authorization transparency gap: an agent platform or reviewer may not clearly understand that the skill consumes secrets, increasing the chance of overbroad installation or unintended secret exposure in downstream automation.
This Python file contains hard-coded Chinese user-facing confirmation text, such as the high-risk operation prompt and continuation question. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not documented here.
Most of the skill description and operational guidance is written in Chinese, while some security sections are in English, and the document does not state any supported language options or allow the user to choose a preferred locale. This can violate a language/locale policy when skills are expected to respect user language preferences rather than implicitly forcing one.
The natural-language comments at L1-L2 are exclusively in Chinese, which can impose a language requirement on users without any opt-in or justification. The policy requires flagging language or locale constraints when the skill forces a specific language without user choice.
No suspicious patterns detected.