T09 · Insecure Skill Coding Practices
- Location
references/job-manifest-template.json:18- Finding
Hard-Coded Discord Recipient in Reusable Delivery Examples
- Content
View full analysis
Vulnerability Details
File Locations:
references/architecture-patterns.md:153-158references/example-migration-daily-briefing.md:67-72references/job-manifest-template.json:18-23
Vulnerability Type: Hard-coded external delivery recipient
Risk Level: MediumVulnerable Code
references/architecture-patterns.md:153-158:json { "delivery": { "channel": "discord", "target": "user:270548320366100480", "accountId": "default" } }references/example-migration-daily-briefing.md:67-72:json "delivery": { "channel": "discord", "target": "user:270548320366100480", "accountId": "default", "mode": "runtime-send" },references/job-manifest-template.json:18-23:json "delivery": { "channel": "discord", "target": "user:270548320366100480", "accountId": "default", "mode": "runtime-send" },Technical Analysis
The reusable architecture example, migration example, and job-manifest template contain the same concrete Discord user ID instead of an unmistakable placeholder. These documents are intended to be copied or adapted when configuring scheduled jobs.
Because the value is syntactically valid and is presented as the recommended provider-aware delivery format, an operator or automation agent may retain it without realizing that it identifies a specific external account. If the resulting manifest is activated, generated reports, briefings, alerts, attachments, or test messages could be delivered to that account.
This issue does not independently bypass authorization or acquire additional system privileges. Exploitation depends on a user or agent copying the example and subsequently approving or enabling outbound delivery. Nevertheless, the concrete identifier creates a credible unsafe-default condition in a reusable configuration template.
Attack Path
- An operator or agent follows the documente ...[truncated 1231 chars]
- Remediation
View remediation
Remediation Suggestions
-
Replace the concrete Discord identifier in every reusable example with an explicit placeholder:
json "target": "user:<DISCORD_USER_ID>" -
Ensure the placeholder is intentionally invalid until deployment-specific configuration supplies a recipient.
-
Add manifest validation that rejects unresolved placeholders and example recipient values.
-
Require the delivery target to come from trusted local configuration or explicit user input rather than copied documentation.
-
Before any live test or production activation, display the resolved channel, account, and recipient and require explicit confirmation.
-
Add a dry-run mode that records the resolved recipient without transmitting content.
-
Review existing manifests derived from these examples and replace any retained occurrence of
user:270548320366100480unless the operator independently verifies it as the intended recipient. -
Add an automated repository check that prevents concrete external account identifiers from being committed to reusable templates.
-
