T09 · Insecure Skill Coding Practices
- Location
references/patterns.md:1127- Finding
Predictable Fallback Token and Plaintext Token Transmission
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent URMA migration guide, but its reference material can steer generated code toward unsafe remote-memory token handling and unauthenticated network exposure.
Review before installing. This skill should only be used by developers who can audit the generated URMA security model. Do not copy its token or client/server examples into production without replacing fixed tokens, adding authenticated encrypted control channels, limiting exported memory and access flags, and binding listeners only to trusted interfaces.
references/patterns.md:1127Predictable Fallback Token and Plaintext Token Transmission
references/pitfalls.md:34Mandatory Migration Guidance Presents Fixed and Plaintext Tokens as a Correct Pattern
references/urma_sample.md:215Canonical Sample Exposes Broadly Writable URMA Memory to Unauthenticated Network Peers
Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.
// 9. Delete event channel
if (jfce) urma_delete_jfce(jfce);
// 10. Delete context
urma_delete_context(ctx);
// 11. Free device list
Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.
// 9. Delete event channel
if (jfce) urma_delete_jfce(jfce);
// 10. Delete context
urma_delete_context(ctx);
// 11. Free device list
The skill description says to invoke on broad terms like 'rdma', 'ibv_*', or 'urma', which can match general troubleshooting, architecture discussion, or educational questions rather than an actual migration request. Over-broad activation can route users into a high-impact code transformation workflow unnecessarily, increasing the chance of unwanted file generation, incorrect guidance, or unsafe automated edits in contexts where migration was not intended.
The 'When to Use This Skill' section lists short keyword-based triggers without boundaries, disambiguation rules, or exclusions. In an agentic environment, this makes accidental invocation likely, which is dangerous because the skill performs prescriptive multi-phase migration steps and can steer analysis or code changes even when the user's goal is only discussion, review, or debugging.
Suspicious Unicode normalization or mixed-script content
The document shows transmitting URMA access tokens over sockets with no warning that these tokens may authorize remote memory operations. In this skill context, that omission is more dangerous because readers are likely to copy migration examples directly into production or test harnesses, causing credential exposure, unauthorized segment imports, and possible remote memory read/write abuse if the channel is intercepted or spoofed.
The skill is scoped as an API migration guide, but it introduces token exchange over raw TCP/socket without authentication, confidentiality, integrity protection, or clear trust-boundary guidance. Because these tokens gate remote memory access/import operations, normalizing ad hoc network exchange in migration docs can lead downstream users to ship insecure credential transport in real deployments.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
.max_sge = 13, .max_rsge = 13, // Wrong! Device max_jfs_rsge = 1
// ❌ Set without checking device capabilities .depth = user_value, // may exceed max_jfs_depth
The reference documentation presents the sample as a canonical client/server URMA implementation but does not warn that it performs real network communication and exchanges remote memory addressing metadata such as EID, UASID, segment virtual address, and jetty identifiers. In a migration skill, users may copy or run this example in inappropriate environments, increasing the chance of unintentionally exposing RDMA-accessible memory or testing against reachable hosts without understanding the trust assumptions.
No suspicious patterns detected.