T09 · Insecure Skill Coding Practices
- Location
schemas/render_plan.schema.json:13- Finding
Unrestricted RenderPlan Targets Permit Arbitrary File Overwrite
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a disclosed code-artifact generator, but it gives agents under-scoped authority to write generated code files and persistent patterns.
Install only for an LQS repository where you are comfortable reviewing generated PHP, SQL, and template changes before they are written. Require explicit per-file approval using canonical in-repo paths, do not allow absolute or parent-directory targets, review migration rollback behavior carefully, and do not let session-derived patterns become trusted project context without maintainer review.
schemas/render_plan.schema.json:13Unrestricted RenderPlan Targets Permit Arbitrary File Overwrite
templates/template_pack.blueprint.json:21Raw Placeholder Substitution Enables Generated PHP, SQL, and Markup Injection
templates/generated/migration_create_table.txt:17Unsafe JSON Embedding Allows PHP Source Injection in Generated Migrations
implementation_runbook.md:5Session-Derived Inferences Can Poison Persistent Agent Context
File system write capability is not justified by the described purpose of the skill, which is generation of drafts, specs, render plans, and preview diffs. A model-directed write step increases the risk of arbitrary file modification, accidental overwrites, or abuse through crafted input that influences target content or destinations, especially if downstream tooling treats the prompt as authority.
The prompt explicitly instructs writing files when approval is given, which exceeds the manifest’s stated scope of a manual, preview-oriented artifact generator. Even with an approval gate, embedding file-write behavior in the skill creates an operational side effect that can turn prompt output into unauthorized or unintended repository changes if an integrating agent honors it.
The manifest says this skill is a prompt/schema/template-driven artifact generator and explicitly states it does not execute code or run migrations. This template is specifically a runnable PHP migration that inserts and deletes records in the permissions table via database calls, which goes beyond a purely documentation/spec-generation role and conflicts with the stated no-migrations scope.
The manifest says this skill is an artifact generator and explicitly states it does not execute code or run migrations automatically. This template defines executable migration methods that issue CREATE TABLE and DROP TABLE statements via \DB::statement, which is behavior beyond pure artifact generation if used as part of the skill's code path.
The activation phrases include very generic developer requests such as "generate controller", "generate model", and "preview diff", which can unintentionally trigger this skill during unrelated coding tasks. Because the skill is prompt-driven and consumes free-text user input, accidental invocation could steer an agent into generating artifacts or workflow steps outside the user's intended context, increasing the risk of incorrect changes or prompt-scope confusion.
The domain glossary defines core workflow terms exclusively in Chinese (e.g. 后台, 列表, 保存, 删除, 预览), which indicates a language-specific operating assumption in the skill context. The file does not offer any language preference, opt-in, or justification that this skill is intended only for Chinese-language users or a China-specific environment.
The JSON content is entirely written in Chinese, including feature descriptions, constraints, assumptions, and ambiguities, with no indication that the user can choose another language or that the skill is intentionally limited to a Chinese-language context. This creates a natural-language policy concern because it effectively imposes a locale/language choice without opt-in or justification.
The documented workflow describes automatic retrieval and transformation of Google Doc content from a link, directly contradicting the skill's declared manual-run, no-auto-fetch behavior. In a prompt-driven artifact generation skill, this inconsistency increases the risk of unauthorized external data ingestion, accidental collection of sensitive document content, and operator misunderstanding about what the skill is permitted to do.
The example contract explicitly documents taking a public Google Doc link and fetching the document body, which conflicts with the stated skill boundary that it does not fetch external documents automatically. This kind of contract/manifest mismatch is dangerous because downstream agents or operators may enable network retrieval behavior that bypasses expected trust boundaries, privacy review, or data-handling controls.
The title and the entire runbook are written in Chinese, presenting the skill instructions in a single enforced language. Under the policy, language constraints should either offer a user choice or be clearly justified as region-specific, which is not stated here.
The manifest describes a prompt-driven artifact generator that does not execute code or run migrations. This runbook explicitly includes 'migration' in the generated TemplatePack and sets a migration table-prefix convention, which expands the skill behavior into database-migration artifact generation beyond the manifest's stated limitation.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
"migration_rules": {
"prefix": "typecho_",
"must_have": ["up", "down"],
"execution": "generate only, no auto run"
},
"known_exceptions": [
{
The prompt begins in Chinese and frames the skill as a Chinese-language requirements analyzer, which implicitly constrains language/locale behavior. There is no indication that the user may choose another language or that this restriction is required for a region-specific compliance reason.
Line L01 states the role entirely in Chinese and establishes the skill behavior in a fixed language, with no indication that the user can choose another language or locale. Under the policy, forcing a specific language without opt-in is a natural-language policy violation.
The file’s natural-language instructions are entirely in Chinese, beginning with '你是规格解析器。', which imposes a specific language context without offering the user any language or locale choice. Under the policy, forcing a language without opt-in is a natural-language policy violation unless clearly justified as region-specific, which is not documented here.
The entire skill prompt is written in Chinese and does not indicate that the language is configurable or based on user preference. Per the policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale constraint is documented and justified.
Line L01 states the skill role entirely in Chinese, and the file provides no option for user language preference or any justification that this is a region-specific tool. This creates a natural-language policy concern because it implicitly constrains the skill to a specific language without opt-in.
Labeling the prompt as a 'write executor' materially conflicts with the manifest’s preview-focused workflow and signals an operational role the skill is not supposed to have. This mismatch can cause integrators or agents to grant broader capabilities than intended, weakening trust boundaries and increasing the chance of unsafe side effects.
The file begins with Chinese-only instructions ('你是 LQS Skill 的写入执行器') and the rest of the skill content is also written entirely in Chinese. This creates a language policy concern because it imposes a specific language/locale without any opt-in or documented justification that the skill is region-specific.
The quickstart describes the skill entirely in Chinese and explicitly positions it as a natural-language analysis skill, which implies a language expectation for user interaction. There is no indication that users may choose another language or that the Chinese-only presentation is a justified region-specific requirement, which can violate language/locale policy expectations.
The file’s title and substantive instructions are presented in Chinese, and nowhere in the document is there an opt-in, alternate language option, or justification that the skill is region-specific. Under the policy rule, forcing a specific language without user choice is a natural-language policy violation.
The header comment explicitly frames the file as generation-only and non-auto-executing, yet the class body includes \DB::statement($sql) in both up() and down(). That is a direct contradiction between the file's stated intent and what the code does when executed.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
/**
* Auto-generated migration template from LQS project patterns.
* Note: generate only, do not auto-execute.
*/
class {{class_name}}
{
This code performs an irreversible database table deletion via DROP TABLE IF EXISTS, but the file provides no user-facing confirmation, prompt, or explicit warning about the destructive action. Although there is a brief comment that custom down logic is optional, it does not disclose to users that rollback will delete the table.
This JSON manifest contains multiple natural-language strings in Chinese, including field labels and assumption/ambiguity text, but does not indicate that the skill is intentionally region-specific or provide any user opt-in for language/locale. Under the policy rule for natural-language constraints, hard-coding a specific language without justification can be a policy violation.
No suspicious patterns detected.