T09 · Insecure Skill Coding Practices
- Location
SKILL.md:107- Finding
Unredacted task output may be forwarded to a hard-coded external channel
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:107-116,SKILL.md:149-164, andSKILL.md:295-305
Vulnerability Type: Unredacted disclosure of command output
Risk Level: MediumThe skill specification forwards portions of process output and error logs directly through the messaging tool. Progress and completion notifications explicitly select the
feishuchannel instead of deriving the destination from the authenticated originating conversation.Relevant progress-reporting code:
javascript if (result.output && result.output !== lastOutput) { const newLines = result.output.slice(lastOutput.length); if (newLines.trim()) { await message({ channel: 'feishu', message: `📊 任务进展:\n\`\`\`\n${newLines.slice(-500)}\n\`\`\`` }); lastOutput = result.output; silentSince = Date.now(); } }Relevant completion-notification code:
javascript const status = result.exitCode === 0 ? '✅' : '❌'; const duration = formatDuration(result.durationMs); await message({ channel: 'feishu', message: `${status} **任务完成!** 耗时:${duration} 退出码:${result.exitCode} ${result.exitCode === 0 ? '🎉 一切顺利!' : '⚠️ 任务失败,请检查日志'} ${fullLog.output ? '最近输出:\n```\n' + fullLog.output.slice(-1000) + '\n```' : ''}` });Relevant error-reporting code:
javascript if (result.exitCode !== 0) { const errorLog = await process({ action: 'log', sessionId, offset: -50, limit: 50 }); await message({ message: `❌ **任务失败!** 退出码:${result.exitCode} 错误摘要:\n\`\`\`\n${errorLog.output.slice(-500)}\n\`\`\` 需要我帮你分析问题原因吗?` }); }Technical Analysis
Build, deployment, migration, and model-training commands commonly print environment variables, authenticated URLs, access tokens, private filesystem paths, database records, or infrastructure identifiers. Limiting the output to the final 500 or 1,000 char ...[truncated 1782 chars]
- Remediation
View remediation
Remediation Suggestions
- Route notifications only to the authenticated conversation and channel that originated the task. Do not hard-code
feishu. - Require explicit user approval before sending task output to a different channel, conversation, or recipient.
- Apply secret redaction before transmission. Detect common token formats, authorization headers, private keys, credential-bearing URLs, passwords, and configured secret values.
- Prefer structured status summaries over raw logs. Raw log delivery should be opt-in and restricted to authorized recipients.
- Normalize and sanitize output before embedding it in Markdown to prevent formatting or mention injection.
- Add configurable output limits and a policy that completely suppresses output for tasks classified as sensitive.
- Add tests verifying that secrets are removed and that notification destinations cannot differ from the originating context without authorization.
- Route notifications only to the authenticated conversation and channel that originated the task. Do not hard-code
