T09 · Insecure Skill Coding Practices
- Location
scripts/geekbi_auth.py:267- Finding
Authentication Tokens Are Mirrored into Skill and Working Directories
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears to be a real GeekBI Temu keyword-search helper, but it stores login tokens in extra local folders and trusts server-supplied links, so it should be reviewed before installation.
Install only if you trust GeekBI and are comfortable with the skill saving authentication state locally. Avoid running it from shared, synced, or version-controlled workspaces until token storage is limited to a protected user config or credential store, and do not use custom base URLs unless you control and trust the endpoint.
scripts/geekbi_auth.py:267Authentication Tokens Are Mirrored into Skill and Working Directories
scripts/temu_keyword_search.py:155Arbitrary and Plaintext Authentication Endpoints Are Accepted
scripts/geekbi_auth.py:372Server-Controlled Links Are Displayed without Scheme or Host Validation
The declared purpose is Temu keyword analysis, but the observed behavior includes invoking a site-list lookup flow instead of directly performing keyword analysis. Description-behavior mismatches are dangerous because they undermine user consent and reviewer trust; a skill can appear narrowly scoped while actually accessing different resources or performing unexpected actions.
The README says '安装后直接用中文描述目标即可', which imposes Chinese as the interaction language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified or alternatives are offered.
The skill instructs the agent to read local reference files and execute Python scripts, which implies file, shell, and likely network capabilities, but it declares no explicit tool scope or allowlist. This weakens least-privilege controls and can let a broader tool-enabled runtime execute actions the user did not clearly authorize, increasing the blast radius if the skill is misused or modified.
Line L11 states the skill will '默认使用简体中文' (use Simplified Chinese by default). This imposes a language choice without indicating user consent or offering a language option, which matches the language/locale policy violation criteria.
The display name, description, and default prompt are entirely in Chinese, which implies a fixed language choice for the skill experience. There is no indication that users can choose another language or that the locale restriction is intentional and documented for a region-specific use case.
Line L126 says that when exit code is 1, the user should be shown only the Chinese message text. This imposes a specific language on the user without opt-in or any documented locale justification, which matches the language/locale policy violation criteria.
This code file uses natural-language strings that explicitly define the skill as a Chinese-language login/status manager, and all user-facing messages/help text throughout the file are in Chinese. Under the language/locale policy, forcing a specific language without user opt-in or a documented region-specific justification is a policy concern.
The clear_auth_state function unlinks authentication state files from multiple storage locations, which is a destructive operation affecting persisted login data. The function itself contains no confirmation prompt, warning comment/docstring, or user-facing disclosure at the point of deletion.
This Python file contains user-facing descriptions, help text, and error messages entirely in Chinese, including the module docstring, CLI argument help, and runtime error/output strings. Because the skill does not offer a language/locale option or document that it is intentionally limited to Chinese-speaking users, it appears to impose a specific language without user opt-in.
The instruction says '默认使用简体中文', which imposes a language default in the skill's responses. Under the policy, forcing a specific language without explicit user choice or opt-in is a natural-language policy concern unless the locale constraint is clearly justified.
This code file contains natural-language strings entirely in Chinese, including the module docstring, argument descriptions, and runtime error messages. Under the policy rule for language/locale, forcing a specific language without opt-in or justification is a natural-language policy violation.
No suspicious patterns detected.