T09 · Insecure Skill Coding Practices
- Location
scripts/get_coupon.py:22- Finding
Hard-Coded API Credentials Exposed and Transmitted to an External Service
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This shopping coupon skill mostly does what it says, but it can run a local self-update command and ships exposed API credentials and unsafe temporary caching.
Review this skill before installing. It appears intended for Chinese-language shopping deals and does not show user data exfiltration, but it contacts a third-party coupon service, includes exposed service credentials, writes a shared temporary cache, and can update its own installed package through the local ClawHub CLI when prompted. Prefer a version that removes in-band self-update, rotates and protects API credentials, and stores cache data in a private per-user directory.
scripts/get_coupon.py:22Hard-Coded API Credentials Exposed and Transmitted to an External Service
scripts/get_coupon.py:17Predictable Shared Temporary Cache Allows Cache Poisoning and Symlink Attacks
The declared purpose is a simple shopping-deals helper, but the detected behavior includes outbound third-party API calls, embedded credentials, local cache read/write activity, and execution of an external self-update subprocess. That mismatch is dangerous because it conceals materially sensitive behaviors, including secret exposure and arbitrary command execution pathways, which can be abused far beyond the user’s reasonable expectations for a shopping skill.
The skill declares no permissions or allowed-tools, yet the analyzed behavior indicates file access, network access, shell execution, and file writes. This creates a transparency and sandboxing gap: reviewers and orchestrators cannot accurately constrain what the skill may do, increasing the risk of unauthorized data access, external exfiltration, or command execution.
The trigger terms are broad enough to match ordinary shopping-related conversation, which can cause the skill to activate in contexts the user did not intend. Because the skill appears to have network, file, and shell-capable behavior, overbroad invocation materially raises the chance of unnecessary data processing or unintended execution of risky functionality.
The example phrases are short, ambiguous, and unconstrained, making accidental invocation likely. In a skill with hidden external calls and execution-related capabilities, ambiguous examples amplify risk by encouraging activation from generic product discussions rather than explicit consent to use a third-party shopping aggregator.
Suspicious Unicode normalization or mixed-script content
This Python skill contains user-facing comments, prompts, help text, and output entirely in Chinese, and the interaction flow assumes Chinese-language commands such as "升级" and example queries like "外卖优惠". That creates a language/locale policy issue because the skill enforces a specific language without offering the user any explicit language selection or opt-in.
A coupon helper should provide shopping advice, but this code also performs privileged local maintenance by upgrading itself. That mismatch is dangerous in agent environments because a benign-looking skill can be prompted into altering local software state, potentially pulling and running new code not reviewed in the current version.
The script can invoke a local subprocess to run clawhub update shopping-helper, which gives a shopping coupon skill the ability to trigger local software maintenance. Even though the command is hardcoded and not shell-injected, executing package/update operations from a user-invokable skill increases the attack surface and could install changed code from an external source if the update channel is compromised or abused.
print(f"🔍 正在检测 {SKILL_NAME} 最新版本...\n")
try:
result = subprocess.run(
["clawhub", "update", SKILL_NAME],
capture_output=True,
text=True,
The skill metadata and apparent purpose are shopping/coupon assistance, but the runtime behavior includes software update functionality. This makes the context more dangerous because users or orchestrators may grant the skill broader trust than warranted, not expecting it to execute local maintenance commands based on conversational triggers like '升级'.
All user-facing instructions and examples are presented only in Chinese, and the skill does not state that language selection is optional or limited to a China-specific audience. This can constitute a language/locale policy issue when a skill implicitly enforces one language without user opt-in or documented justification.
No suspicious patterns detected.