T09 · Insecure Skill Coding Practices
- Location
SKILL.md:159- Finding
Shell Command Injection Through an Unvalidated X Username
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent coffee-chat research helper, but it needs review because it combines social scraping, third-party export, persistent credentials, and an unsafe shell example.
Review before installing. Use only public information for legitimate networking preparation, avoid scraping unless you are comfortable with the platform and privacy implications, do not paste untrusted X handles into the provided shell command, and store Notion or Apify tokens in a proper credential store rather than a shell profile. Treat Notion export as sending the playbook and researched personal details to a third-party workspace.
SKILL.md:159Shell Command Injection Through an Unvalidated X Username
SKILL.md:59Notion API Token Persisted in a Plaintext Shell Startup File
SKILL.md:31Unpinned Apify CLI and Mutable Third-Party Scraper Actor
This markdown skill explicitly lists trigger phrases, but some are broad enough to overlap with ordinary requests unrelated to networking coffee chats. Terms like "meeting prep" and "chat playbook" lack domain constraints, increasing the chance of unintended activation.
The manifest presents the skill as simple coffee-chat preparation, but the body expands into broader intelligence gathering, including scraping X/Twitter content and optionally exporting results to Notion. That mismatch can mislead users and reviewers about the true data collection and transmission scope, increasing the chance that personal data is gathered or shared without informed consent.
The skill instructs the agent to collect and scrape personal profile and social-media data, including LinkedIn and X content, without an explicit privacy notice, consent boundary, or guidance on lawful/appropriate use. In context, this makes accidental over-collection and inappropriate profiling of third parties more likely.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
### 2. Notion Integration (optional — for saving playbooks to Notion)
**Create an integration:**
1. Go to https://www.notion.so/my-integrations
2. Click **"New integration"**
3. Give it a name (e.g. "Coffee Chat Skill")
Referencing the Notion API endpoint reflects a built-in mechanism for sending collected intelligence off-platform. In this skill's context, the danger is not the domain itself but that researched personal data may be persisted externally without sufficient privacy guardrails or user awareness.
NOTION_PAGE_ID="YOUR_NOTION_PAGE_ID"
NOTION_KEY="${NOTION_API_KEY}"
curl -s -X PATCH "https://api.notion.com/v1/blocks/${NOTION_PAGE_ID}/children" \
-H "Authorization: Bearer $NOTION_KEY" \
-H "Notion-Version: 2022-06-28" \
-H "Content-Type: application/json" \
Referencing the Notion API endpoint reflects a built-in mechanism for sending collected intelligence off-platform. In this skill's context, the danger is not the domain itself but that researched personal data may be persisted externally without sufficient privacy guardrails or user awareness.
NOTION_PAGE_ID="YOUR_NOTION_PAGE_ID"
NOTION_KEY="${NOTION_API_KEY}"
curl -s -X PATCH "https://api.notion.com/v1/blocks/${NOTION_PAGE_ID}/children" \
-H "Authorization: Bearer $NOTION_KEY" \
-H "Notion-Version: 2022-06-28" \
-H "Content-Type: application/json" \
The stated purpose is to generate a personalized coffee chat playbook for meeting preparation. Persisting that output to a third-party workspace via Notion is an extra integration capability beyond preparing the playbook itself, and the manifest does not frame remote publication/storage as part of the skill's purpose.
Detected: suspicious.exposed_secret_literal, suspicious.generated_source_template_injection