T09 · Insecure Skill Coding Practices
- Location
aqi-hanoi.js:10- Finding
Hardcoded WAQI API Credential Exposed in Source Code and Request URL
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This AQI skill does what it claims, but it contains an exposed WAQI API token and sends city lookups to WAQI.
Before installing, be aware that city queries are sent to the WAQI API and the bundled WAQI token is exposed in the source. Prefer a version that uses a user-provided secret from the environment, rotates the exposed token, and adds request timeouts and response-size limits.
aqi-hanoi.js:10Hardcoded WAQI API Credential Exposed in Source Code and Request URL
aqi-hanoi.js:35Unbounded Remote Response Buffering and Missing Request Timeout
The documented behavior does not fully match the described capability and transparency expectations: the skill appears to rely on a hardcoded external API token, sends user-provided city data to a third-party service, and exposes CLI-style behavior not clearly disclosed in metadata. While this is not direct code execution, hidden credentials and undisclosed external data flow can mislead operators, complicate review, and create supply-chain or privacy risk if the skill is deployed in a managed agent environment.
The natural-language instructions and description are presented in Vietnamese, but the skill does not indicate that this language choice is optional or limited to a Vietnam-specific audience. This can violate language/locale policy when a skill implicitly forces one language without user opt-in.
The script embeds a live WAQI API token directly in source code and automatically transmits it in every outbound request. Hardcoded secrets are easily exposed through source distribution, logs, or repository history, allowing unauthorized reuse of the token, quota exhaustion, billing impact, or account abuse.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
function fetchAQI(cityInput) {
const citySlug = cityMap[cityInput.toLowerCase()] || cityInput.toLowerCase();
const url = `https://api.waqi.info/feed/${encodeURIComponent(citySlug)}/?token=${WAQI_TOKEN}`;
https.get(url, (res) => {
let data = '';
The skill omits a clear user-facing notice that city queries are transmitted to an external API. This weakens informed consent and privacy transparency, especially in agent ecosystems where users may assume processing is local unless otherwise stated.
Natural-language strings and comments indicate the skill is designed around Vietnamese output and terminology, but there is no indication that users can choose another language or explicitly opt into Vietnamese. This can violate language/locale policy when a skill forces a specific language by default.
No suspicious patterns detected.