T09 · Insecure Skill Coding Practices
- Location
scripts/ingestion_core.py:16- Finding
Cross-Workspace Data Tampering Through Globally Scoped Identifiers
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is not trying to steal data, but its recommended database pattern can let one workspace overwrite another workspace's indexed content if used as-is.
Review carefully before installing or using in a shared service. Treat the code as an unsafe example until the schema uses workspace-scoped composite keys and foreign keys, upserts include workspace ownership checks, and answer synthesis treats retrieved document content as untrusted data.
scripts/ingestion_core.py:16Cross-Workspace Data Tampering Through Globally Scoped Identifiers
scripts/retrieval_core.py:44Indirect Prompt Injection Through Unsanitized Retrieved Document Content
Without declared permissions the skill's intent is opaque and cannot be validated.
No suspicious patterns detected.