T09 · Insecure Skill Coding Practices
- Location
SKILL.md:70- Finding
Personal Birth Data Embedded in a Third-Party URL
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 70-74
Vulnerability Type: Personal data exposure through URL query parameters
Risk Level: MediumVulnerable Code
text ## Output online chart URL https://ziwei.pub/astrolabe/?d=<birth date, format YYYY-M-D>&t=<time index>&leap=<whether leap month, true or false>&g=<sex, male or female>&type=<calendar type, solar or lunar>Technical Analysis
The Skill instructs the agent to construct a third-party URL containing the user's birth date, approximate birth time, sex, calendar type, and leap-month status in its query string. This information constitutes a personal birth profile.
URL query parameters can be disclosed through the destination server's access logs, browser history, chat transcripts, analytics systems, proxy logs, monitoring infrastructure, screenshots, and copied links. If the user opens the generated URL, the third-party service receives all encoded profile attributes. Even if the link is not opened, it remains exposed in the agent's output and any systems retaining that output.
The disclosure is unnecessary because the Skill separately specifies local chart calculation through the
iztropackage. The reviewed content does not establish malicious collection or automatic transmission, but the default generation of a personal-data-bearing external URL is an insecure privacy practice.Attack Path
- The user supplies a birth date, birth time, sex, calendar type, and leap-month status.
- The agent follows
SKILL.mdand inserts these values into the prescribedziwei.pubURL. - The complete URL appears in the conversation and may be retained by chat logging or monitoring systems.
- If the user opens the URL, the browser sends the embedded information to the third-party website and its supporting infrastructure.
- Anyone with access to browser history, application logs, proxy l ...[truncated 666 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove automatic generation of the third-party URL and use the local
iztrocalculation path by default. - If the external service remains optional, obtain explicit informed consent before constructing or displaying the URL.
- Clearly identify the destination, the exact fields that will be disclosed, and the privacy implications before the user consents.
- Minimize transmitted data and avoid placing personal attributes in URL query strings. Prefer a privacy-preserving local workflow or, where supported, a consented POST request with appropriate retention controls.
- Do not persist the generated link in logs, telemetry, long-term memory, or analytics.
- Provide a redacted link template unless the user explicitly requests a populated external link.
- Document the third party's privacy and retention behavior before recommending the service.
- Remove automatic generation of the third-party URL and use the local
