T09 · Insecure Skill Coding Practices
- Location
mcp-server.js:117- Finding
Arbitrary File Disclosure Through Static-File Path Traversal
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a real pension calculator, but its local web server can expose sensitive financial data and readable files without adequate access controls.
Install only if you are comfortable with a local Node web server storing pension data in files and exposing it through unauthenticated local HTTP endpoints. Avoid entering real financial details until the server is restricted to loopback, authenticated, protected against path traversal, and given clear delete/retention controls.
mcp-server.js:117Arbitrary File Disclosure Through Static-File Path Traversal
mcp-server.js:49Unauthenticated Network Access to Sensitive Financial Data APIs
mcp-server.js:65Unbounded HTTP Request Accumulation Enables Memory and Disk Denial of Service
mcp-server.js:260Prototype Pollution Through Unrestricted MCP Parameter Paths
The skill asks users to provide sensitive financial and personal retirement data, while the supplied documentation indicates undeclared local file persistence and server/API functionality. When sensitive data handling is not clearly disclosed up front, users may expose personal information without informed consent, and downstream components may process or retain it more broadly than expected.
The skill asks users to provide sensitive financial and personal retirement data, while the supplied documentation indicates undeclared local file persistence and server/API functionality. When sensitive data handling is not clearly disclosed up front, users may expose personal information without informed consent, and downstream components may process or retain it more broadly than expected.
The skill asks users to provide sensitive financial and personal retirement data, while the supplied documentation indicates undeclared local file persistence and server/API functionality. When sensitive data handling is not clearly disclosed up front, users may expose personal information without informed consent, and downstream components may process or retain it more broadly than expected.
Referenced artifact was not completely inspected
entry: "mcp-server.js"
The UI directly tells users to copy and paste their pension data into an AI chat for analysis, which normalizes exfiltration of sensitive retirement and financial profile information to an external system. In the context of a pension calculator, this is especially risky because the data is personal, longitudinal, and financially revealing, making accidental over-disclosure likely.
fast-uri 3.1.0 is associated with multiple high-severity parsing issues including host confusion and possible SSRF primitives. Even though the lockfile does not prove the skill parses attacker-controlled URLs, URL parsing libraries are often security-sensitive, and misuse through validation or allowlist logic could enable outbound request bypasses or trust-boundary failures.
hono 4.12.12 has numerous advisories affecting routing, cookie handling, and possible HTML/JSX injection surfaces. Given this skill explicitly supports a web interface, a vulnerable web framework in the dependency tree is especially relevant because exposed HTTP routes, templating, or header generation may be reachable by untrusted users.
ip-address 10.1.0 is flagged for address parsing inconsistencies and XSS in HTML-emitting methods. The XSS portion may be irrelevant if HTML helpers are unused, but the parsing inconsistency can matter anywhere IP-based allowlists, rate limiting, or trust decisions are made, and this package is pulled in by express-rate-limit-related dependencies.
This markdown file states that data is automatically loaded from a server on page startup and supports multi-device synchronization, which implies network transfer and remote storage of user data. The description does not include any warning about privacy, server persistence, or when user data leaves local storage.
The file documents a web server that supports POST requests to save data and shares a data directory with another server component. Because this behavior affects user data persistence and system storage, the markdown should disclose that data will be written server-side and clarify where it is stored.
The markdown explicitly says the skill supports server file saving through an API endpoint, alongside localStorage and JSON export/import. Since server-side file persistence can affect privacy and system integrity, the description should warn users that their data may be stored remotely or outside the browser.
The 'important note' asserts universal applicability across all regions and no regional differentiation, which is a strong claim about behavior and scope. Later, the disclaimer acknowledges that actual pension calculations are determined by local authorities, creating a direct contradiction in the skill's stated intent and reliability.
The trigger phrase is broad enough to match ordinary conversation and can cause the skill to activate automatically when users merely ask about pensions. In this skill's context, activation leads quickly to collection and local storage of sensitive financial and personal data, increasing privacy risk and the chance of unintended tool use.
The workflow directs users to enter age, retirement age, account balances, contribution history, and savings information without a clear privacy warning first. Because the skill persists this data to local files and may expose it through a local server workflow, the absence of an upfront warning materially increases the risk of unintentional disclosure or retention of highly sensitive financial data.
The technical description says the Web interface is implemented as a pure frontend with no backend server, which implies browser-only operation. However, elsewhere the file explains that data saving depends on starting the Node MCP server because static hosting cannot handle POST requests and the skill persists data to local files, so the documentation actively contradicts the real architecture.
This UI is not limited to local pension calculation: it loads data from a server, posts full pension/financial profile data back to a server, exports JSON files, and explicitly prepares data for AI consumption. The data involved is highly sensitive financial profile information, so unnecessary transmission and secondary sharing materially increase privacy, leakage, and misuse risk.
The code creates a summary of retirement age, balances, contribution history, and future deposits, then copies it to the clipboard and instructs the user to provide it to an AI. Packaging sensitive financial data for exfiltration to third-party AI services is dangerous because users may not understand retention, training, or downstream disclosure risks.
The application sends sensitive pension and financial profile data to '/api/save-data' without any prominent user-facing privacy disclosure explaining what is sent, why, where it is stored, or who can access it. Even if transmission is expected by the developer, the absence of transparent notice and consent creates a privacy vulnerability and increases the chance of unauthorized or surprising data exposure.
Comments and success messages explicitly position server save and file export as being 'for LLM' or '供LLM读取', indicating that sensitive user data is being prepared for non-essential downstream AI consumption. This makes the intent of secondary data use clearer and increases concern because the feature is framed around sharing financial profile data beyond the calculator's primary purpose.
The clipboard flow copies a detailed pension summary and prompts the user to paste it into an AI chat, but it does not provide an explicit privacy warning about third-party processing, retention, or account-level exposure. Clipboard contents can also be inadvertently pasted elsewhere, broadening exposure of sensitive financial information.
This JavaScript file contains user-facing natural-language descriptions and report strings exclusively in Chinese, including the module description and generated report/recommendation text. The stated policy forbids forcing a specific language without user opt-in, and the file provides no indication that users can choose another language or that the locale restriction is explicitly documented as intentional.
The report title and recommendation messages returned by generateReport/generateRecommendations are fixed Chinese strings, so any consumer of this skill receives Chinese output regardless of user preference. That is a natural-language locale policy issue because the skill does not offer language choice or disclose a justified region-specific limitation.
The file’s natural-language comments and validation messages are exclusively in Chinese, indicating the skill is designed around a single language/locale without any visible user choice mechanism. Under the policy, forcing a specific language without opt-in is a natural-language policy concern unless the locale restriction is explicitly justified.
This file contains natural-language comments and user-visible strings centered on Chinese-language use, but there is no indication that the skill is region-specific or that users can opt into this locale. Under the policy, forcing a specific language without user choice is a natural-language policy violation.
Natural-language strings throughout the file, including tool descriptions and user instructions, are exclusively in Chinese and direct the user to respond with Chinese phrases such as "已完成". There is no indication that the user can choose another language or that the Chinese-only constraint is required for a region-specific compliance reason.
No suspicious patterns detected.