T09 · Insecure Skill Coding Practices
- Location
scripts/poi-debug.sh:329- Finding
Arbitrary Python Code Execution Through an Unquoted Heredoc
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This POI debugging skill has a coherent purpose, but it can query sensitive internal logs, replay captured requests, and run a shell script with unsafe input handling and shared temporary-file storage.
Install only in an authorized internal environment and treat GSIDs, trace IDs, logged URLs, response bodies, and reports as sensitive. Before routine use, tighten triggers, add confirmation before log queries and request replay, validate inputs, avoid plaintext HTTP where possible, and store outputs in a private directory with cleanup instead of shared /tmp.
scripts/poi-debug.sh:329Arbitrary Python Code Execution Through an Unquoted Heredoc
scripts/poi-debug.sh:82Log Query and JSON Injection Through Unvalidated Arguments
scripts/poi-debug.sh:165Sensitive Logged Requests Are Replayed Over Plaintext HTTP
scripts/poi-debug.sh:176Predictable Shared Temporary File Enables Data Exposure and Symlink Attacks
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
ppend('累积流量为 0,可能数据异常')
### Q13: 如何输出为 Markdown 报告?
```bash
# 添加导出选项
./poi-debug.sh <gsid> <poiid> --format markdown > report.md
原因: aone-kit 或 sf 不在 PATH 中
解决:
export PATH="/app/501280/.local/bin:$PATH"
# 或添加到 ~/.bashrc
echo 'export PATH="/app/501280/.local/bin:$PATH"' >> ~/.bashrc
source ~/.bashrc
原因: log_name 不正确
解决:
# 确认正确的 log_name
# 从 Loghouse UI 查看:https://loghouse.alibaba-inc.com/
# 对于 lse2-us-business-service,通常是 nginx_uni
原因: 灰度环境响应慢或网络问题
解决:
# 增加超时时间
curl -s --max-time 60 "$FULL_URL"
# 或尝试线上环境
./poi-debug.sh <gsid> <poiid> online
The trigger list includes broad or ambiguous terms such as "contentPerson" and "手艺人模块", which can cause the skill to activate outside the intended POI-debugging context. Because this skill orchestrates code lookup, log access, and request reproduction, accidental invocation could expose internal diagnostics or cause unnecessary access to sensitive engineering systems.
The trigger phrase list contains broad terms like “poi 问题”, “详情页异常”, and “poi 调试” that can match ordinary troubleshooting conversations rather than explicit requests to run this specific skill. In an agent environment, ambiguous activators can cause unintended invocation of a powerful debugging workflow that may access logs, source mappings, trace data, or internal code paths without the user clearly intending that action.
The README instructs users to replay requests and query logs using a GSID/session identifier, but it does not warn that these identifiers and resulting logs may contain sensitive user or operational data. In a debugging skill that accesses production-like telemetry and reproduces user flows, missing handling guidance increases the risk of oversharing, insecure storage, or misuse of session-linked information.
Automatically persisting troubleshooting results to /tmp can expose sensitive internal data such as GSIDs, trace IDs, response payloads, and service details to other local users or processes, especially on shared systems. In this skill's context, the orchestrator handles internal debugging artifacts, so storing them in a broadly accessible temporary directory increases the chance of accidental disclosure.
The README includes full example values for GSID, POIID, TraceID, internal hostnames, file paths, and response characteristics without any handling guidance. Even if illustrative, exposing realistic internal identifiers and operational details in documentation can normalize unsafe sharing practices and may leak sensitive environment information if the examples are real or copied from production-like debugging sessions.
The skill orchestrates shell commands, file reads/writes, curl, and code/log retrieval but does not declare any explicit tool scope or allowed-tools boundary. That means an agent may execute powerful actions without least-privilege constraints, increasing the chance of unauthorized data access, arbitrary network requests, and unsafe file operations during routine troubleshooting.
The trigger phrases are broad enough to activate on common support or debugging language such as 'POI 排查', 'poi 问题', or 'traceId 分析' without clear exclusions or confirmation gates. In practice this can cause the skill to run in contexts where the user did not intend log queries, request replay, or code inspection, exposing sensitive identifiers and initiating unnecessary high-privilege actions.
The skill instructs the agent to extract full logged URLs and replay them with curl while handling gsid, traceId, and other debugging identifiers, but it provides no user-facing warning or safety controls around sensitive data handling. Replaying captured URLs can reuse privileged query parameters or session-linked identifiers, leading to inadvertent exposure of internal data, privacy issues, or unintended requests against production-like environments.
The manifest declares many broad trigger phrases such as generic POI/debug/troubleshooting terms, which can cause the skill to activate in conversations beyond its intended scope. Because this skill appears to orchestrate internal diagnostic steps involving code, logs, request replay, and trace/gsid analysis, overbroad activation increases the chance of exposing sensitive operational workflows or causing the agent to perform powerful actions on insufficiently specific user intent.
The FAQ instructs users to list and copy debugging artifacts from /tmp into a personal documents directory without any warning that these files may contain GSIDs, trace IDs, POI identifiers, logs, and raw response payloads. In this skill context, those artifacts are operational data gathered from internal systems, so normalizing long-term local retention and copying increases the chance of sensitive internal data exposure beyond its original troubleshooting purpose.
The file provides a ready-to-run log query template that includes a concrete employee ID and explicitly instructs operators to query logs by GSID, which is a user session identifier. Even though the GSID value in the template is placeholder text, this materially lowers the barrier to accessing and correlating sensitive session-linked telemetry, and there is no warning about authorization, minimization, redaction, or retention when handling user/session data.
The script automatically replays a backend request with curl using parameters derived from log data, without any explicit operator confirmation or warning that a live internal service call will be made. In this debugging context, replaying requests can trigger side effects, hit sensitive internal endpoints, or unintentionally resend production traffic patterns, especially since the URL path is taken from logs and the script targets internal gray/prod hosts.
The script stores replayed backend response data and generated debug reports under /tmp, which is commonly world-readable or accessible to other local users/processes depending on system configuration. Because this skill processes production debugging artifacts such as GSID, traceId, URLs, response bodies, and code-location metadata, persisting them without warning, access controls, or cleanup can expose sensitive operational and user-related data beyond the intended debugging session.
SQP-3 适用于所有文件类型。该文件整体以中文强制性说明操作步骤与触发词配置,未声明这是面向特定中文团队的限定文档,也未提供语言选择或说明可按用户语言偏好提供内容,存在语言/locale 策略风险。
Natural-language content throughout the file is Chinese-only, including the title, descriptions, examples, and operational guidance. Under the policy, forcing a specific language without user opt-in can be a locale/language policy violation unless the constraint is explicitly justified, which is not stated here.
The README header states the skill '自动执行 6 步排查流程', while the concrete feature list and sample run enumerate only five visible stages: 日志查询, 请求复现, 响应解析, 代码定位, 生成排查报告. This is an active documentation inconsistency about what the skill does, not merely omitted detail.
The natural-language instructions and operational guidance in the README are presented entirely in Chinese, with no indication that users may choose another language or that the language restriction is intentional and scoped. This can constitute a language/locale policy issue because the skill imposes a specific language by default rather than offering user choice.
The natural-language content throughout the skill FAQ forces a specific language/locale experience for users, and there is no indication of opt-in, alternative language support, or documented regional justification. SQP-3 applies to all file types and covers language or locale policy violations of this kind.
No suspicious patterns detected.