T09 · Insecure Skill Coding Practices
- Location
SKILL.md:28- Finding
Exposure of Internal Infrastructure and Deployment Metadata
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 28–31
Vulnerability Type: Internal infrastructure information disclosure
Risk Level: LowEvidence
markdown - **Server**: `wphu@gpu506.aibee.cn` - **Container**: `step3vl-finetune` - **Project directory**: `/app/` (inside the container) - **Model path**: `/data/algorithm/tracking/Checkpoints/Step3-VL-10B`Technical Analysis
The publicly distributable Skill documentation embeds an organization-specific username and hostname, container name, internal filesystem layout, and model-storage path. These values are not credentials and do not provide direct access by themselves, but they disclose operational details that are unnecessary for a reusable fine-tuning guide.
Such information can assist reconnaissance by identifying account naming conventions, infrastructure hostnames, container workloads, application locations, and valuable model-storage directories. An attacker could combine this metadata with credentials obtained through phishing, credential reuse, or another vulnerability to make subsequent targeting more precise.
Attack Path
- An attacker obtains or reads the Skill package.
- The attacker extracts the server account, hostname, container name, and filesystem paths from
SKILL.md. - The attacker uses the identifiers for infrastructure discovery, targeted phishing, password spraying against separately exposed authentication services, or more focused post-compromise navigation.
- If access is obtained through an independent weakness, the disclosed paths help the attacker locate the application and model assets more quickly.
Impact Assessment
This issue does not independently grant privileges or prove that the disclosed host is externally reachable. Its direct impact is limited to information disclosure. However, it reduces the effort required to identify and target internal systems and could facilitate access to pro ...[truncated 59 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace organization-specific identifiers with neutral placeholders such as
user@gpu-server,/app, and/models/model-name. - Store environment-specific deployment values in access-controlled operational documentation rather than the distributed Skill.
- Review the repository history and related documentation for additional infrastructure details.
- Establish documentation review controls to detect internal hostnames, usernames, private paths, registry addresses, and service endpoints before publication.
- If the hostname or account name is sensitive, assess whether it has been exposed elsewhere and monitor relevant authentication services for targeted access attempts.
- Replace organization-specific identifiers with neutral placeholders such as
