T09 · Insecure Skill Coding Practices
- Location
scripts/research.mjs:43- Finding
Unrestricted File Overwrite Through the Output Path
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed Tavily-powered research and report generator, with cautions around third-party query sharing and user-chosen output files.
Install only if you are comfortable sending research topics to Tavily. Do not include secrets, private customer data, or confidential strategy in queries, and use simple report filenames in a safe working directory because --output can replace an existing writable file.
scripts/research.mjs:43Unrestricted File Overwrite Through the Output Path
Referenced artifact was not completely inspected
node scripts/research.mjs "AI Agent 市场趋势 2025" --deep
Referenced artifact was not completely inspected
node scripts/research.mjs "AI Agent 市场趋势 2025" --deep
Referenced artifact was not completely inspected
node scripts/research.mjs "AI Agent 市场趋势 2025" --deep
Referenced artifact was not completely inspected
node scripts/research.mjs "AI Agent 市场趋势 2025" --deep
The skill declares that it requires environment variables and performs network-backed research, but it does not explicitly constrain or disclose tool scope via permissions or allowed-tools metadata. This creates ambiguity about what runtime capabilities the skill is expected to use, which can lead to overbroad execution in hosting environments and weaken reviewability of external data access.
The skill description highlights research features but does not warn that user-supplied topics will be sent to an external service via Tavily web/API requests. Users may provide sensitive internal project names, customer data, or strategic questions under the assumption analysis is local, causing unintended third-party disclosure.
The hardcoded use of the Tavily external endpoint means this skill inherently depends on a remote service and sends request metadata plus search content off-host. In the context of a research tool this is expected behavior, but it is still security-relevant because users may assume local processing and accidentally disclose sensitive information to a third party.
console.log('🔍 Searching...');
const resp = await fetch('https://api.tavily.com/search', {
method: 'POST',
headers: {
'Content-Type': 'application/json',
The hardcoded use of the Tavily external endpoint means this skill inherently depends on a remote service and sends request metadata plus search content off-host. In the context of a research tool this is expected behavior, but it is still security-relevant because users may assume local processing and accidentally disclose sensitive information to a third party.
console.log('🔍 Searching...');
const resp = await fetch('https://api.tavily.com/search', {
method: 'POST',
headers: {
'Content-Type': 'application/json',
This code includes user-facing descriptions and CLI help/output in Chinese, which effectively imposes a specific language on users. The file does not present an option to select another language or document that the tool is intentionally limited to a Chinese-speaking context.
No suspicious patterns detected.