T09 · Insecure Skill Coding Practices
- Location
scripts/fetch_page.py:174- Finding
Credentials Are Automatically Submitted to an Unvalidated Destination
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill’s browser automation purpose is clear, but it can submit credentials and persist authenticated page contents with weak scoping and safeguards.
Review before installing. Use this only for domains you explicitly trust, avoid setting broad ROUTER_* credentials in the environment, do not pass real passwords on the command line, and treat generated screenshots and HTML as sensitive files that may contain private account or internal system data.
scripts/fetch_page.py:174Credentials Are Automatically Submitted to an Unvalidated Destination
scripts/fetch_page.py:174Arbitrary Browser Navigation Enables Server-Side Request Forgery and Internal Resource Capture
scripts/fetch_page.py:271Plaintext Command-Line Credentials Can Leak Through Process and Shell Metadata
scripts/fetch_page.py:216Authenticated Page Content Is Persisted Without Access-Control or Cleanup Protections
references/examples.md:21Generated Selenium Templates Disable the Chromium Sandbox
MANIFEST.md:15Unpinned Dependencies and Browser Binaries Are Installed from Mutable Upstream Sources
The trigger conditions are very broad, including generic phrases like '帮我完成 xxx' and '帮我操作 xxx', which can cause the skill to activate for many unrelated requests. In this skill’s context, accidental activation is risky because it can lead to webpage fetching, DOM capture, and generation of automation for sensitive sites without sufficiently specific user intent.
The quick-reference trigger list repeats ambiguous activation rules and lacks constraints that the user must explicitly request webpage analysis or Selenium generation. Because this skill handles screenshots, rendered HTML, login flows, and automation guidance, imprecise triggering increases the chance of unintended collection or execution-oriented assistance on sensitive pages.
Referenced artifact was not completely inspected
| `SKILL.md` | 主工作流说明 | 触发时 |
The primary skill description and usage instructions are presented in Chinese, including trigger wording, behavior notes, and safety guidance, with no statement that users may choose their preferred language. This can constitute a language-policy issue if the skill implicitly requires Chinese interaction rather than offering locale choice or documenting a justified region-specific constraint.
The manifest advertises broad trigger phrases such as '分析页面', '生成 selenium', and '帮我操作 xxx', which can match ordinary user requests and cause unintended activation of a highly autonomous browser-automation skill. Because the skill can use credentials and perform login flows, accidental invocation increases the chance of unauthorized actions, credential exposure in context, or automation against sensitive internal systems.
The manifest and operational instructions are written entirely in Chinese, including trigger phrases and output requirements, with no indication that users may choose another language. This can conflict with language/locale policy if the skill implicitly requires Chinese rather than offering a user choice.
The skill describes capturing full-page screenshots, rendered HTML DOM, metadata, and potentially login-related state, but does not clearly warn users that page contents will be stored to disk. This is dangerous because users may invoke the skill on pages containing personal data, internal dashboards, or sensitive business information without understanding the retention and exposure implications.
The primary skill description and trigger wording are presented in Chinese only, which implies a language-specific interaction model without stating that users may choose another language. While some environment variable descriptions and warnings are bilingual later in the file, the manifest does not clearly offer language choice for normal skill use.
The manifest advertises very broad trigger phrases such as '分析页面', '生成 selenium', '网页自动化', and '帮我操作 xxx', which can cause the skill to activate in response to generic user requests that are not clearly intended to invoke browser automation. In this skill's context, unintended invocation is more dangerous because the skill is autonomous and may perform page access, form interaction, and login attempts using supplied credentials.
The activation description includes broad phrases like helping operate pages or complete tasks, which can match ordinary user requests without clear security boundaries. This increases the chance the skill is invoked for sensitive browser automation, credential entry, or actions on third-party sites without sufficiently explicit user intent or narrowing constraints.
The manifest description and instructions are written to operate in Chinese and do not indicate that the skill can respond in another language or follow the user's preferred locale. This can violate language/locale policy when the user has not opted into Chinese or when the environment is multilingual.
The quick-reference trigger list repeats ambiguous phrases that can cause accidental invocation in normal conversation. In this skill's context, accidental activation is more dangerous because the workflow includes page fetching, possible login handling, DOM extraction, and generation of actionable automation steps for arbitrary websites.
The skill states that credentials must only be supplied in conversation, yet it also declares router credential environment variables at the top. That contradiction creates a real risk that the skill or its supporting scripts may implicitly consume ambient secrets, causing unintended credential use or disclosure during webpage automation against login-protected targets.
The documentation explicitly demonstrates automated login by locating username/password fields and entering hardcoded credentials, even though the file is presented as a general Selenium reference rather than a narrowly scoped authentication skill. This can normalize credential-handling behavior and lead downstream agents or users to embed secrets in automation flows without proper safeguards, increasing the risk of unauthorized access or secret leakage.
The login example shows direct handling of sensitive authentication data, including a plaintext password string, without any warning about secure credential management. This encourages insecure copying of patterns into real workflows, where secrets may be committed to repositories, exposed in logs, or reused in unauthorized automation.
The file is entirely written as mandatory guidance in Chinese and states that all generated Selenium code must follow these rules, but it does not indicate that Chinese is optional or tied to a region-specific requirement. Under the stated policy, forcing a specific language without opt-in can be a natural-language policy violation.
The module documentation materially understates behavior by describing simple page capture while the script can also detect login pages, read credentials from arguments or environment variables, and perform automated authentication. This is dangerous because operators may run it against sensitive targets without realizing it will submit credentials and then collect authenticated content, expanding the security and privacy impact beyond what the documentation suggests.
The script implicitly pulls credentials from environment variables and uses them for automatic login, which can cause unintended credential use against an untrusted or mistyped URL. This is especially risky in automation/agent environments where secrets are broadly injected into the process environment and the operator may not realize this script will consume them.
After login, the script automatically stores full-page screenshots and rendered HTML to disk, which can include account data, CSRF tokens, internal application state, or other sensitive information. In an agent skill context, this is more dangerous because the captured files may be persisted, shared with downstream tools, or exposed to users who did not intend to export authenticated content.
The example includes hardcoded login credentials and demonstrates automated authentication plus screenshot/file-writing behavior without any guidance on secret handling or output sanitization. In an agent skill, examples often get copied into production workflows, which can normalize insecure credential storage and create artifacts that may capture sensitive account data or authenticated application state.
The file title and normative guidance are entirely in Chinese, and line L003 states that all generated Selenium code must follow these rules, implicitly imposing a single language/locale. Under the policy, forcing a specific language without user opt-in or documented regional justification is a natural-language policy violation.
The module docstring and advertised usage describe a page-fetching and screenshot tool, but the implementation also detects login pages and can automatically submit credentials from CLI arguments or environment variables. This hidden capability increases the risk of credential misuse, unintended authenticated access, and accidental collection of sensitive post-login content because operators may not realize the script performs authentication.
This Python file contains user-facing natural-language documentation and runtime messages exclusively in Chinese, including the module docstring and command-line help text. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified, which is not present here.
The screenshot helper writes image files to a local screenshots directory without warning that artifacts will be created and may contain sensitive page contents. In automation contexts, screenshots can capture personal data, admin panels, or session-specific information and persist it on disk longer than intended.
This markdown file includes a screenshot helper that writes image files to a local screenshots directory, which can capture page contents and user data. The surrounding documentation does not warn readers that running this pattern creates persistent files containing potentially sensitive visual information.
Detected: suspicious.exposed_secret_literal