T09 · Insecure Skill Coding Practices
- Location
scripts/check_sensitive_words.py:180- Finding
Server-Side Request Forgery Through Unrestricted URL Fetching
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent WeChat copy checker, but its URL mode can fetch arbitrary network locations and send the extracted text to RedFoxHub, so users should review it carefully before installing.
Install only if you are comfortable sending scanned copy, uploaded file text, image-extracted text, or fetched webpage text to RedFoxHub. Avoid scanning confidential, regulated, or secret material; use an isolated environment, provide the API key through an explicit environment variable, and do not let the URL feature access localhost, private networks, or cloud metadata endpoints.
scripts/check_sensitive_words.py:180Server-Side Request Forgery Through Unrestricted URL Fetching
SKILL.md:66Unpinned Third-Party Dependency Installation
scripts/check_sensitive_words.py:267Unsanitized API-Provided HTML Propagated to Downstream Output
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
last_error = None
for attempt in range(max_retries + 1):
try:
response = requests.post(API_URL, headers=headers, json=payload, timeout=30)
if response.status_code >= 500 and attempt < max_retries:
import time
The README mentions encrypted transmission and that copy is not stored locally, but it does not clearly and explicitly warn that submitted text, uploaded file contents, image-extracted text, and fetched URL content are sent to a third-party external detection service. Users may unknowingly submit sensitive business drafts, regulated content, or personal data off-platform, creating confidentiality, privacy, and compliance risk.
The README says users can 'Describe what you need in plain language—no fixed commands to memorize,' which makes activation scope ambiguous and suggests the skill may respond to a wide range of ordinary language. While examples are provided later, this line does not define clear trigger boundaries or exclusion conditions.
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
### Quick Phrase Reference
| Intent | Example prompt | Outcome |
| ------------------- | ------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------- |
| Paste copy to check | "Check this draft for prohibited words: This whitening miracle really works—you'll see results in three days" | Hit highlights, replacement table, and optimized copy |
| Upload a file | Upload a TXT, DOC, or DOCX file and ask for WeChat prohibited-word detection | File content is read and checked automatically |
The README states '直接用自然语言描述需求,无需记忆固定命令', which encourages free-form requests rather than specific trigger phrases or constraints. For a markdown skill description, this is an ambiguous activation condition that could overlap with common everyday speech and lead to unintended invocation.
The skill declares dependencies and describes behavior that uses environment variables, local file reading, and outbound network access, but it does not declare any explicit tool scope or permission boundaries. This weakens least-privilege controls and can cause the host agent to grant broader capabilities than users expect, especially because the skill reads local content and sends extracted text to a remote API.
The skill description and all user-facing instructions are written exclusively in Chinese and are framed around a fixed WeChat public-account workflow, with no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is explicitly documented and justified.
The script silently reads ~/.bashrc, ~/.zshrc, ~/.bash_profile, and ~/.profile to recover credentials, which exceeds what users typically expect from a text-scanning utility. Reading unrelated local configuration files can expose secrets and normalizes covert credential discovery behavior, especially risky in an agent/skill context where users may not inspect code closely.
The script reads local shell configuration files to extract an API key without explicit user disclosure or consent. Even though it targets a named variable, accessing shell init files is a sensitive local-read capability that can surprise users and may expose credentials stored in those files.
The tool sends full user-provided content to a third-party remote API for analysis without an explicit warning, confirmation, or privacy notice. If users scan drafts, internal documents, logs, or scraped web content, sensitive or proprietary data may be disclosed outside the local environment unexpectedly.
This skill's core behavior is to transmit user content to an external service for scanning, so the transmission is intentional and functionally necessary; however, it still creates a real data exposure risk because content may include confidential drafts, documents, or web-extracted text. In this skill context, the danger is heightened by the lack of up-front disclosure and the broad input sources it can process.
last_error = None
for attempt in range(max_retries + 1):
try:
response = requests.post(API_URL, headers=headers, json=payload, timeout=30)
if response.status_code >= 500 and attempt < max_retries:
import time
The line '平台固定为公众号,无需手动指定' hard-codes a single platform context in the user-facing instructions. This can be a natural-language policy concern because it removes user choice rather than offering an explicit opt-in or clearly framed locale/platform selection.
The script emits user-facing status and error messages in Chinese, such as the dependency error string, with no option to select another language. This is a natural-language policy concern because the tool imposes a locale on all users rather than offering language choice or documenting a justified region-specific restriction.
The docstring says the function supports "DOC、DOCX、TXT等文本类型文件," and the unsupported-type error says it supports "图片、TXT、DOC、DOCX等文本类型文件," but the code only handles .doc/.docx via python-docx and several text-like extensions. There is no image extraction or OCR logic, and .doc support is not truly implemented by python-docx in the same way as legacy Word binaries.
Argument descriptions and user-facing error messages throughout the CLI are written only in Chinese, which forces a specific language experience. There is no indication that users can choose locale or that the skill is intentionally restricted to a Chinese-language context.
No suspicious patterns detected.