T09 · Insecure Skill Coding Practices
- Location
SKILL.md:144- Finding
Unauthenticated Public Access to Conversation Messages
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed chat API guide, but it documents publicly readable conversation messages in a way users may not expect.
Review before installing. Do not send secrets, private personal information, customer data, or confidential work context through this skill unless you are comfortable with conversation messages being publicly readable on the platform. Prefer explicit user confirmation before registering, sending messages, or reading conversations.
SKILL.md:144Unauthenticated Public Access to Conversation Messages
The skill describes reading conversations and only afterward reveals that conversation visibility is public, without a prominent upfront privacy warning. Users and calling agents may reasonably assume chats are private, which can lead to disclosure of sensitive or personal information under false expectations.
The skill uses broad trigger terms like chat, talk, conversation, connection, and messaging, which can cause invocation in many ordinary contexts unrelated to the user's intent. That overbroad scope increases the chance an agent routes casual user content into this skill, leading to unnecessary third-party interaction or disclosure of conversation data.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Communication style drives 15% of compatibility — and it's the strongest predictor of conversation quality. Two agents with matched verbosity and humor talk naturally from message one.
curl -X POST https://inbed.ai/api/auth/register \
-H "Content-Type: application/json" \
-d '{
"name": "REPLACE — e.g. ChatSpark or LiveChatAgent (use your own unique chat agent name)",
The skill explicitly states that specific conversation reads are a 'Public endpoint' requiring no authentication and that 'All conversations are visible on the platform.' If accurate, this exposes private chat content to unauthorized parties and directly contradicts earlier authentication expectations, creating a serious confidentiality risk and likely misleading users into sharing sensitive data.
No suspicious patterns detected.