T09 · Insecure Skill Coding Practices
- Location
server.py:533- Finding
Public Analysis Defaults Can Disclose Dataset Results Without Enforced Confirmation
- Content
View full analysis
Vulnerability Details
File Location:
server.py, lines 533–629
Vulnerability Type: Unsafe default causing unintended public disclosure
Risk Level: HighVulnerable Code
python async def discovery_analyze( target_column: str, file_ref: str | dict | None = None, analysis_depth: int = 2, visibility: str = "public", title: str | None = None, description: str | None = None, excluded_columns: str | list | None = None, column_descriptions: str | dict | None = None, author: str | None = None, source_url: str | None = None, use_llms: bool = False, api_key: str | None = None, ) -> str:python run_payload: dict = { "file": { "key": uploaded_file["key"], "name": uploaded_file.get("name", "dataset"), "size": uploaded_file.get("size", 0), "fileHash": uploaded_file.get("fileHash", ""), }, "columns": columns, "targetColumn": target_column, "analysisDepth": analysis_depth, "isPublic": visibility == "public", "useLlms": use_llms, }Technical Analysis
The
discovery_analyzetool defaultsvisibilityto"public". That value is converted directly into"isPublic": Truein the analysis request. Public analyses are documented as being published to a public gallery.SKILL.mdlines 62–66 instruct the agent to ask whether the analysis should be public or private. However, this is a documentation-level instruction rather than a constraint enforced by the executable entry point. A direct MCP caller, an automated workflow, or an agent that omits the optional argument can bypass the documented selection step.The tool's API therefore treats the absence of an explicit privacy decision as consent to public disclosure. This is unsafe for datasets whose analysis results, column metadata, summaries, or discovered patterns are confidential.
Attack Path
- A user uploads a confidential dataset through
discovery_upload.
...[truncated 1074 chars]
- A user uploads a confidential dataset through
- Remediation
View remediation
Remediation Suggestions
- Change the default to
visibility="private"so omission fails closed. - Prefer making
visibilitymandatory rather than assigning any implicit publication state. - Require an explicit parameter such as
publish_publicly=Truebefore creating a public analysis. - For agent-driven workflows, implement a short-lived confirmation token issued only after the user is shown that the results will be publicly published.
- Reject public submissions if the confirmation token is missing, expired, or does not match the uploaded file and analysis parameters.
- Present the publication destination and data classification warning immediately before confirmation.
- Add tests verifying that omitted visibility never produces
"isPublic": Trueand that direct MCP calls cannot bypass the confirmation requirement.
- Change the default to
