T09 · Insecure Skill Coding Practices
- Location
SKILL.md:226- Finding
Default cloud evidence upload can disclose secrets contained in matched source lines
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 226-246 and 304-346
Vulnerability Type: Uncontrolled disclosure of sensitive source data to a third-party endpoint
Risk Level: HighVulnerable Code Snippet
text ### 3.1 What Gets Sent The fingerprint manifest, behavior tags, and **extracted evidence artifacts** are uploaded. Evidence includes the specific URLs, shell commands, and credential access paths that triggered each tag — enabling the cloud to perform real content-level threat analysis. **Evidence redaction rules** — before upload, the scanner applies the following sanitization: - Environment variable **values** are replaced with `[REDACTED]` (only the variable name is sent) - File content from sensitive paths (`~/.ssh`, `~/.aws`, `~/.env`) is never included — only the **path** and **access pattern** are sent - The `context` field is truncated to the single matched line; multi-line context is not collected - Full source code is NOT sent — only the lines that triggered a detection tagtext | Sub-field | Description | |-----------|-------------| | `tag` | The behavior tag that was triggered | | `value` | Raw extracted value (URL / command / path) | | `file` | Source file path where the pattern was found | | `line` | Line number of the match | | `context` | Full content of the matched line |Technical Analysis
Cloud analysis is enabled by default and sends extracted evidence to
https://as.dun.163.com/v1/agent-sec/skill/check. The evidence format permits both a raw extracted value and the complete content of the matched source line.The documented redaction policy only guarantees removal of environment-variable values and file content read from a limited set of sensitive paths. It does not cover other common secret representations, including:
- Hardcoded API keys, passwords, private keys, or bearer tokens
- Authorization headers and cookies embedded in s ...[truncated 2325 chars]
- Remediation
View remediation
Remediation Suggestions
- Make cloud evidence upload explicitly opt-in rather than enabled by default.
- Display the exact outbound payload and destination and require informed user approval before transmission.
- Do not upload complete matched lines. Extract only the minimum structured feature needed for classification.
- Replace denylist-based redaction with allowlist-based serialization so unknown fields and raw context are excluded by default.
- Redact authorization headers, cookies, URL credentials, sensitive query parameters, private-key blocks, command arguments, and known credential formats.
- Detect and redact high-entropy strings even when their variable names do not contain terms such as
TOKENorSECRET. - Canonicalize and validate evidence after redaction, then run a second secret-scanning pass over the final serialized request.
- Prefer local classification for sensitive-path and credential-access findings; send only tag names and non-reversible identifiers.
- Document remote retention, logging, access-control, deletion, and cache policies.
- Add tests proving that secrets embedded in URLs, headers, commands, and matched source lines never appear in outbound requests.
