T09 · Insecure Skill Coding Practices
- Location
scripts/breathing_calc.py:625- Finding
Missing Numeric Input Validation Can Crash Calculations or Produce Unsafe Valve Recommendations
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent local engineering calculator, but validated calculation-safety defects could produce unsafe valve recommendations in a documented use case.
Review this before installing if you plan to use it for real engineering decisions. It does not show agentic abuse such as exfiltration or persistence, but its current calculations need independent validation, especially for 5000-10000 m scenarios and for malformed, zero, negative, or extreme numeric inputs.
scripts/breathing_calc.py:625Missing Numeric Input Validation Can Crash Calculations or Produce Unsafe Valve Recommendations
scripts/breathing_calc.py:366Altitude Conversion Silently Clamps Values Above 5000 Meters and Underestimates Valve Demand
Suspicious Unicode normalization or mixed-script content
Suspicious Unicode normalization or mixed-script content
Suspicious Unicode normalization or mixed-script content
Suspicious Unicode normalization or mixed-script content
Suspicious Unicode normalization or mixed-script content
The skill description, feature list, and example invocation are written in Chinese and the example natural-language trigger is also Chinese, with no indication that other languages are supported. This can constitute a language/locale policy issue because the skill appears to require a specific language without explicit user opt-in or alternatives.
This manifest presents the skill name and primary descriptive content entirely in Chinese, while also including some English tags/triggers elsewhere. Because there is no explicit user opt-in, language selection, or justification that the skill is region-specific, this can violate the language/locale policy for natural-language content.
The title and all instructional content are presented only in Chinese, with no indication that the skill supports other languages or lets the user opt in to this locale. Under the policy, forcing a specific language without user choice can be a natural-language policy violation unless the regional constraint is documented and justified.
The module docstring and all user-facing CLI help text are written entirely in Chinese, which imposes a specific language on users. The file does not offer an opt-in language selection or explain that the tool is intentionally region- or locale-specific, so it conflicts with the language/locale policy criteria.
No suspicious patterns detected.