T09 · Insecure Skill Coding Practices
- Location
references/web-api-params.md:202- Finding
Transmission of Device Identifiers and Location Data over Plaintext HTTP
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent map-migration documentation skill, but it includes unsafe copy-ready guidance for sensitive location/device data and mutable install/dependency examples that users should review carefully.
Install only after reviewing the migration examples. Do not send MAC addresses, IMEI, cell tower data, or precise location over plaintext HTTP, and use dedicated restricted API keys instead of shared demo keys for production. Pin CLI, repository, Gradle, and CocoaPods versions in controlled environments.
references/web-api-params.md:202Transmission of Device Identifiers and Location Data over Plaintext HTTP
references/sdk-migration.md:11Unpinned Android SDK Dependencies Use Dynamic Versions
SKILL.md:370Installation Command Executes an Unpinned Package and Retrieves Mutable Skill Content
SKILL.md:41Shared API Credentials Are Embedded in Documentation and Generated Examples
The skill explicitly documents a non-HTTPS geolocation endpoint that accepts sensitive device identifiers such as MAC address and IMEI, while only giving a weak note to use HTTPS 'where supported.' If followed, this can expose device identifiers and location-related data to interception or logging in transit, which is especially dangerous because the content is framed as migration guidance developers may copy directly.
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
title: 'Tokyo',
icon: 'icon.png'
});
marker.setMap(null); // remove
// AMap
const marker = new AMap.Marker({
The trigger list contains broad generic phrases like 'free map API', 'geocoding', 'directions', and 'places search', which can cause the skill to activate in unrelated contexts. Over-broad invocation increases the chance of unintended execution, context hijacking, or surfacing embedded risky guidance such as public keys and insecure endpoints to users who did not request this skill.
The skill instructs users to run npx skills add without pinning an exact package/version, which can fetch whatever the registry serves at execution time. This creates a supply-chain risk: a compromised package, malicious update, or typosquatted dependency could be executed on the user's system.
The follow-up statement normalizes npx skills add as an official install path, again without version pinning or integrity guarantees. Recommending an unpinned executable install path increases the chance users will execute unexpected code if the upstream package changes or is compromised.
The documentation embeds a concrete AMap API key directly in example script URLs and frames the skill as including free public keys for global developers. Even if intended as a shared or low-privilege key, publishing live credentials in reusable examples encourages insecure key handling, increases the chance of quota theft or abuse, and may lead developers to ship the same exposed key into production.
The guide encourages use of geocoding, reverse-geocoding, routing, and location SDK features that inherently transmit user-entered addresses, coordinates, and potentially live location data to a third-party provider, but it does not warn developers about privacy, consent, retention, or regional compliance implications. In a migration skill aimed at global developers, omission of this disclosure can lead downstream apps to integrate location flows without proper user notice or legal review, increasing privacy and compliance risk.
The documentation includes a live-looking AMap API key directly in a sample request. Even if intended as a public/demo key, publishing concrete credentials in reusable examples encourages unauthorized use, key scraping, quota theft, billing abuse, and downstream developers copying the key into production code. In this skill’s context, the danger is increased because the skill explicitly advertises 'free public API keys included,' suggesting deliberate redistribution of shared credentials.
The geolocation section instructs users to send Wi‑Fi MAC addresses, cell tower data, and device IMEI without any privacy, consent, minimization, or legal-compliance warning. These identifiers can enable device tracking or collection of sensitive location data, and the risk is heightened by the note showing a non-mainland endpoint over HTTP, which could expose telemetry in transit if copied as-is.
The file states that no external links are needed because all migration info is contained here, yet the setup and example code require external script URLs to function. This is a mild description-behavior mismatch in the documentation's claim about self-containment rather than a security-sensitive contradiction.
No suspicious patterns detected.