T09 · Insecure Skill Coding Practices
- Location
scripts/storage.py:150- Finding
SQL Injection Through Unvalidated Update Column Names
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent fridge-management skill, but it needs review because it stores database credentials plainly and contains unsafe database update code.
Install only if you are comfortable with a skill keeping fridge inventory on disk or in your chosen database. Avoid putting real database passwords in the config file unless you can restrict file permissions and use a dedicated low-privilege database account. Treat the database mode as needing hardening before use.
scripts/storage.py:150SQL Injection Through Unvalidated Update Column Names
scripts/storage.py:18Database Credentials Stored in Plaintext Without Enforced File Permissions
scripts/storage.py:110Unpinned Database Driver Installation Guidance
The skill describes local file reads/writes and config persistence but does not declare any explicit tool scope or permissions boundary. This can lead to overbroad file access at runtime, making unintended reads/writes or privilege expansion harder to audit and constrain.
The skill supports remote database storage and collects connection details, including credentials, but provides no warning about privacy, network transmission, or credential-handling risks. In context, this increases the chance that users send sensitive inventory and secrets to remote systems without understanding exposure, encryption, or retention implications.
The skill persists configuration and food inventory to local files but does not clearly warn users that their data will be stored on disk. Users may unknowingly leave sensitive household or routine information in plaintext local storage, increasing privacy and forensic exposure on shared or compromised systems.
The query trigger phrases such as “有什么/查看冰箱/当前食物” are broad enough to overlap with normal conversation, which can cause accidental invocation of the skill. In a stateful skill that reads and writes persistent data, misfires may expose private inventory data or trigger unintended actions in the wrong context.
Using the generic trigger word “建议” for recipe recommendations is overly ambiguous and can collide with ordinary assistant interactions. That raises the chance of accidental activation, causing unnecessary access to stored fridge contents and potentially disclosing user data in unrelated conversations.
This code deletes stored items from the local data file and immediately persists the change, but there is no confirmation prompt, warning message, or explanatory comment indicating that the action is destructive. For a code file, irreversible data deletion should include some visible disclosure unless the destructive behavior is clearly surfaced elsewhere.
The MySQL delete_item method permanently removes rows from the fridge_items table and commits the transaction immediately, but the code provides no user disclosure, confirmation, or warning about the destructive effect. This is a safety-relevant irreversible operation under the code-file criteria.
The PostgreSQL delete_item method executes a DELETE statement and commits it without any visible disclosure that the operation is destructive. Because the removal is irreversible at the storage layer, the file should provide some warning or require callers to confirm intent.
This method permanently deletes a document from the MongoDB collection with no confirmation, prompt, or warning text in the code. Under the missing-user-warnings rule for code files, destructive storage operations should surface their impact to users or be explicitly documented.
描述与触发短语完全以中文给出,呈现出该技能默认面向中文交互的约束,但文档没有说明这是可选语言设置,也没有提供用户选择其他语言的方式。按规则,强制特定语言而无用户选择可构成语言/locale 策略问题。
The file is entirely written in Chinese and presents the skill behavior and data guidance only in that language, with no indication that users may choose another language or locale. This can violate a language/locale policy when a skill effectively mandates a specific language without opt-in or documented justification.
The file's natural-language interface elements are written in Chinese, and no mechanism is indicated for user language choice or locale opt-in. Under the policy rule, forcing a specific language without user choice can be a locale-policy issue unless the regional constraint is clearly documented.
No suspicious patterns detected.