T09 · Insecure Skill Coding Practices
- Location
SKILL.md:62- Finding
Untrusted Search Results Passed Directly to an LLM Prompt
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This news aggregation skill is purpose-aligned and disclosed, but users should understand that queries and search results are sent to SkillBoss for search and summarization.
Install only if you are comfortable using SkillBoss as the search and summarization provider. Avoid confidential or regulated queries, because queries and retrieved result content may be processed by that external API. Treat generated summaries as drafts and verify important claims and links against the cited sources.
SKILL.md:62Untrusted Search Results Passed Directly to an LLM Prompt
The skill explicitly sends collected search results to a remote SkillBoss chat endpoint for summarization, but the documentation does not warn users that retrieved content will be transmitted to a third-party service. This creates a privacy and data-governance risk because search results may include sensitive queries, internal topics, or regulated data, and users are not given an opportunity to consent or minimize what is shared.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
import requests, os
SKILLBOSS_API_KEY = os.environ["SKILLBOSS_API_KEY"]
API_BASE = "https://api.skillboss.co/v1"
def pilot(body: dict) -> dict:
r = requests.post(
The code performs an authenticated outbound POST request to a remote API and can transmit arbitrary request bodies, including search queries and collected results. In this skill's context, that means external data transfer is part of normal operation, but without explicit safeguards it can expose sensitive user-provided or retrieved content to a third party.
API_BASE = "https://api.skillboss.co/v1"
def pilot(body: dict) -> dict:
r = requests.post(
f"{API_BASE}/pilot",
headers={"Authorization": f"Bearer {SKILLBOSS_API_KEY}", "Content-Type": "application/json"},
json=body,
The README states that the skill automatically searches, filters, and organizes news, which implies network access and possible transmission of queries or metadata, but it does not warn users about that behavior. While network access is expected for a news aggregation skill, the lack of disclosure can mislead users about privacy and operational behavior, especially in environments with restricted outbound access or logging concerns.
The natural-language description and operational guidance are presented entirely in Chinese, which can amount to a language policy issue when no user opt-in or locale justification is provided. There is no indication that the skill is intended only for a Chinese-language audience or region-specific use.
No suspicious patterns detected.