T09 · Insecure Skill Coding Practices
- Location
scripts/fetch_coupons.py:39- Finding
Unvalidated Remote Coupon Destinations Are Presented to Users
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill fetches disclosed travel coupon links and QR codes from a third-party API; the main risk is that users should verify those external redemption destinations before opening them.
Install only if you are comfortable using a third-party coupon API and opening coupon links or QR codes from external domains. Verify the destination before redeeming, especially in WeChat, and treat the unrelated takeout-coupon reference file as documentation clutter rather than the core trip-coupon workflow.
scripts/fetch_coupons.py:39Unvalidated Remote Coupon Destinations Are Presented to Users
The skill description does not clearly warn that it will contact a third-party API and present redemption URLs and QR codes hosted on external domains. Without an upfront disclosure, users may not realize their request triggers external network access and that following the returned links can send them to unvetted third-party destinations, creating phishing, tracking, and trust risks.
The trigger phrases are broad enough to match generic travel-saving or booking-related requests that are not clearly asking to redeem third-party coupons. This can cause unintended invocation of a networked skill that fetches and promotes external links/QR codes, increasing the chance of surprising users and routing them to third-party destinations without clear prior intent.
Multiple lines instruct that coupon links should be opened in WeChat or redeemed by scanning in WeChat, which effectively imposes a specific platform/locale usage pattern. The document does not clearly frame this as an optional preference with alternatives or justify it as a region-specific constraint.
This markdown file presents all instructions, field descriptions, and usage details exclusively in Chinese. Under the policy rule for natural-language violations, forcing a single language without user opt-in or a documented regional justification can be a locale-policy issue.
The heading uses Chinese text ("外卖优惠券") without any indication that the skill supports multiple languages or that the user opted into a Chinese locale. This can violate language/locale policy when a skill appears to assume a specific language by default.
The docstring and printed message include the Chinese phrase "外卖优惠券" as the skill/topic label, but the file provides no indication that language selection is optional or region-specific. Under the policy, language constraints should be opt-in or clearly justified; otherwise they can constitute a locale/language policy issue.
The top-level docstring is entirely in Chinese and presents the skill as a fixed Chinese-language tool, with no indication that other languages/locales are supported or that the user can opt in to Chinese. The policy for this audit flags language/locale constraints when a skill forces a specific language without user choice or justification.
No suspicious patterns detected.