T09 · Insecure Skill Coding Practices
- Location
scripts/gitea_api.py:34- Finding
Site-administrator token transmitted over plaintext HTTP
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is for a real onboarding workflow, but it uses broad administrator access and insecure account-linking/network defaults that need review before installation.
Review this skill before installing. Use it only in a controlled paper-kb deployment, move Gitea to HTTPS before any token is configured, avoid a site-wide admin token where possible, add proof that the Feishu user controls the requested Gitea account, protect or avoid storing Feishu tokens in users.json, and install dependencies in a dedicated virtual environment rather than the system Python.
scripts/gitea_api.py:34Site-administrator token transmitted over plaintext HTTP
scripts/init_user.py:147Gitea accounts can be bound without proof of account ownership
scripts/init_user.py:129Registration metadata and Feishu table routing rely only on an asserted open_id
setup.sh:8Unpinned dependencies are installed into the system Python environment
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# paper-kb / init_user 环境配置
# 复制本文件为 .env 并填入真实值
# Gitea 服务器地址(注意确认是哪台服务器!末尾不要带斜杠)
GITEA_URL=http://43.156.243.152:3000
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# paper-kb / init_user 环境配置
# 复制本文件为 .env 并填入真实值
# Gitea 服务器地址(注意确认是哪台服务器!末尾不要带斜杠)
GITEA_URL=http://43.156.243.152:3000
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# paper-kb / init_user 环境配置
# 复制本文件为 .env 并填入真实值
# Gitea 服务器地址(注意确认是哪台服务器!末尾不要带斜杠)
GITEA_URL=http://43.156.243.152:3000
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# paper-kb / init_user 环境配置
# 复制本文件为 .env 并填入真实值
# Gitea 服务器地址(注意确认是哪台服务器!末尾不要带斜杠)
GITEA_URL=http://43.156.243.152:3000
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# paper-kb / init_user 环境配置
# 复制本文件为 .env 并填入真实值
# Gitea 服务器地址(注意确认是哪台服务器!末尾不要带斜杠)
GITEA_URL=http://43.156.243.152:3000
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# paper-kb / init_user 环境配置
# 复制本文件为 .env 并填入真实值
# Gitea 服务器地址(注意确认是哪台服务器!末尾不要带斜杠)
GITEA_URL=http://43.156.243.152:3000
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# paper-kb / init_user 环境配置
# 复制本文件为 .env 并填入真实值
# Gitea 服务器地址(注意确认是哪台服务器!末尾不要带斜杠)
GITEA_URL=http://43.156.243.152:3000
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# paper-kb / init_user 环境配置
# 复制本文件为 .env 并填入真实值
# Gitea 服务器地址(注意确认是哪台服务器!末尾不要带斜杠)
GITEA_URL=http://43.156.243.152:3000
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# paper-kb / init_user 环境配置
# 复制本文件为 .env 并填入真实值
# Gitea 服务器地址(注意确认是哪台服务器!末尾不要带斜杠)
GITEA_URL=http://43.156.243.152:3000
The file instructs operators to create and use a Gitea administrator access token with broad privileges including admin write. Even though no live token is present, embedding a workflow that requires a highly privileged long-lived token increases the blast radius of compromise and encourages unsafe secret management if copied into a real .env file.
# Gitea 服务器地址(注意确认是哪台服务器!末尾不要带斜杠)
GITEA_URL=http://43.156.243.152:3000
# 机器人账号的 Access Token
# 要求:该账号必须是 Gitea 站点管理员(管理后台→用户管理→勾选"是管理员")
# Token 权限范围:repo 读写、admin 写、user 读
GITEA_ADMIN_TOKEN=在这里填入token
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
except ImportError:
return
here = Path(__file__).resolve().parent
for candidate in (here / ".env", here.parent / ".env"):
if candidate.exists():
load_dotenv(candidate)
return
The code explicitly implements admin-only capabilities such as enumerating admin access and creating repositories for arbitrary users. Those operations are powerful control-plane actions; if exposed through an agent skill or invoked unexpectedly, they can modify other users' resources and facilitate unauthorized persistence or lateral abuse in the Gitea instance.
The skill provides fixed Chinese reply text and directs the agent to send it verbatim, which effectively forces a specific language for user communication. The file does not indicate that the language is optional, user-selected, or justified as a region-specific constraint.
The skill explicitly instructs users to register via a plain HTTP Gitea URL, which exposes credentials and session data to interception or modification by any network attacker on the path. This is especially risky because the step is part of account onboarding, where users are likely to submit usernames, passwords, or other sensitive setup data without noticing the absence of transport security.
This manifest description explains what the skill does but does not specify precise invocation phrases, scope boundaries, or exclusion conditions. For a manifest file, that can make activation criteria ambiguous and increase the chance of unintended invocation in contexts involving generic user initialization or registration guidance.
The natural-language description is written to indicate Chinese-specific behavior and labels without any indication that users may choose another language or that the locale restriction is intentional and justified. This can violate language/locale policy when a skill implicitly enforces a specific language without opt-in.
This code hardcodes the type display field as Chinese ("中文类型名") for outputs written to frontmatter, Feishu tables, and index section titles. That is a natural-language locale constraint, and the file does not provide any user choice, opt-in, or documented region-specific justification for requiring Chinese.
The module loads a Gitea administrator token from the environment and prepares it for all API requests, giving this code broad administrative reach if the token is present. In the context of a reusable skill module, bundling admin-capable credential use with no visible scoping, least-privilege controls, or operation gating significantly increases the blast radius of misuse or compromise.
This code sends HTTP requests with an Authorization header derived from GITEA_ADMIN_TOKEN, which is a safety-relevant network operation involving credentials. Although the module docstring describes its technical role, there is no user-facing warning, confirmation, or disclosure here about outbound API calls using admin-level authentication.
The put_file function creates or updates files in a remote repository, which is a persistent write operation affecting system data. While the function name and docstring describe behavior, there is no warning or disclosure about the side effect of modifying repository contents.
ensure_system_repo bootstraps a repository and writes users.json, creating durable configuration state on the Gitea server. This is a safety-relevant change to system integrity, but the file lacks any explicit warning or user disclosure beyond routine implementation comments.
The documented '--check' mode implies a simple registration-status lookup, but do_check() returns the entire stored user record when a user exists. That record includes Feishu app/table identifiers and potentially other sensitive metadata, creating an unnecessary information disclosure path to any caller able to supply an open_id.
The update-feishu mode is described as writing back table information, but do_update_feishu() also echoes the provided feishu_app_token and feishu_table_id to stdout. Since stdout is consumed by orchestration systems and often logged, this leaks sensitive identifiers into logs and downstream tooling unnecessarily.
The natural-language instruction 全部使用中文 imposes a fixed language policy on AI-generated content. There is no indication that users can choose another language or that the Chinese-only requirement is an explicitly justified regional constraint.
The script persists feishu_app_token and feishu_table_id in the user mapping record and also depends on GITEA_ADMIN_TOKEN, but the file lacks any warning comment or docstring explaining that credentials are stored and used for privileged operations. Because this involves sensitive tokens and administrator access, the absence of explicit disclosure is a safety concern.
No suspicious patterns detected.