T09 · Insecure Skill Coding Practices
- Location
SKILL.md:91- Finding
Exposure of Internal Credential-Vault Reference and Automation Service Details
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a coherent n8n routing guide, but it exposes a concrete credential-vault locator and directs users toward unaudited local automation setup that can create persistent workflows.
Review this before installing in a shared or broadly privileged agent environment. Replace the concrete 1Password credential locator with a generic configuration reference, verify the external n8n start script separately, use a least-privilege n8n API key, and require explicit user approval before resolving secrets or activating workflows.
SKILL.md:91Exposure of Internal Credential-Vault Reference and Automation Service Details
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
- Weekly competitive intel run → **~$10–20/month saved**
- Recurring "check X, send Y" tasks → **97% cheaper in n8n**
> **Note:** Social publishing (LinkedIn, X) uses Buffer (`skills/buffer-publisher/SKILL.md`). Typefully cancelled 2026-03-25.
If a task runs daily and takes no reasoning, it should be in n8n. Full stop.
The file documents sensitive operational details, including localhost service location and a credential reference, without any warning to avoid exposing, copying, or retrieving secrets. In an agent skill, this can normalize unsafe secret handling and encourage downstream agents or users to treat the referenced credential as part of normal task execution rather than protected material.
The skill documentation includes a concrete secret locator for the n8n API key (op://.../credential) even though the skill’s stated purpose is only task-routing guidance. Exposing the existence and exact storage path of a credential lowers the effort required for an attacker or over-privileged agent to target and retrieve that secret, and the routing context does not justify disclosing it.
No suspicious patterns detected.