T09 · Insecure Skill Coding Practices
- Location
scripts/data_manager.py:116- Finding
Spreadsheet Formula Injection Through Unsanitized Complaint Data
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This complaint-handling skill is purpose-aligned, but it handles sensitive customer records with under-scoped local storage and external notification behaviors that users should review before installing.
Install only in an authorized complaint-management environment. Before use, configure paths and WeCom destinations deliberately, restrict access to generated reports/backups, avoid unnecessary personal data, and add spreadsheet formula neutralization plus clear retention and notification policies.
scripts/data_manager.py:116Spreadsheet Formula Injection Through Unsanitized Complaint Data
scripts/wecom_sender.py:32Unrestricted Webhook URL Enables Server-Side Request Forgery
The skill explicitly processes and records customer personal data such as names, phone numbers, complaint details, and satisfaction records, but the user-facing content does not provide clear privacy warnings, handling constraints, retention limits, or consent guidance. In this context, the skill normalizes collecting and storing personally identifiable information in spreadsheets and platforms, which increases the risk of unnecessary disclosure, over-collection, or improper downstream use.
The module docstring and all user-facing CLI help text are written only in Chinese, which effectively imposes a specific language on users. The file does not indicate that the skill is region-specific or provide any opt-in or alternative locale, so this is a natural-language policy concern under the language/locale rule.
The module title and governing-process description are written only in Chinese, and the file exposes no indication that users may choose another language or locale. Under the policy, language constraints should be opt-in or clearly justified as region-specific; this file provides neither in its natural-language text.
This code overwrites the '投诉记录' sheet in the configured Excel workbook, which contains customer complaint data and related identifiers. Although there is a success print after saving, there is no confirmation prompt or prior disclosure warning before performing the write operation on potentially sensitive user data.
The code implements a hard-coded backup routine that duplicates a complaint Excel file containing personal and complaint data into a fixed directory under the user's home path. This increases data exposure and retention risk because sensitive records are copied to an additional location without access controls, configurability, encryption, or any visible consent/justification in the module.
The backup function silently creates another on-disk copy of sensitive complaint data, expanding the attack surface and persistence of personal information. Even if intended for recovery, undisclosed duplication of regulated or private records can worsen the consequences of endpoint compromise, over-retention, or accidental disclosure.
The module sends complaint data including customer name, room number, complaint content, and timing to an external WeCom webhook without any consent check, minimization, masking, or user-facing notice. In a complaint-handling context this is potentially sensitive business and personal information, so exfiltration or over-sharing to a third-party messaging platform creates a real confidentiality and compliance risk.
The only natural-language description in this file is written entirely in Chinese, which may reflect a language-specific constraint without any indication that users can choose another language. Under the policy rule for language/locale constraints, this can be a violation when a specific language is imposed without user opt-in or justification.
The file's docstrings and operational messages are written only in Chinese, which effectively fixes the skill's language for users and operators. Under the policy, forcing a specific language without opt-in or documented locale justification is a natural-language policy concern.
This code file contains natural-language descriptions and generated reminder content exclusively in Chinese, including module docstrings and all user-facing message templates. Under the policy rule, forcing a specific language without opt-in can be a locale-policy violation when no user choice or justification is provided.
The natural-language content in docstrings and outbound notification templates is entirely fixed in Chinese, and the file provides no indication that users can choose another language or locale. This can violate language/locale policy when a skill forces a specific language without user opt-in.
No suspicious patterns detected.