T09 · Insecure Skill Coding Practices
- Location
scripts/fetch_hotspot.py:169- Finding
API Credential Transmitted Without TLS Certificate Verification
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a trend-fetching tool, but it handles an API key insecurely and advertises recurring push behavior without enough controls.
Install only after the publisher fixes TLS verification, removes the unnecessary unpinned dependency, replaces unsafe temp-file creation, repairs the syntax error, and documents subscription confirmation and cancellation. Use a narrowly scoped, revocable RedFox API key if you test it.
scripts/fetch_hotspot.py:169API Credential Transmitted Without TLS Certificate Verification
scripts/fetch_hotspot.py:425Unsafe Predictable Temporary File Creation
SKILL.md:64Unnecessary and Unpinned Third-Party Dependency Installation
scripts/fetch_hotspot.py:370Malformed Function Call Prevents Script Execution
The documented purpose does not fully disclose sensitive behaviors: external calls to redfox.hk, reading REDFOX_API_KEY from the environment, and saving full data to a local file. Undisclosed capability expansion is dangerous because reviewers and users may trust the skill for simple hotlist aggregation while it also handles secrets and persists fetched data, increasing the chance of unintended data exposure or policy bypass.
The trigger examples include very generic phrases such as "Hot ranking," "trending list," and "all-platform hot search," which can easily overlap with ordinary user conversation. In an agent ecosystem, this can cause unintended invocation of the skill when a user is merely discussing trends, leading to unexpected external API use, data retrieval, or workflow branching without clear user intent.
Subscription phrases like "Subscribe to daily push" and "Subscribe to weekly push" are ambiguous because they do not identify the skill, subject, destination, or confirmation step. If matched loosely, they could trigger persistent scheduled actions from routine conversation, creating unwanted notifications or ongoing API-backed tasks without sufficiently explicit consent.
The README advertises scheduled push subscriptions but does not warn users that this creates ongoing notifications or other persistent user-impacting behavior. Lack of disclosure reduces informed consent and makes accidental enrollment more likely, especially in a skill that otherwise appears focused on passive data lookup.
The README uses very broad activation examples such as “热点榜 / 热榜 / 全平台热搜”, which overlap with normal user conversation and can cause the skill to trigger when the user did not clearly intend to invoke it. In an assistant environment, ambiguous triggers can lead to unintended data retrieval, context switching, or downstream actions that the user did not explicitly request.
The subscription phrase “订阅每日推送” is an action-oriented trigger that can create an ongoing scheduled behavior, but the README does not indicate any confirmation or opt-in safeguards. Ambiguous or one-shot wording for a persistent action increases the risk of accidental subscription and unwanted recurring notifications.
The skill advertises executable behavior that reads environment variables, performs outbound network access, and writes files, but it does not declare any corresponding tool scope or permissions. This weakens reviewability and consent boundaries, making it easier for a host agent or user to invoke capabilities they did not clearly authorize.
L022 states the skill '不支持查询特定热词详情,仅提供全网热点榜聚合查询', which narrows the intended capability. However, later sections document --keywords filtering and --expand-keywords behavior for targeted term queries, indicating the skill does in fact support focused keyword-based retrieval. This is an active contradiction in the skill documentation.
The skill claims subscription/push functionality but provides no consent model, frequency controls, unsubscribe mechanism, or explanation of what user data would be stored to support notifications. Subscription features inherently involve persistence and repeated contact, so vague documentation can lead to privacy issues, unwanted notifications, or unauthorized monitoring workflows.
The trigger phrase "热点榜" is very broad and likely to appear in ordinary user conversation, making accidental invocation plausible. In a skill that is meant to intercept natural-language trend queries, this can cause the agent to route unrelated or ambiguous requests into the skill unexpectedly, reducing user control and increasing the chance of context hijacking or unintended actions such as subscriptions.
"今日热点" is a common conversational phrase, so the skill may activate when a user is simply discussing current events rather than intentionally invoking this capability. Because the skill aggregates information from multiple platforms and may steer the session toward follow-up actions like viewing more or subscribing, ambiguous activation creates an avoidable prompt-routing risk.
The phrase "最新热榜" is generic and overlaps with everyday requests for the latest trending topics. In an agent environment, broadly matching this phrase can lead to unintentional invocation of the skill, especially when multiple skills or native assistant features could satisfy the same request.
The open-ended "搜..." trigger pattern is under-specified and can match a very large class of everyday requests, creating a broad interception surface. Combined with automatic keyword generalization, the skill may transform a narrow user request into a wider query than intended, which increases the risk of surprising behavior and overbroad data retrieval.
This markdown file is entirely prescriptive in Chinese and includes fixed Chinese interaction phrases such as reply commands for viewing lists and subscribing. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified, which is not present here.
The entire skill document is written as a Chinese-only specification and the prescribed output examples are also only in Chinese, with no indication that users may choose another language or locale. Under the policy, forcing a specific language without opt-in can be a natural-language locale violation unless the regional constraint is explicitly justified.
The skill's natural-language descriptions, warnings, and CLI help text are written exclusively in Chinese, with no indication that users may choose another language. Per the policy, forcing a specific language without opt-in is a natural-language policy concern.
The manifest presents this skill as a hot-search aggregation/report/export/subscription tool for users, but does not indicate any need to access host environment secrets. Reading REDFOX_API_KEY from process environment gives the code access to deployment credentials, which is a broader capability than the user-facing purpose implies.
This code sends user-supplied source, platform, keyword, and date parameters to a remote HTTPS API and includes the REDFOX_API_KEY in the request headers. Although the function has an internal docstring, there is no user-facing disclosure at the CLI boundary that input data will be transmitted to an external service.
The script writes the full fetched dataset to a temporary file and then exposes that path in output. This creates unnecessary local data persistence and may disclose more data than the user expected, especially in shared environments where temp files may be readable by other local users or later reused by other components.
Writing full result data to a temp file without explicit user consent increases the chance of unintended local disclosure and over-retention. Because the script also surfaces the file path, another local actor or downstream tool may access data that the user only expected to see in summarized form.
The primary invocation and usage description is presented entirely in Chinese and includes user-facing trigger examples like '问我准没错', '今日热点', and '查看{平台名}完整榜单' without stating that Chinese is optional or that the skill is intentionally limited to a Chinese-language audience. Under the language/locale policy, forcing a specific language without opt-in can be a natural-language policy concern.
Natural-language policy review applies to all file types. The skill instructions and command phrases are presented only in Chinese, which effectively forces a specific language/locale for use without any opt-in, multilingual alternative, or documented region-specific justification.
"昨天的热点" is still broad conversational language, but it is somewhat more specific than the shorter trigger phrases and therefore slightly less collision-prone. Even so, without clear activation constraints, the skill could still capture ordinary dialogue and perform unintended retrieval behavior.
"本周热点" is a natural phrase a user might say in many contexts, so it can collide with ordinary assistant requests. The context of this skill makes accidental routing credible because the skill is specifically designed around common trending-topic queries.
The script reads REDFOX_API_KEY from the environment to authenticate outbound requests. While the missing-variable error explains how to set the variable, it does not warn users up front that the skill accesses a credential from the environment as part of its normal operation.
Detected: suspicious.insecure_tls_verification