other
- Location
SKILL.md:22- Finding
Unnecessary External Disclosure of Financial Data and Authentication Tokens
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:22-30,SKILL.md:190-205,README.md:52-71
Vulnerability Type: Privacy misrepresentation and unnecessary sensitive-data transmission
Risk Level: MediumThe Skill presents examples that transmit business turnover, invoice amounts, accounting data, tax-return figures, and bearer credentials to external services. These instructions conflict with the README's unconditional claims that no external data is sent and no sensitive data leaves the machine.
Vulnerable Code Snippets
SKILL.md:22-30:bash # Check if business needs GST registration (threshold: S$1M annual turnover) curl -s "https://www.iras.gov.sg/api/gst-threshold-check" -d '{"turnover": 1000000}'bash # Calculate GST (9% as of 2024) curl -s "https://api.gstcalculator.sg/calculate" -d '{"amount": 1000, "rate": 0.09}' # Returns: {amount: 1000, gst: 90, total: 1090}SKILL.md:190-205:bash # Export sales data curl -s "https://api.xero.com/api/Invoices?status=PAID" \ -H "Authorization: Bearer TOKEN" # Export purchase data curl -s "https://api.xero.com/api/Bills?status=PAID" \ -H "Authorization: Bearer TOKEN"bash # Submit GST return (requires CorpPass authentication) curl -s "https://apiservices.iras.gov.sg/gst/f5" \ -X POST \ -H "Authorization: Bearer CORPPASS_TOKEN" \ -d '{"period": "202403", "box1": 100000, "box4": 9000, ...}'README.md:52-71:markdown ## External Endpoints | Endpoint | Data Sent | Purpose | |----------|-----------|---------| | https://www.iras.gov.sg/api/* | None (reference only) | GST registration info | | https://api.gstcalculator.sg/* | Amount, rate | GST calculation | ## Security & Privacy - **No sensitive data leaves your machine** - All calculations are local - **No API keys required** - Uses public IRAS reference data - **Scripts are open source** - Review before installi ...[truncated 3370 chars]- Remediation
View remediation
Remediation Suggestions
- Remove the third-party GST calculator request and perform GST arithmetic exclusively with the bundled local script.
- Implement the registration threshold comparison locally rather than transmitting turnover.
- Require explicit, per-operation user confirmation before contacting Xero, IRAS, or any other external service.
- Clearly identify each recipient, transmitted field, purpose, and applicable retention policy before sending data.
- Replace the unconditional privacy statements with accurate disclosures that distinguish local calculations from optional integrations.
- Do not place real tokens directly in documentation, prompts, command history, or agent transcripts. Retrieve them from a protected credential store at execution time.
- Use short-lived, least-privilege tokens restricted to the precise read or filing operation required.
- Prevent authorization headers and request bodies from being written to logs, error messages, or telemetry.
- Validate external endpoint ownership and use only documented official APIs. Remove or disable endpoints whose authenticity and operational necessity cannot be established.
- Make network access opt-in by default rather than relying on users to configure routing rules to opt out.
