T09 · Insecure Skill Coding Practices
- Location
SKILL.md:24- Finding
Unrestricted Transmission of Raw Trading Prompts to a Third-Party Service
- Content
View full analysis
","symbols":["",""]}' ``` ``` ### Technical Analysis The workflow instructs the agent to copy the complete raw trading prompt into an HTTP request sent to `app.miraix.fun`, a third-party service. It does not require: - Explicit user consent before external transmission. - Disclosure of the external recipient. - Detection or redaction of API keys, credentials, account identifiers, strategy details, or other confidential information. - Data minimization. - A local-only alternative for sensitive prompts. - Verification of the service's retention and privacy practices. Although HTTPS protects the request in transit, it does not prevent the receiving service from storing, processing, or disclosing the submitted data. A user may reasonably believe that a prompt provided to the agent remains within the current interaction and may not expect it to be copied verbatim to an unrelated external service. The shell example also directly interpolates the raw prompt into a single-quoted JSON body. If an implementation constructs this command through textual substitution rather than a structured HTTP client or safe argument passing, quotation characters in the prompt could corrupt the JSON or potentially create command-injection risk. The reviewed package does not contain an executable implementation proving command injection, so that aspect is a secondary implementation risk rathe ...[truncated 1356 chars]- Remediation
View remediation
