T09 · Insecure Skill Coding Practices
- Location
SKILL.md:20- Finding
Hardcoded University Account Identifier in Reusable Skill Instructions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:20
Vulnerability Type: Hardcoded personal authentication identifier
Risk Level: MediumComplete Code Snippet:
markdown - Default SZU username may be prefilled as `2410032057` for this user's local workflow, but keep the password runtime-only and do not persist it into the skill.Technical Analysis
The reusable Skill contains a specific Shenzhen University username and explicitly permits agents to prefill it during authentication. Although the identifier is not a password, it is authentication-related personal data and should not be embedded in a distributable Skill.
Any user who can inspect or invoke the Skill can recover the identifier. Because the instruction is operational rather than merely descriptive, an agent may also submit authentication attempts under the disclosed identity when another user runs the workflow. The surrounding protections against storing passwords do not mitigate disclosure or misuse of the hardcoded username.
Attack Path
- An unauthorized party obtains or invokes the Skill package.
- The party reads the hardcoded university username from
SKILL.md, or allows the agent to follow the prefill instruction. - The workflow opens the Shenzhen University authentication portal.
- The disclosed username is entered automatically or manually.
- The party uses the identifier for account enumeration, targeted phishing, credential-stuffing attempts, or repeated failed authentication attempts.
- Depending on identity-provider controls, these attempts may disclose account validity or cause temporary account lockout.
Impact Assessment
The issue discloses a personal account identifier and facilitates targeted attacks against the associated university account. It does not directly expose a password or grant authenticated privileges. Successful compromise would still require an additional authentication factor or weakn ...[truncated 350 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the numeric username from the Skill and its documentation.
- Ask the user to provide the account identifier at runtime only when authentication is required.
- If local reuse is necessary, retrieve the identifier from an explicitly configured environment variable or operating-system credential manager.
- Do not log, serialize, or write the runtime identifier into repository files, generated payloads, or temporary files.
- Add a repository secret and personal-data scanning rule to detect institution identifiers and other authentication metadata before publication.
- Preserve the existing requirement to pause for passwords, captchas, verification codes, and multifactor authentication.
