T09 · Insecure Skill Coding Practices
- Location
SKILL.md:19- Finding
Hardcoded Institutional User Identifier
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 19
Vulnerability Type: Hardcoded sensitive account metadata
Risk Level: LowComplete Code Snippet:
markdown - Default SZU username may be prefilled as `2410032057` for this user's local workflow, but keep the password runtime-only and do not persist it into the skill.Technical Analysis
The Skill embeds a specific Shenzhen University username directly in its instructions. Although this is not a password and the surrounding instructions prohibit storing passwords and verification codes, an institutional account identifier is still sensitive account metadata that should not be distributed with a reusable Skill.
When the Skill is loaded, an agent may automatically prefill this identifier on the documented university authentication page. This leaks information associated with a particular user and creates a risk that unrelated users will initiate authentication attempts under the wrong account. The identifier may also assist account enumeration, targeted phishing, or social-engineering activity when combined with the disclosed institutional affiliation and login route.
Attack Path
- An attacker or unrelated operator obtains or loads the Skill package.
- They inspect
SKILL.mdand recover the embedded institutional username. - They associate the identifier with the Shenzhen University authentication route documented by the Skill.
- They may use it for account-enumeration attempts, targeted phishing, social engineering, or repeated authentication attempts.
- Separately, a legitimate agent following the instructions may prefill the identifier for another user, causing accidental use or disclosure of the account identity.
Impact Assessment
The issue does not directly disclose a password, MFA token, authenticated session, or system privilege. It therefore does not independently grant account access. Its scope ...[truncated 319 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the literal username from
SKILL.md. - Ask the user to provide their institutional username at runtime when authentication is required.
- Keep the username, password, MFA codes, and session tokens out of the Skill repository, generated files, command history, and logs.
- If account reuse is necessary, retrieve the username from a user-controlled credential manager or environment-specific configuration that is excluded from version control.
- Require explicit confirmation before filling any login identifier so that a reusable Skill cannot silently authenticate under another person's identity.
- Review repository history and distributed copies for the identifier and remove it where practical.
- Remove the literal username from
