T09 · Insecure Skill Coding Practices
- Location
SKILL.md:55- Finding
Authorization Header Leakage Through Unvalidated Pagination URLs
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent ETL guide, but its sample API extractor can forward authorization headers to unvalidated pagination URLs while handling financial/business data.
Review before installing or using this skill for real credentials. Harden the API extractor to restrict pagination to the original trusted HTTPS host, add timeouts and page limits, load secrets from environment variables or 1Password CLI, pin dependencies in an isolated environment, and ensure any Telegram alerts contain only sanitized status text.
SKILL.md:55Authorization Header Leakage Through Unvalidated Pagination URLs
SKILL.md:288Unpinned Third-Party Dependency Installation
The manifest says the skill is not for raw SQL query writing, and the safety rules state extraction is read-only by default. Yet the QBO example embeds a free-form query string (SELECT * FROM Invoice) directly in the request URL, demonstrating raw query composition against a source system rather than a constrained extractor pattern. This contradicts the documented boundary around avoiding raw query writing.
The checklist and safety rules explicitly require secrets to be stored in environment variables rather than hardcoded. However, the example code defines HEADERS = {"Authorization": "Bearer <TOKEN>"...}, normalizing an in-code credential pattern that conflicts with the stated guidance. Even as a placeholder, the documented example contradicts the declared secure usage model.
The skill instructs users to send completion or failure notifications to Telegram without warning that operational details, paths, timestamps, pipeline names, or error content may be transmitted to a third-party service. In an ETL context handling financial and business data, even status metadata can reveal sensitive internal operations or be expanded later to include logs and customer information.
No suspicious patterns detected.