T09 · Insecure Skill Coding Practices
- Location
monitor.py:78- Finding
Remote security notifications are silently discarded
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill appears to be a simple local NAS monitor, but it materially overstates remote alerting and monitoring features that the shipped code does not implement.
Review this carefully before installing if you need real unattended NAS alerting: the current artifact does not send Feishu, Discord, or Telegram notifications and does not implement several advertised monitoring checks. It is suitable only as a local, foreground prototype unless those gaps are fixed.
monitor.py:78Remote security notifications are silently discarded
monitor.py:52CPU temperature monitoring failures are silently suppressed
monitor.py:43Memory monitoring fails when the monitor is imported as a module
The documented behavior does not match the apparent implementation: key claims such as Feishu/Discord alerting and network monitoring are described as supported while analysis indicates they are incomplete or placeholder-only. This is dangerous because operators may rely on the skill for security-relevant monitoring and alert delivery that does not actually occur, leading to missed incidents or delayed response.
The skill advertises or implies shell-based operational capability but does not declare any explicit tool scope such as permissions or allowed-tools. This creates a least-privilege and transparency problem: an agent or user may invoke shell-capable behavior without a clearly bounded execution policy, increasing the risk of unintended command execution against the NAS host.
The file header and later user-facing strings indicate the skill presents operational output in Chinese, but there is no opt-in, language selection, or justification that the skill is region-specific. This can violate a language/locale policy when users are not given a choice.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
def check_disk_usage(self):
"""检查磁盘使用率"""
result = subprocess.run(['df', '-h'], capture_output=True, text=True)
lines = result.stdout.strip().split('\n')[1:]
for line in lines:
The skill description says it monitors NAS health and auto-alerts via Feishu/Discord. However, the notification function is a stub with a TODO and no outbound messaging logic, so the code does not actually perform the described alert delivery behavior.
The main descriptive content begins in Chinese and the feature list continues in that language, with no indication that other languages are supported or that the user can choose a preferred locale. This can violate language/locale policy expectations when a skill forces a specific language without opt-in.
No suspicious patterns detected.