T09 · Insecure Skill Coding Practices
- Location
references/wasm-plugin-sdk.md:216- Finding
External Authorization Plugin Fails Open When Call Dispatch Fails
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly purpose-aligned for offline nginx-to-APIG migration, but its generated gateway-plugin guidance includes unsafe authorization and deployment patterns that need careful review before use.
Review generated WasmPlugin code before deployment, especially any authentication or authorization plugin. Change external-auth examples to fail closed on dispatch errors, pin dependencies and image digests or reviewed versions, avoid persistent global Go proxy changes unless intentional, preview and namespace-scope kubectl delete commands, and treat request bodies, Authorization headers, mirrored traffic, and log attributes as sensitive data.
references/wasm-plugin-sdk.md:216External Authorization Plugin Fails Open When Call Dispatch Fails
references/wasm-plugin-sdk.md:18Mutable and Incompletely Pinned Go Dependencies Create Supply-Chain Risk
scripts/analyze-ingress-offline.sh:143Untrusted Annotation Values Can Inject Terminal Control Sequences
The code aligns with part of the description: it performs offline analysis of nginx Ingress YAML without cluster access and classifies annotations for APIG migration compatibility. However, the declared purpose is broader and promises multiple migration capabilities that are not present in this code chunk. The actual code only analyzes one YAML file and outputs classification results; it does not generate migrated Ingress YAML, map resources to Higress-native constructs, select built-in plugins in any concrete way, develop WasmPlugins, or produce a substantive migration report/deployment guide. This is a description-behavior mismatch because significant declared capabilities are absent from the supplied code.
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
6. For custom WasmPlugin, use `github.com/higress-group/wasm-go/pkg/wrapper` SDK exclusively
7. Track annotation value changes (e.g., `ewma` → `round_robin`) explicitly in the report
8. For `server-snippet`/`configuration-snippet`, enumerate every directive and verify 1:1 conversion completeness
9. Never execute cluster write operations (`kubectl apply`, `docker push`, etc.) — only output instructions for the user
## Reference Links
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
| `basic-auth` | HTTP Basic Auth (RFC 7617) | `auth_basic` directive | [doc](https://help.aliyun.com/zh/api-gateway/cloud-native-api-gateway/user-guide/basic-auth-plug-ins) |
| `hmac-auth` | HMAC signature-based authentication | Signature validation scripts | [doc](https://help.aliyun.com/zh/api-gateway/cloud-native-api-gateway/user-guide/hmac-auth-plug-ins) |
| `jwt-auth` | JWT validation from URL params, headers, or cookies; supports per-caller credentials | JWT Lua scripts, `auth_request` for JWT | [doc](https://help.aliyun.com/zh/api-gateway/cloud-native-api-gateway/user-guide/jwt-auth-plug-ins) |
| `oauth` | OAuth 2.0 Access Token issuance based on JWT (RFC 9068) | OAuth Lua scripts | [doc](https://help.aliyun.com/zh/api-gateway/cloud-native-api-gateway/user-guide/oauth-plugin) |
| `jwt-logout` | JWT logout & unique-login control via Redis; supports session kick-off across devices | Custom session invalidation logic | [doc](https://help.aliyun.com/zh/api-gateway/cloud-native-api-gateway/user-guide/jwt-logout-plug-ins) |
## Traffic Control
The skill states it operates offline and does not execute tools, yet it contains instructions referencing file-path and directory handling plus shell-based verification/tool checks, while declaring no explicit tool scope. That mismatch can lead an agent runtime to grant broader-than-necessary file_read or shell capabilities, increasing the risk of unintended local file access or command execution if the skill is invoked on untrusted input.
The instruction says all output should use Chinese, which imposes a language choice regardless of the user's preference. This is a natural-language policy issue because the file does not offer an opt-in or alternative language selection.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
See `references/deployment-guide-template.md` for the guide template.
> **Scope boundary**: This skill generates all artifacts and instructions. It does NOT execute `kubectl apply`, `docker push`, or any cluster/registry write operations. Those are left to the user.
> **No confirmation needed**: Every item above is always generated. Never ask "是否需要生成迁移文件/检查清单/部署指南?"
## Success Verification Method
This markdown file includes user-facing migration guidance entirely in Chinese in the acceptance examples, with no indication that the skill supports language selection or that Chinese is a justified locale constraint. That can violate language/locale policy because it implicitly requires a specific language for user instructions without opt-in.
The guidance recommends replacing unsupported annotations with built-in or custom WasmPlugins, including external auth callouts, header/body manipulation, mirroring, and WAF behavior, but it does not warn that these extensions can change trust boundaries and expose sensitive traffic or credentials. In this skill context, users may rely on the migration output as safe-by-default, so missing cautions can lead to deployment of plugins that exfiltrate request data, mishandle authentication, or introduce unsafe custom code paths.
proxy-request-buffering is listed as unsupported with an implied WasmPlugin replacement path, but the surrounding text says it can usually be safely dropped. That contradiction can lead the agent to over-prescribe custom plugins for a setting that may not need one, or worse, to drop buffering semantics without flagging edge cases where backends require buffered requests, causing request handling errors or data-path regressions.
The file labels denylist-source-range as unsupported, yet the note immediately states APIG officially supports the equivalent control via higress.io/blacklist-source-range. A migration agent following the unsupported classification may strip an active blacklist or replace it incorrectly with a plugin instead of the native security control, weakening access restrictions.
The document gives a blanket rule that every unsupported annotation must be replaced with a WasmPlugin, but later carves out service-upstream as an exception that should simply be stripped. This inconsistency can cause the migration agent to generate unnecessary plugin references or conflicting migration outcomes, increasing the chance of incorrect traffic behavior and avoidable custom extension deployment.
The rollback section instructs users to run kubectl delete ingress -l migration.higress.io/source=nginx, which can delete live ingress resources across the selected label set without clearly warning that this is a destructive production action. In a migration skill, users may copy-paste rollback commands under time pressure, so insufficient scoping, confirmation guidance, and safety warnings increase the chance of unintended service disruption.
The file instructs users to use a region-specific Alibaba Cloud registry and later tells them to check the Alibaba Cloud APIG console, effectively steering operation toward a specific platform/region. The guidance does not offer an opt-in or alternative path, and the locale/platform constraint is not explicitly justified as mandatory beyond a brief implementation note.
Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.
This markdown file includes examples that explicitly mention calling external services and routing request bodies upstream, which can transmit request data off-process or off-box. The surrounding documentation does not warn users about privacy or data-handling implications of sending request/response content to external services.
The documentation demonstrates attaching attributes such as user identifiers to access logs and trace spans, which can affect privacy and data retention. There is no accompanying warning advising users to avoid logging sensitive or regulated data.
This markdown file includes an example that reads the incoming authorization header and forwards it to another service via config.client.Get(...). Although the document has a general production safety notice, it does not explicitly warn readers that the pattern transmits potentially sensitive credentials or request-derived data to external services, which is the type of disclosure SQP-2 expects in markdown guidance.
The file points exclusively to Chinese-language official documentation via a /zh/ URL and does not offer any language choice or note that the content is region/language-specific. This creates a natural-language locale constraint that may not suit all users.
Natural-language policy requires avoiding forced language or locale unless users are given a choice or the constraint is clearly justified. This template presents all operational guidance solely in Chinese and does not indicate that the language is optional or region-specific by design.
This markdown file contains user-facing natural language entirely in Chinese, with no indication that users may choose another language or that the locale restriction is intentional. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.
This shell script immediately creates a plugin directory and writes several files into it, later also marking generated scripts as executable. While the script prints what it is generating, it does not clearly warn up front that running it will modify the filesystem and create executable helper scripts in the chosen location.
No suspicious patterns detected.