T09 · Insecure Skill Coding Practices
- Location
scripts/call_starops_agent.py:371- Finding
Unvalidated Endpoint Override Can Redirect Signed STAROps Requests
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent STAROps diagnostic client, but it needs Review because a configurable endpoint can redirect signed Alibaba Cloud requests and incident context to an arbitrary host.
Install only in trusted projects and review any .starops/config.json before running. Prefer the default Alibaba Cloud STAROps endpoint, avoid setting STAROPS_AGENT_ENDPOINT unless you fully trust the destination, use least-privilege RAM credentials limited to CreateThread/CreateChat, and do not include secrets or regulated incident data in questions unless your organization has approved STAROps for that data.
scripts/call_starops_agent.py:371Unvalidated Endpoint Override Can Redirect Signed STAROps Requests
scripts/requirements.txt:1Dependency Installation Does Not Enforce Package Integrity Hashes
The skill instructs the agent to extract and reuse thread IDs and to surface a STAROPS_URL tied to an investigation thread. Those identifiers can preserve and expose prior diagnostic context, potentially allowing sensitive incident data, service topology, or prior conversation contents to be linked across turns or disclosed to unintended recipients if thread values are logged, echoed, or reused in the wrong context.
**Thread Management:**
- Extract thread ID from output
- Use the printed `STAROPS_URL` when the user needs to inspect the same thread in the STAROps console
- Always pass `--thread "<id>"` for related follow-up questions to preserve context
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
, "text", "value", "answer"):
value = message.get(field)
if isinstance(value, str) and value.strip():
parts.append(value.strip())
items = message.get("items")
if isinstance(items, list):
parts.extend(extract_text_parts(items))
contents = message.get("contents")
if isinstance(contents, list):
parts.extend(extract_text_parts(contents))
tools = message.get("tools")
if isinstance(tools, list):
parts.extend(extract_text_tool_parts(tools))
return "\n".join(dedupe_preserve_order(parts)).strip()
def extract_tool_records(message: Mapping[str, Any]) -> list[ToolRecord]:
raw_tools: list[Any] = []
tools = message.get("tools")
if isinstance(tools, list):
raw_tools.extend(tools)
items = message.get("items")
if isinstance(items, list):
for item in items:
if isinstance(item, dict) and isinstance(item.get("tools"), list):
raw_tools.extend(item["tools"])
The skill performs sensitive operations involving environment variables, local config file reads, and outbound network access, but it declares no explicit tool scope or permission boundaries. This increases the chance that an invoking agent will grant broader-than-necessary capabilities, making credential exposure or unintended external data transmission harder to govern and audit.
The skill metadata lists usage and triggers using Chinese phrases only, which can impose a language/locale expectation on users without stating that Chinese is required or offering an alternative language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
mkdir -p .starops
cat > .starops/config.json <<'JSON'
{
"employeeId": "<your-digital-employee-id>",
The documentation explicitly states that user questions and workspace/project variables are sent to a remote Alibaba Cloud STAROps endpoint, but it does not mention this external transmission as a user-facing privacy or data-sharing warning. In a diagnostic skill, prompts, incident details, service names, and workspace metadata may contain sensitive operational or business information, so silent forwarding to a third-party service creates a real data exposure risk.
The script transmits the user's question and workspace/project context to a remote Alibaba Cloud STAROps endpoint, but the CLI flow does not present an explicit warning or confirmation that potentially sensitive incident, service, or topology data will leave the local environment. In an AIOps diagnostic skill, prompts often contain internal infrastructure details, making accidental data disclosure more likely and more sensitive than in a generic chatbot context.
The dependency pin requests==2.32.4 matches a version identified by the scanner as affected by a known vulnerability fixed in requests 2.33.0. Even though the issue is in a utility path (extract_zipped_paths()), including a vulnerable library in an incident-diagnosis skill is still risky because agent code may process remote resources or archives indirectly through supporting code paths, and future code changes could expose the vulnerable function.
Dynamic getattr() with a non-literal attribute name can access arbitrary object attributes, potentially bypassing access controls.
def call_or_none(obj: Any, method_name: str) -> Any:
method = getattr(obj, method_name, None)
if method is None:
return None
return method()
No suspicious patterns detected.