T09 · Insecure Skill Coding Practices
- Location
scripts/main.py:7- Finding
Operational Data Transmitted Over Plaintext HTTP
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill performs the stated PCS-to-EBP data transfer, but it automatically moves internal operational data with weak controls and plaintext HTTP.
Review before installing. Only run this in the intended internal environment, with authorization for both PCS export and EBP import. Prefer HTTPS endpoints, narrow the activation trigger, add explicit approval before upload, verify the destination, and delete or protect the generated Excel file after use. Avoid enabling the cron example until logging, validation, and rollback procedures are in place.
scripts/main.py:7Operational Data Transmitted Over Plaintext HTTP
SKILL.md:34Third-Party Dependencies Installed Without Version or Integrity Pinning
The script automatically uploads the generated Excel file to another application without any confirmation, validation of destination, or user-visible notice that scraped data will be transmitted. In this skill context, the whole purpose is cross-system data transfer from PCS to EBP/EPBP, so unintended transmission of sensitive operational data is a realistic risk if the wrong environment, session, or dataset is used.
The trigger list is very broad and generic for an automation skill that performs data extraction, Excel file creation, and upload into another system. Broad activation terms like 'pcs', 'epbp', and 'RPA' increase the chance of accidental invocation in unrelated conversations, which could cause unintended automation against internal systems.
The skill description explains how to run a workflow that scrapes data from an internal page, writes it to a local Excel file, and uploads it into another system, but it does not clearly warn users that these side effects occur automatically. Without prominent notice and confirmation requirements, users may trigger data movement and file creation without understanding that internal operational data is being exported and transferred between systems.
The script's user-facing prints, comments, and UI text assumptions are entirely in Chinese, and there is no indication that users may choose another language or that the skill is intentionally restricted to a Chinese-only environment. This can violate language or locale policy when a specific language is imposed without opt-in or justification.
The script persists data scraped from the PCS page into a local Excel file without any consent prompt, retention notice, or cleanup step. If the table contains sensitive business data, this creates an avoidable data-at-rest exposure on the automation host and may leave residual files accessible to other users, processes, backups, or malware.
No suspicious patterns detected.