T09 · Insecure Skill Coding Practices
- Location
references/networking.md:96- Finding
Sensitive API Data Logged Without Redaction
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Flutter guide is not malicious, but several copy-paste examples could expose sensitive app data or request broad permissions without enough safety guidance.
Review this skill before installing if your agents will generate production Flutter networking or mobile-permission code from it. Treat the networking snippets as patterns needing hardening: redact logs, disable body logging in production, allowlist cacheable endpoints, encrypt or avoid sensitive caches, clear user-specific caches on logout, and request mobile permissions only for features that truly need them.
references/networking.md:96Sensitive API Data Logged Without Redaction
references/networking.md:410Authenticated GET Responses Persisted in Unencrypted Hive Cache
Referenced artifact was not completely inspected
| iOS/Android/Web specific implementations | [Platform Integration](references/platform-specific.md) |
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
<!-- ios/Runner/Info.plist -->
<key>NSCameraUsageDescription</key>
<string>This app needs camera access to take photos</string>
The auto-save example transmits form data to the server after a debounce interval without any explicit user confirmation or warning that data will be sent automatically. In a development guide, this can normalize implementation of background transmission for potentially sensitive draft content, increasing privacy and compliance risk if developers copy the pattern into real forms handling personal or confidential data.
This markdown file includes code that explicitly sets locale: const Locale('en'), which forces a specific language without user opt-in. The policy allows locale constraints only when documented and justified or when users are offered a choice, neither of which applies to this example snippet.
The example returns const Locale('en') as the fallback locale, which imposes a specific language choice in natural-language behavior. Although the file later shows a language selector, this snippet still demonstrates forced English as the default rather than respecting system locale or requiring explicit user choice.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
ApiClient._internal() {
dio = Dio(BaseOptions(
baseUrl: 'https://api.example.com/v1',
connectTimeout: const Duration(seconds: 10),
receiveTimeout: const Duration(seconds: 30),
sendTimeout: const Duration(seconds: 30),
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
ApiClient._internal() {
dio = Dio(BaseOptions(
baseUrl: 'https://api.example.com/v1',
connectTimeout: const Duration(seconds: 10),
receiveTimeout: const Duration(seconds: 30),
sendTimeout: const Duration(seconds: 30),
The disk cache example persists arbitrary GET response bodies to Hive without any filtering, classification, encryption, or retention warning. In a Flutter app, API responses often contain user profile data, tokens, or other sensitive information, so this pattern can lead to unintended local data retention and exposure on shared, rooted, backed-up, or compromised devices.
The guide includes broad iOS and Android permission examples for camera, photo library, microphone, location, storage, and internet even though the demonstrated code only shows simple platform detection, haptics, and basic device info retrieval. In a developer skill, copy-pastable permission blocks can lead consumers to over-request dangerous permissions, increasing privacy exposure, review risk, and attack surface beyond what the feature set actually requires.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
<!-- ios/Runner/Info.plist -->
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
<!-- ios/Runner/Info.plist -->
The documentation demonstrates collecting device-identifying information such as device model, device name, manufacturer, and OS version without any privacy warning, minimization guidance, or explanation of acceptable use. While not directly exfiltrating data, this normalizes collecting fingerprinting-relevant attributes and may encourage downstream apps to gather personal or device-identifying data without consent or disclosure.
Detected: suspicious.exposed_secret_literal