T09 · Insecure Skill Coding Practices
- Location
scripts/push_api_to_product_platform.py:22- Finding
API Definitions Transmitted over Unencrypted HTTP
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill matches its stated purpose, but it pushes potentially sensitive API documentation to a hardcoded external HTTP endpoint and documents optional automation that could send data during git workflows.
Review the destination before installing or using this skill. Do not send confidential, production, credential-bearing, or customer-sensitive API definitions through the documented HTTP endpoint; require HTTPS, explicit approval before each push, and a trusted authenticated destination. Avoid copying the pre-push hook unless your team deliberately wants automatic submissions during git operations.
scripts/push_api_to_product_platform.py:22API Definitions Transmitted over Unencrypted HTTP
The skill clearly performs network transmission and references local files/scripts, yet it declares no explicit tool scope or permissions boundary. In an agent environment, this can allow unintended file access and outbound requests without transparent user consent or platform-level restriction, increasing the risk of data exfiltration or misuse.
The skill documents an external HTTP endpoint and instructs users to send API definition content, but it does not prominently warn that potentially sensitive internal interface metadata will be transmitted off-system. This is more dangerous in context because backend Java API definitions often contain internal paths, parameters, schemas, and business logic details that may be confidential, and the endpoint uses plain HTTP rather than HTTPS.
The natural-language trigger '直接告诉我需求,我引导你完成推送' is broad enough that routine conversation about APIs or product requirements could activate a workflow that prepares or sends data externally. Overbroad invocation raises the chance of accidental execution, especially when the skill's core action is network transmission of potentially sensitive interface definitions.
The file title and all instructions are written exclusively in Chinese, and the document presents the standard as universally applicable without offering any language or locale choice. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is clearly justified.
The document directs users to POST internal API definition data to a remote endpoint over plain HTTP, which exposes potentially sensitive API metadata to interception and tampering in transit. Because the skill also frames this as a normal workflow without any warning, users may unknowingly exfiltrate internal architecture details outside the repository and organization boundary.
The pre-push hook automates outbound submission whenever matching files change, creating silent data transmission during a common developer workflow. This increases the likelihood of accidental disclosure of internal API specifications and can surprise users by coupling source-control actions to network exfiltration without clear consent or review.
The script transmits API definition content to a remote endpoint automatically, but in normal mode it does not clearly warn the user that potentially sensitive internal API metadata will be sent off-host. Because API definitions often contain internal paths, parameters, auth expectations, and business logic details, silent or non-obvious transmission increases the risk of unintended data disclosure, especially when users invoke the tool with only a file path or inline JSON.
This markdown file presents all user-facing instructions and labels exclusively in Chinese. Under the language/locale policy rule, forcing a specific language without offering user choice or documenting a justified locale constraint can be a policy violation.
All natural-language docstrings, CLI descriptions, help text, and runtime messages are presented only in Chinese. That creates a locale/language constraint without any opt-in or alternative, which matches the policy category for forced language usage.
No suspicious patterns detected.