T09 · Insecure Skill Coding Practices
- Location
scripts/index.js:43- Finding
API Key May Be Transmitted over Unencrypted HTTP
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill appears intended to list Appian packages, but its credential and configuration handling is broader and less accurately disclosed than users should accept without review.
Review before installing. Use only with trusted APPIAN_BASE_URL values, prefer injected environment secrets, avoid relying on appian.json fallback files, and do not run it from directories where an untrusted parent appian.json could be discovered.
scripts/index.js:43API Key May Be Transmitted over Unencrypted HTTP
scripts/index.js:17Fallback Credential Loader Searches Undocumented Parent Directories
The skill uses sensitive environment variables and makes outbound network requests, but it does not declare an explicit tool scope such as permissions or allowed-tools. This weakens containment and reviewability because the runtime capabilities required by the skill are broader than what is formally documented or enforced, increasing the chance of unintended credential exposure or unauthorized external access if the skill is modified or reused.
The security manifest declares file operations as 'none', but the implementation reads appian.json from the current or parent directories and imports those values into process.env. A false security manifest can mislead reviewers, policy engines, or sandbox decisions, causing the skill to be treated as less sensitive than it is while it actually accesses local files and potentially secrets.
The code comments claim there is no file I/O, but credential validation walks parent directories and reads a local appian.json file if present. This mismatch is security-relevant because operators and downstream tooling may trust the documentation and grant the skill access or approvals under false assumptions, while the actual behavior expands the attack surface to local configuration discovery and secret ingestion.
Detected: suspicious.env_credential_access