T09 · Insecure Skill Coding Practices
- Location
SKILL.md:145- Finding
Mandatory Web Search May Disclose Sensitive Error Content
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 145
Vulnerability Type: Sensitive information exposure through external search
Risk Level: MediumComplete Code Snippet:
markdown | | | ② WebSearchで完全なエラーメッセージを検索 |Technical Analysis
The debugging escalation procedure requires the agent to search for the complete error message after three failed attempts. Error messages can contain credentials, access tokens, internal hostnames, private filesystem paths, database query values, customer information, source-code fragments, or other operational metadata.
A web search transmits its query outside the local execution environment. The instruction does not require the agent to inspect or redact the error before transmission, minimize the query to a nonsensitive fragment, or obtain authorization when sensitive information remains. Consequently, following the instruction literally can disclose confidential information to a search provider and any associated logging or analytics systems.
Attack Path
- An application produces an error containing a secret or other internal data.
- The agent makes three unsuccessful debugging attempts, activating the mandatory five-step audit.
- The agent follows line 145 and submits the complete error message through WebSearch.
- The search provider receives and may retain the sensitive query.
- Anyone with access to provider logs, browser history, proxy logs, or organizational search telemetry may obtain the disclosed information.
Impact Assessment
Exploitation does not grant additional local privileges or directly execute code. Its primary impact is confidentiality loss outside the project boundary. Depending on the error contents, exposure may affect credentials, internal infrastructure identifiers, proprietary implementation details, or user data. Leaked credentials could subsequently enable access with the privileges assigned to those credentials.
- Remediation
View remediation
Remediation Suggestions
Replace the requirement to search the complete error message with a privacy-preserving workflow:
- Inspect the error locally before using an external search service.
- Remove credentials, tokens, cookies, personal data, query values, internal hostnames, IP addresses, filesystem paths, and proprietary identifiers.
- Search only the shortest generic fragment needed to identify the error.
- Prefer official documentation and local source inspection before external search.
- Require explicit authorization if meaningful sensitive content cannot be removed.
- Document which redactions were applied without recording the original secret.
A hardened instruction would be: “Search a minimal, redacted, nonsensitive fragment of the error message; never submit the complete raw error to an external service.”
