T09 · Insecure Skill Coding Practices
- Location
SKILL.md:21- Finding
API Credentials and Sensitive Queries May Be Sent over Plaintext HTTP
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill matches its stated RAGret search purpose, but it needs review because it can send an API key and sensitive queries to an unvalidated or plaintext endpoint.
Install only if you trust the RAGret endpoint you will configure. Prefer HTTPS for any non-local service, confirm the base URL before first use, use a least-privilege API key, and avoid sending confidential queries to unknown or plaintext endpoints.
SKILL.md:21API Credentials and Sensitive Queries May Be Sent over Plaintext HTTP
The manifest description uses broad activation criteria such as generic search, retrieval, or knowledge-base intent, which could cause the skill to trigger for many user requests that were not clearly intended for this specific remote service. Because the skill directs the agent to contact a remote API and even suggests defaulting to a localhost endpoint when the base URL is unclear, overbroad activation increases the chance of unintended network access, data disclosure to an internal service, or workflow hijacking away from safer/local retrieval paths.
No suspicious patterns detected.