T09 · Insecure Skill Coding Practices
- Location
SKILL.md:59- Finding
Potential disclosure of user conversations and private knowledge-base content to an unverified endpoint
- Content
View full analysis
`[Document ${i+1}] ${doc.content}`) .join('\n\n'); const systemPrompt = `You are an enterprise knowledge assistant. Reference documents: ${context}`; const messages = [ { role: 'system', content: systemPrompt }, { role: 'user', content: question } ]; body: JSON.stringify({ model: 'doubao-pro', messages }) ``` The production configuration example defines the same placeholder destination: ```yaml doubao: session_id: ${DOUBAO_SESSIONID} base_url: https://api.example.com/v1 ``` ### Technical Analysis Sending prompts to an external model is necessary for the declared LLM integration functionality. However, the provided implementation sends complete user messages—and, in the RAG workflow, private enterprise document excerpts—to `api.example.com`. This is a placeholder domain and is not identified or validated as an official Doubao API endpoint. The instructions do not demonstrate: - An allowlist of approved API hostnames. - Rejection of placeholder or untrusted production endpoints. - Explicit user disclosure and consent before transmitting private content. - Secret and personally identifiable information redaction. - Context minimization before transmission. - A policy limiting which knowledge-base documents may leave the local environment. ...[truncated 1867 chars]- Remediation
View remediation
