T09 · Insecure Skill Coding Practices
- Location
SKILL.md:225- Finding
Unauthenticated Network-Facing Processing API
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This podcast chaptering skill is purpose-aligned, but its API examples can expose transcript processing and filesystem actions without enough access controls.
Review before installing or using in production. Do not expose the sample API publicly as written; require authentication, bind locally by default, restrict batch jobs to a dedicated workspace, add upload and rate limits, and pin dependencies. Treat transcripts as potentially sensitive because AI mode sends transcript text to an external model provider unless you use a local model path.
SKILL.md:225Unauthenticated Network-Facing Processing API
SKILL.md:261Caller-Controlled Filesystem Paths in Batch Processing Endpoint
SKILL.md:225Unbounded File Upload Buffering and JSON Processing
SKILL.md:285Unpinned Third-Party Dependency Installation
L011 使用“Use when 需要API集成、接口对接、Webhook配置、系统连接时使用”等宽泛条件来描述何时调用该技能,覆盖面过大,且没有给出明确触发词、边界或反例。这类表述容易与大量常见开发/集成场景重叠,导致技能被意外调用。
The description lists '自动发布集成:支持主流播客平台', which presents auto-publishing/platform integration as a core capability. Later, the documentation explicitly states '默认仅生成内容不自动发布', indicating the skill does not actually perform publishing by default and only supports integration into a workflow. This is an intent-level contradiction in the documentation.
The skill describes uploading transcript files and sending transcript content to an external LLM API, but it does not clearly warn that user data may leave the local environment and be processed by a third party. In a podcast workflow, transcripts may contain unreleased content, personal data, or confidential business information, so silent external transmission creates a meaningful privacy and compliance risk.
L011 明确写有“支持中文交互,无需复杂配置即开即用”,并在其他位置持续以中文作为默认交互表述,但没有说明用户可选择其他交互语言。虽然文档也提到支持多语言处理,交互语言层面的默认中文仍可能被理解为强制语言策略。
At L291 the documentation says the AI chaptering feature requires 'OPENAI_API_KEY', matching the OpenAI client usage shown earlier. But the setup example at L300 exports 'API_KEY' instead, which contradicts the stated runtime requirement and would not satisfy the documented code path as written.
No suspicious patterns detected.