T09 · Insecure Skill Coding Practices
- Location
INTEGRATION.md:44- Finding
Unredacted User Prompts May Be Persisted in Plaintext Logs
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly matches an AI decision-helper purpose, but it includes under-scoped prompt logging guidance, broad activation, release automation that can alter Git state, and overstated safety/model claims.
Review before installing or integrating. Do not run the release script in a real repository unless you intend to initialize, stage, commit, and tag the whole directory. If you use the integration guide, remove or redact raw prompt logging, and treat debate results as heuristic unless real model calls and resource limits are implemented.
INTEGRATION.md:44Unredacted User Prompts May Be Persisted in Plaintext Logs
orchestrator_v4.py:62Memory Limit Is Not Correctly Measured or Enforced
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
if score < 0.7:
# 追问
return prompt
else:
# 执行
execute_task(user_input)
If the skill’s true behavior includes Git initialization, staging, commits, identity changes, or release-tag workflows while the description only presents a lightweight reasoning framework, users and host agents may authorize it under false assumptions. That mismatch is dangerous because repository-modifying actions can alter local state, capture unrelated files into commits, and trigger downstream release or deployment processes unexpectedly.
If the skill’s true behavior includes Git initialization, staging, commits, identity changes, or release-tag workflows while the description only presents a lightweight reasoning framework, users and host agents may authorize it under false assumptions. That mismatch is dangerous because repository-modifying actions can alter local state, capture unrelated files into commits, and trigger downstream release or deployment processes unexpectedly.
The example logging block records raw user_input directly along with model and token metadata, with no minimization, redaction, consent, or retention guidance. In an agent framework, user input may contain credentials, personal data, proprietary prompts, or regulated information, so this creates a realistic privacy and data-exposure risk if logs are accessed, exported, or reused.
The skill advertises executable/code-like usage but does not declare any explicit tool scope or permissions boundary, which creates ambiguity about what file access is expected or allowed. In agent environments, undeclared capabilities can lead to over-privileged execution, accidental file disclosure, or reviewers/users misunderstanding the skill’s operational reach.
The natural-language instructions and examples are entirely in Chinese, including the trigger phrases users are expected to say, with no indication that other languages are supported or that Chinese is a required, justified locale. This can violate language/locale policy when the skill effectively constrains interaction language without user opt-in.
The trigger phrases are broad everyday expressions like evaluation and comparison requests, making accidental activation likely in unrelated conversations. Over-broad triggering can cause the skill to seize control outside its intended scope, inject unsolicited workflow logic, or interfere with safer/default agent behavior in contexts where users did not intend to invoke it.
This Python file contains natural-language strings such as problem labels and output text in Chinese, and there is no indication that the skill is intentionally region-specific or that users can opt into another language. That creates a language/locale policy concern because the skill effectively forces a specific language in its interface and example usage.
This code's natural-language examples, prompts, and displayed labels are all in Chinese, and there is no indication that users may choose another language or that the skill is intentionally region-specific. That creates a language/locale policy concern because the skill appears to impose a specific language by default.
This code includes user-facing natural-language content in Chinese, including the debate prompt and processing options, and the rest of the CLI output is also Chinese. Under the policy, forcing a specific language without user opt-in or documented justification is a natural-language policy concern.
The script initializes a Git repository, stages all files with 'git add .', and creates a commit in the current directory without any confirmation, safety check, or warning about modifying repository state. In an agent or automation context, this can unintentionally capture sensitive files, alter an existing workspace, or create commits/tags in the wrong directory, which makes it a real operational security risk even though it is not overtly malicious.
This code file contains user-facing natural-language content in Chinese in the module docstring, class/method docstrings, and prompt template, but does not indicate that the skill is Chinese-only or provide any language/locale opt-in. Under the policy, forcing a specific language without user choice is a natural-language policy violation.
The class docstring asserts asynchronous three-model execution with timeout and memory protections, but the implementation never enforces those controls and only performs local heuristic scoring. This is dangerous because downstream agents or operators may trust the component as providing bounded, model-backed evaluation when it actually provides fabricated results without the stated safety guarantees, enabling unsafe decision-making and control bypass by assumption.
_call_model_async is documented as an asynchronous model invocation returning a model-generated score and rationale, but it instead fabricates both from deterministic heuristics. In an agent skill, this creates integrity risk: other components may treat outputs as independent model judgments, causing false confidence, auditability failures, and potentially harmful automated recommendations based on nonexistent analysis.
This JSON log contains multiple natural-language fields entirely in Chinese, including user input and descriptive metadata, without any indication that language choice is optional or region-specific. Under the policy, forcing or assuming a specific language without documented opt-in can be a natural-language policy violation.
This Python file contains core documentation and runtime output entirely in Chinese, including the main result string returned to users. Under the policy, forcing a specific language without opt-in is a natural-language locale violation unless the skill is clearly documented as region-specific or offers a language choice, which this file does not.
The orchestrator returns natural-language prompts and success output in Chinese, such as the clarity response path and the final execution message. Because there is no visible user opt-in, negotiation, or configuration for language, this behavior can force a specific locale on users in violation of the stated policy.
This code returns a hard-coded Chinese follow-up prompt to the user, regardless of the user's language preference or input language. The file also presents its user-facing descriptions and outputs only in Chinese, with no opt-in or documented region-specific justification, which is a natural-language locale policy concern.
The module docstring presents usage, trigger phrases, and interaction examples entirely in Chinese, and the activation model relies on Chinese phrases only. This imposes a specific language/locale expectation without indicating that users may choose another language or that the skill is intentionally region-specific.
The manifest describes a stripped-down framework centered on Socratic clarification and multi-model debate. In this file, however, the gateway embeds CNC/manufacturing-specific trigger logic and later returns a recommendation about being ready to execute a quotation flow, which is narrower and more operational than a generic minimal framework description suggests.
When clarity is sufficient, the gateway returns the recommendation "需求已锚定,准备执行报价", indicating the skill is preparing to execute a pricing/quotation task. The manifest only mentions preserving Socratic clarification and multi-model debate methodology, not a quotation-execution-oriented business workflow.
This CONTRIBUTING guide is primarily written in English, but the closing slogan and note switch to Chinese without any opt-in, translation, or justification. That creates a language/locale policy inconsistency for contributors who may not understand the closing instructions or attribution text.
The example input is presented only in Chinese ("帮我加工10个TC4零件"), which can impose a specific language expectation on users without opt-in. Under the policy, locale or language constraints should either be optional for the user or clearly justified as region-specific.
The author description includes Chinese-only text ("靠得住、能干事、在状态"), and the document also mixes languages without indicating whether users may choose their preferred language. This can conflict with language-choice policy when a specific language is presented without opt-in or a documented reason.
The closing notice is written in Chinese (with partial English transliteration) and does not explain whether the skill is intended for a Chinese-speaking audience or whether other languages are supported. This may be a language-policy issue because it introduces a locale-specific message without opt-in or justification.
No suspicious patterns detected.