T09 · Insecure Skill Coding Practices
- Location
SKILL.md:70- Finding
Hardcoded API Credential Transmitted over Plaintext HTTP
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is not clearly malicious, but it gives agents high-impact publishing and production-server powers using unsafe defaults that require human review.
Review before installing or using this skill. Do not rely on the built-in API key, do not send credentials over HTTP, and do not let an agent run the root SSH, deployment, PM2 startup, or delete commands without explicit human authorization and a least-privilege deployment design.
SKILL.md:70Hardcoded API Credential Transmitted over Plaintext HTTP
SKILL.md:113Mutable Remote Repository and Dependency Code Executed Without Integrity Pinning
SKILL.md:106Production Deployment and Maintenance Performed as Root
SKILL.md:151PM2 Startup Registration Creates Cross-Session Persistence
The skill directs the agent to transmit requests to an external host by default (http://118.145.101.171) and elsewhere includes authenticated write operations using a fallback API key. External transmission to a hard-coded remote service is risky in agent environments because it can leak operational data, trigger unintended network actions, and normalize contacting an untrusted endpoint without validation.
curl ${BASE_URL:-http://118.145.101.171}/api/articles
# 搜索文章
curl "${BASE_URL:-http://118.145.101.171}/api/articles?search=关键词"
# 按分类过滤
The documentation provides create, update, and delete API examples, including a destructive DELETE call, without any confirmation workflow, dry-run guidance, or warnings about irreversible changes. In an agent context, this increases the risk of accidental or unauthorized modification of published content if the agent operationalizes examples directly.
The skill includes direct production administration steps using ssh root@118.145.101.171, git pull, and PM2 lifecycle control. For a content-publication skill, embedding root-level server operations materially expands the agent's authority and could enable unauthorized infrastructure changes, persistence, or service disruption if followed automatically or with insufficient review.
The production deployment section instructs privileged access and service-management actions such as SSH as root, build/deploy, and PM2 start/delete, but gives no safety boundaries or approval requirements. This can cause service outage, unintended deployment, or unauthorized system changes if an agent treats the instructions as routine operational guidance.
The natural-language content of the skill is written exclusively in Chinese and does not offer an alternative language or indicate that the user can choose their preferred locale. This can violate a language/locale policy when a specific language is forced without opt-in.
No suspicious patterns detected.