T09 · Insecure Skill Coding Practices
- Location
references/C9-qualification.md:67- Finding
Raw Cloud Access Credentials Accepted as Skill Inputs
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This documentation-only skill is not malicious, but it designs sensitive platform operations that need human review and stronger safeguards before use.
Install only if you are deliberately working on a C2C local-services platform and can enforce safeguards outside the skill. Do not paste raw cloud keys, ID images, bank data, or live production user data into chat. Treat account freezes, bans, credit changes, marketing outreach, and sensitive profiling as draft recommendations unless a human-approved, audited, legally reviewed workflow controls execution.
references/C9-qualification.md:67Raw Cloud Access Credentials Accepted as Skill Inputs
references/C4-analytics.md:974High-Risk Alerts Automatically Freeze User Accounts Before Human Review
The skill prescribes automatic restrictive enforcement such as freezing related accounts for 72 hours based on risk monitoring outcomes, without documented due process, confidence thresholds, appeal paths, false-positive safeguards, or prior notice. In a payments/wallet-like platform context, automated account freezes can directly block access to user funds and services, creating substantial abuse, fairness, and compliance risk.
The trigger list includes highly generic terms such as "platform," "marketplace," and "local service," which can cause the skill to activate in contexts far outside its intended C2C local-services scope. Over-broad activation increases the chance the agent loads this skill unnecessarily, polluting routing decisions and potentially applying inappropriate domain instructions to unrelated tasks.
The skill content is entirely presented in Chinese and does not indicate that users may choose another language or locale. Under the language/locale policy, forcing a specific language without opt-in can be a natural-language policy violation unless the locale restriction is explicitly documented and justified.
This section explicitly describes collecting and analyzing highly sensitive user data, including IM communication records, inferred income, behavioral history, and profiling of referral-network participants, but it provides no privacy notice, purpose limitation, consent model, minimization rules, or retention controls. In the context of a C2C local-services platform that also references payments, credit scoring, referrals, and compliance risk, such profiling can enable invasive surveillance, unlawful secondary use, and significant privacy/regulatory exposure if implemented as written.
This markdown file presents all operational instructions and outputs exclusively in Chinese, which can amount to a language/locale policy violation when no user opt-in or locale justification is provided. The document does not indicate that the skill is region-specific or that users may choose another language.
The file title and all operational descriptions are written entirely in Chinese, indicating the skill is effectively constrained to a specific language/locale. The document does not mention that the language is optional, user-selected, or limited to a justified region-specific deployment.
The skill specifies user recall and targeted outreach tactics such as Push and SMS based on user segmentation and loss-state analysis, but provides no requirement to verify consent, lawful basis, frequency limits beyond business goals, or compliant handling of personal data. In a growth-operations skill for a C2C platform, this omission can directly enable privacy-invasive targeting and unauthorized marketing contact at scale.
This section describes behavioral profiling, activity-based grouping, interest labels, balance distribution, and personalized push messaging without any warning that such data is sensitive or that its use may require consent and careful governance. Because the skill is designed for automated growth operations, it increases the risk of covert profiling, over-targeting, and misuse of user behavioral data.
The lifecycle modeling task processes user event streams, transaction records, point-balance history, and recency data to classify users into lifecycle stages and emit segmentation tags, but does not mention notice, consent, fairness review, or limits on downstream use. This is dangerous because it operationalizes profiling that can affect how users are targeted, rewarded, or deprioritized without transparency or controls.
The dormant-user reactivation workflow proposes multi-channel outreach through Push, SMS, and in-app messaging tied to inactivity duration, balance status, and historical response patterns, yet omits consent validation and contact-risk controls. In the context of a user-growth engine, this can facilitate repeated unsolicited contact and privacy-invasive re-engagement campaigns.
The document defines broad collection and analysis of highly sensitive data categories including financial flows, search logs, IM records, device fingerprints, IP addresses, GPS location, user/provider profiling, and fraud graphs, but provides no privacy constraints, data minimization rules, consent requirements, retention limits, or access controls. In the context of a platform skill that could be operationalized directly, this omission can normalize over-collection and unsafe downstream handling of regulated personal and financial data.
This markdown file presents all operational instructions and outputs exclusively in Chinese, and nowhere indicates that the user may choose another language or that the skill is limited to a Chinese-only regulatory context. Under the language/locale policy rule, forcing a specific language without user opt-in is a natural-language policy concern.
This unit explicitly requests highly sensitive identity documents and infrastructure details, including business license scans, legal representative ID cards, responsible person identity verification photos, and server access information, but provides no warning or handling constraints for secrets and personal data. In an agent skill context, this can normalize pasting raw PII and operational data into prompts, increasing the risk of privacy violations, unauthorized retention, or downstream disclosure.
This unit asks for cloud AccessKey/SecretKey material for SMS integration without any warning that these are secrets requiring protected handling. In a skill or LLM workflow, soliciting live API credentials in prompt inputs creates a direct risk of credential leakage, account compromise, abuse of SMS services, billing fraud, and lateral access depending on key scope.
This markdown skill file presents all instructions, unit names, and pipeline descriptions exclusively in Chinese, and it does not indicate that the user can choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified.
All natural-language instructions and outputs in this skill file are presented in Chinese, and the file does not indicate that the language is optional, user-selectable, or limited to a specific regional deployment. Under the policy, forcing a specific language without user opt-in can be a language or locale policy violation.
This markdown skill file presents all operational instructions and outputs exclusively in Chinese, and there is no indication that users may choose another language or that the skill is intentionally restricted to a Chinese-speaking or region-specific context. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.
No suspicious patterns detected.