T09 · Insecure Skill Coding Practices
- Location
scripts/iot_controller.py:21- Finding
Bearer Token Transmission to an Unrestricted and Potentially Unencrypted Endpoint
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill openly aims to control a Linux desktop and connected devices very broadly, but its safeguards are not reliably implemented or scoped.
Review before installing. Only use this skill in a contained environment where broad desktop, device, network, and IoT control is acceptable. Do not pass real tokens or Wi-Fi passwords on command lines, avoid using it for camera/audio/serial/IoT/power actions unless you can supervise them, and prefer a narrower skill with enforced confirmations for destructive operations.
scripts/iot_controller.py:21Bearer Token Transmission to an Unrestricted and Potentially Unencrypted Endpoint
scripts/iot_controller.py:5Arbitrary HTTP Requests Enable Server-Side Request Forgery and Internal Service Access
scripts/iot_controller.py:47API Tokens and Wi-Fi Passwords Are Accepted Through Process Arguments
scripts/process_manager.py:27Process Termination Bypasses Documented Confirmation and Query-First Safeguards
scripts/serial_comm.py:23Serial Device Commands Are Transmitted Without Device Approval or Confirmation
scripts/camera_controller.py:40User-Controlled Output Paths Permit Arbitrary Writable-File Replacement
{stdout}scripts/common.py:87Shell Execution Helper Uses an Incomplete Denylist with shell=True
scripts/hardware_controller.py:51Power and Network Reconfiguration Commands Lack Implemented Confirmation Gates
SKILL.md:8Dependencies Are Installed Without Reproducible Version and Integrity Controls
The description claims all-powerful control across Linux desktop software, hardware, and peripherals for any task, while the cited implementation evidence is far narrower. In context, that mismatch is dangerous because the skill already discusses screenshotting, camera, microphone, network, and command execution—areas where over-trust can directly become privacy or integrity harm.
The description claims all-powerful control across Linux desktop software, hardware, and peripherals for any task, while the cited implementation evidence is far narrower. In context, that mismatch is dangerous because the skill already discusses screenshotting, camera, microphone, network, and command execution—areas where over-trust can directly become privacy or integrity harm.
The description claims all-powerful control across Linux desktop software, hardware, and peripherals for any task, while the cited implementation evidence is far narrower. In context, that mismatch is dangerous because the skill already discusses screenshotting, camera, microphone, network, and command execution—areas where over-trust can directly become privacy or integrity harm.
The description claims all-powerful control across Linux desktop software, hardware, and peripherals for any task, while the cited implementation evidence is far narrower. In context, that mismatch is dangerous because the skill already discusses screenshotting, camera, microphone, network, and command execution—areas where over-trust can directly become privacy or integrity harm.
The description claims all-powerful control across Linux desktop software, hardware, and peripherals for any task, while the cited implementation evidence is far narrower. In context, that mismatch is dangerous because the skill already discusses screenshotting, camera, microphone, network, and command execution—areas where over-trust can directly become privacy or integrity harm.
The description claims all-powerful control across Linux desktop software, hardware, and peripherals for any task, while the cited implementation evidence is far narrower. In context, that mismatch is dangerous because the skill already discusses screenshotting, camera, microphone, network, and command execution—areas where over-trust can directly become privacy or integrity harm.
The description claims all-powerful control across Linux desktop software, hardware, and peripherals for any task, while the cited implementation evidence is far narrower. In context, that mismatch is dangerous because the skill already discusses screenshotting, camera, microphone, network, and command execution—areas where over-trust can directly become privacy or integrity harm.
The description claims all-powerful control across Linux desktop software, hardware, and peripherals for any task, while the cited implementation evidence is far narrower. In context, that mismatch is dangerous because the skill already discusses screenshotting, camera, microphone, network, and command execution—areas where over-trust can directly become privacy or integrity harm.
The description claims all-powerful control across Linux desktop software, hardware, and peripherals for any task, while the cited implementation evidence is far narrower. In context, that mismatch is dangerous because the skill already discusses screenshotting, camera, microphone, network, and command execution—areas where over-trust can directly become privacy or integrity harm.
The description claims all-powerful control across Linux desktop software, hardware, and peripherals for any task, while the cited implementation evidence is far narrower. In context, that mismatch is dangerous because the skill already discusses screenshotting, camera, microphone, network, and command execution—areas where over-trust can directly become privacy or integrity harm.
The description claims all-powerful control across Linux desktop software, hardware, and peripherals for any task, while the cited implementation evidence is far narrower. In context, that mismatch is dangerous because the skill already discusses screenshotting, camera, microphone, network, and command execution—areas where over-trust can directly become privacy or integrity harm.
The description claims all-powerful control across Linux desktop software, hardware, and peripherals for any task, while the cited implementation evidence is far narrower. In context, that mismatch is dangerous because the skill already discusses screenshotting, camera, microphone, network, and command execution—areas where over-trust can directly become privacy or integrity harm.
The description claims all-powerful control across Linux desktop software, hardware, and peripherals for any task, while the cited implementation evidence is far narrower. In context, that mismatch is dangerous because the skill already discusses screenshotting, camera, microphone, network, and command execution—areas where over-trust can directly become privacy or integrity harm.
The description claims all-powerful control across Linux desktop software, hardware, and peripherals for any task, while the cited implementation evidence is far narrower. In context, that mismatch is dangerous because the skill already discusses screenshotting, camera, microphone, network, and command execution—areas where over-trust can directly become privacy or integrity harm.
The description claims all-powerful control across Linux desktop software, hardware, and peripherals for any task, while the cited implementation evidence is far narrower. In context, that mismatch is dangerous because the skill already discusses screenshotting, camera, microphone, network, and command execution—areas where over-trust can directly become privacy or integrity harm.
The description claims all-powerful control across Linux desktop software, hardware, and peripherals for any task, while the cited implementation evidence is far narrower. In context, that mismatch is dangerous because the skill already discusses screenshotting, camera, microphone, network, and command execution—areas where over-trust can directly become privacy or integrity harm.
The description claims all-powerful control across Linux desktop software, hardware, and peripherals for any task, while the cited implementation evidence is far narrower. In context, that mismatch is dangerous because the skill already discusses screenshotting, camera, microphone, network, and command execution—areas where over-trust can directly become privacy or integrity harm.
The description claims all-powerful control across Linux desktop software, hardware, and peripherals for any task, while the cited implementation evidence is far narrower. In context, that mismatch is dangerous because the skill already discusses screenshotting, camera, microphone, network, and command execution—areas where over-trust can directly become privacy or integrity harm.
The description claims all-powerful control across Linux desktop software, hardware, and peripherals for any task, while the cited implementation evidence is far narrower. In context, that mismatch is dangerous because the skill already discusses screenshotting, camera, microphone, network, and command execution—areas where over-trust can directly become privacy or integrity harm.
The skill prominently advertises powerful system-control and device-access features but does not place clear privacy and system-impact warnings up front. Because it covers hardware, GUI, network, storage, Bluetooth, IoT, and other sensitive domains, users may not appreciate that loading or invoking the skill can expose secrets, alter system state, or affect connected devices.
The phrase indicating the skill applies to any task 'without exception' creates an activation scope broad enough to match essentially all user requests. For a skill that advertises command execution, orchestration, system control, and access to devices, this dramatically increases the chance of accidental or unsafe invocation in sensitive contexts.
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
| 级别 | 示例 | 处理方式 |
|------|------|----------|
| 🔴 高危 | `rm -rf /`、`format C:` | **必须用户确认** |
| 🟡 中危 | `pip uninstall`、`sudo` | 警告提示 |
| 🟢 低危 | `ls`、`cat`、`python script.py` | 直接执行 |
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
| 级别 | 示例 | 处理方式 |
|------|------|----------|
| 🔴 高危 | `rm -rf /`、`format C:` | **必须用户确认** |
| 🟡 中危 | `pip uninstall`、`sudo` | 警告提示 |
| 🟢 低危 | `ls`、`cat`、`python script.py` | 直接执行 |
Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.
Returns:
Tuple of (stdout: str, stderr: str, returncode: int)
"""
env = os.environ.copy()
env["PYTHONIOENCODING"] = "utf-8"
# Prepend encoding setup to ensure UTF-8 output
Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.
Returns:
Tuple of (stdout: str, stderr: str, returncode: int)
"""
env = os.environ.copy()
env["PYTHONIOENCODING"] = "utf-8"
# Prepend encoding setup to ensure UTF-8 output
No suspicious patterns detected.