T09 · Insecure Skill Coding Practices
- Location
cms_executor/engine/executor.py:220- Finding
Preview Mode Executes Live CMS Mutations While Claiming No Changes Are Made
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill bundles a much broader ERP/CMS/agent system than advertised and includes unsafe CMS execution paths that can make live changes or upload local files under weak controls.
Review before installing. Do not run this with real ERP, CMS, Amazon, or model API credentials until the scope is clarified and the preview, approval-timeout, upload-path, secret-export, and audit-logging issues are fixed. Use an isolated test environment and grant only narrowly scoped test credentials.
cms_executor/engine/executor.py:220Preview Mode Executes Live CMS Mutations While Claiming No Changes Are Made
cms_executor/agent_integration.py:278Read-Only Roles Can Upload Arbitrary Local Files to a Remote CMS
cms_executor/engine/executor.py:352Medium-Risk CMS Writes Are Automatically Approved After Human Approval Timeout
api_integration/api_config.py:166ERP API Keys Are Exported to Plaintext YAML Files
cms_executor/engine/audit.py:334Audit Log Flush Uses an Invalid File API and Silently Loses Durable Audit Records
The design materially exceeds the skill’s declared multi-CMS foreign-trade scope by adding GEO marketing, Amazon operations, customer service, memory, scheduling, and security infrastructure. This kind of scope expansion increases the attack surface and can cause the skill to access or act on data and systems users would not reasonably expect from the manifest.
Amazon-specific retail operations are presented as a first-class domain even though the skill metadata claims Shopify, WooCommerce, and Magento CMS orchestration. This mismatch can mislead operators about what data sources, APIs, and business actions the skill may touch, creating authorization and governance risk.
The plan explicitly includes scraping support and anti-bot evasion measures such as multi-IP pools and request spacing, despite the skill being ներկայացted as a CMS coordination system. Evasion-oriented collection capabilities increase legal/compliance risk and create a pathway for unauthorized data harvesting, abuse of third-party services, and concealment of collection activity.
The registry materially exceeds the skill’s declared purpose. Instead of a bounded Shopify/WooCommerce/Magento foreign-trade coordination skill, it defines a large GEO/Amazon operational cluster with broad orchestration, content, advertising, monitoring, memory, and reporting capabilities, creating capability drift and expanding what can be invoked far beyond user expectations. In an agent system, this increases attack surface, raises the chance of unauthorized task routing, and can enable misuse of unrelated business functions under an apparently narrower skill label.
The README describes an enterprise ERP-oriented multi-agent cluster, which materially conflicts with the manifest claiming an Amazon foreign-trade multi-CMS system for Shopify/WooCommerce/Magento. This kind of identity mismatch can mislead users about what the skill actually does, what systems it may connect to, and what data it may access, increasing the risk of unsafe installation or over-trust.
The documented integrations emphasize SAP, Yonyou, Kingdee, and REST ERP adapters rather than the declared CMS platforms. Users expecting storefront/CMS integrations could unknowingly enable access to back-office business systems, creating a serious transparency and trust problem around system boundaries and potential data exposure.
Listing only ERP integrations where the manifest promises Shopify/WooCommerce/Magento support is a substantive capability mismatch, not a minor docs inconsistency. In a security context, misleading integration claims can cause operators to grant credentials or approve deployment under false assumptions about reachable systems and operational impact.
The body’s ERP MCP-service orientation contradicts the front matter’s foreign-trade multi-CMS framing. That is dangerous because users could unknowingly expose ERP-connected tooling when they believe they are enabling a commerce-platform skill with approvals and safeguards.
The body’s ERP MCP-service orientation contradicts the front matter’s foreign-trade multi-CMS framing. That is dangerous because users could unknowingly expose ERP-connected tooling when they believe they are enabling a commerce-platform skill with approvals and safeguards.
The body’s ERP MCP-service orientation contradicts the front matter’s foreign-trade multi-CMS framing. That is dangerous because users could unknowingly expose ERP-connected tooling when they believe they are enabling a commerce-platform skill with approvals and safeguards.
The body’s ERP MCP-service orientation contradicts the front matter’s foreign-trade multi-CMS framing. That is dangerous because users could unknowingly expose ERP-connected tooling when they believe they are enabling a commerce-platform skill with approvals and safeguards.
The body’s ERP MCP-service orientation contradicts the front matter’s foreign-trade multi-CMS framing. That is dangerous because users could unknowingly expose ERP-connected tooling when they believe they are enabling a commerce-platform skill with approvals and safeguards.
The body’s ERP MCP-service orientation contradicts the front matter’s foreign-trade multi-CMS framing. That is dangerous because users could unknowingly expose ERP-connected tooling when they believe they are enabling a commerce-platform skill with approvals and safeguards.
The body’s ERP MCP-service orientation contradicts the front matter’s foreign-trade multi-CMS framing. That is dangerous because users could unknowingly expose ERP-connected tooling when they believe they are enabling a commerce-platform skill with approvals and safeguards.
The body’s ERP MCP-service orientation contradicts the front matter’s foreign-trade multi-CMS framing. That is dangerous because users could unknowingly expose ERP-connected tooling when they believe they are enabling a commerce-platform skill with approvals and safeguards.
The body’s ERP MCP-service orientation contradicts the front matter’s foreign-trade multi-CMS framing. That is dangerous because users could unknowingly expose ERP-connected tooling when they believe they are enabling a commerce-platform skill with approvals and safeguards.
The body’s ERP MCP-service orientation contradicts the front matter’s foreign-trade multi-CMS framing. That is dangerous because users could unknowingly expose ERP-connected tooling when they believe they are enabling a commerce-platform skill with approvals and safeguards.
The body’s ERP MCP-service orientation contradicts the front matter’s foreign-trade multi-CMS framing. That is dangerous because users could unknowingly expose ERP-connected tooling when they believe they are enabling a commerce-platform skill with approvals and safeguards.
The body’s ERP MCP-service orientation contradicts the front matter’s foreign-trade multi-CMS framing. That is dangerous because users could unknowingly expose ERP-connected tooling when they believe they are enabling a commerce-platform skill with approvals and safeguards.
The body’s ERP MCP-service orientation contradicts the front matter’s foreign-trade multi-CMS framing. That is dangerous because users could unknowingly expose ERP-connected tooling when they believe they are enabling a commerce-platform skill with approvals and safeguards.
The body’s ERP MCP-service orientation contradicts the front matter’s foreign-trade multi-CMS framing. That is dangerous because users could unknowingly expose ERP-connected tooling when they believe they are enabling a commerce-platform skill with approvals and safeguards.
The body’s ERP MCP-service orientation contradicts the front matter’s foreign-trade multi-CMS framing. That is dangerous because users could unknowingly expose ERP-connected tooling when they believe they are enabling a commerce-platform skill with approvals and safeguards.
The body’s ERP MCP-service orientation contradicts the front matter’s foreign-trade multi-CMS framing. That is dangerous because users could unknowingly expose ERP-connected tooling when they believe they are enabling a commerce-platform skill with approvals and safeguards.
The body’s ERP MCP-service orientation contradicts the front matter’s foreign-trade multi-CMS framing. That is dangerous because users could unknowingly expose ERP-connected tooling when they believe they are enabling a commerce-platform skill with approvals and safeguards.
The body’s ERP MCP-service orientation contradicts the front matter’s foreign-trade multi-CMS framing. That is dangerous because users could unknowingly expose ERP-connected tooling when they believe they are enabling a commerce-platform skill with approvals and safeguards.
Detected: suspicious.exposed_secret_literal, suspicious.insecure_tls_verification