T09 · Insecure Skill Coding Practices
- Location
templates/租房合同.md:6- Finding
Plaintext Sensitive Personal and Financial Data Embedded in a Distributed Template
- Content
View full analysis
Vulnerability Details
File Location:
templates/租房合同.md, lines 6, 8, 14, 30, and 110–114
Vulnerability Type: Plaintext exposure of sensitive identity, contact, residential, and financial data
Risk Level: MediumVulnerable Code Snippet
text Line 6: Landlord: Wang Jianguo; national ID number: 440106198501011234; telephone: 13800138000. Line 8: Tenant: Li Xiaohong; national ID number: 440105199203025678; telephone: 13900139000. Line 14: Property address: Room 101, No. 18 Huacheng Avenue, Zhujiang New Town, Tianhe District, Guangzhou. Line 30: Account holder: Wang Jianguo; bank account: 6222023602112345678. Line 110: National ID numbers: 440106198501011234 and 440105199203025678. Line 112: Telephone numbers: 13800138000 and 13900139000. Line 114: Signature dates: March 28, 2026.Technical Analysis
The rental agreement template is populated with realistic-looking names, national identification numbers, telephone numbers, a complete residential address, and a bank account number. These values are stored directly in plaintext and distributed as part of the Skill package.
Other project templates generally use placeholder fields, making the pre-populated values in this file unnecessary for functionality. The repository does not establish whether these values are genuine or synthetic. Nevertheless, distributing realistic sensitive values creates a privacy and data-handling risk because package recipients, source-code indexers, generated-document users, and automated processing systems can extract and reproduce them without access controls.
This is an insecure coding and content-management practice rather than a code-execution vulnerability. No authentication bypass, command execution, privilege escalation, persistence, or network exfiltration mechanism was identified.
Attack Path
- An attacker or unauthorized recipient obtains the Skill package or accesses a repository containing it.
- Th ...[truncated 1323 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace every pre-populated sensitive value with explicit placeholders, such as:
{{landlord_name}}{{tenant_name}}{{national_id}}{{telephone_number}}{{property_address}}{{account_holder}}{{bank_account_number}}{{signature_date}}
- Use conspicuously invalid examples only when examples are essential. Do not use values that match production identity, telephone, or bank-account formats.
- Review repository history, release archives, caches, and published packages for earlier copies of the exposed values.
- If any values are genuine, notify the affected individuals and follow applicable incident-response and privacy-reporting procedures. Ask the relevant financial institution whether account monitoring or replacement is necessary.
- Add automated secret and personally identifiable information scanning to the release pipeline, including checks for national ID formats, telephone numbers, bank card numbers, full addresses, and account-holder combinations.
- Require a manual privacy review for legal-document templates before publication.
- Validate generated documents before export so unresolved placeholders or bundled example identities cannot be submitted accidentally.
- Replace every pre-populated sensitive value with explicit placeholders, such as:
