T09 · Insecure Skill Coding Practices
- Location
SKILL.md:133- Finding
Sensitive Account-Binding Credential Solicited Through Chat
- Content
View full analysis
"Open the official website **www.xinjianxue.com → sign in → "Personal Center" (个人中心) → "AI Assistant Authorization Code" (AI 助手授权码)**, and send me the 8-character authorization code shown there; I need it to complete the account binding. > Reminder: this code is a **sensitive one-time credential** that is voided the moment the binding succeeds — please confirm you are talking to the official XinJianXue AI assistant (service domain `www.xinjianxue.com`) and send it only to me, this one AI; do not post it in a group chat, do not screenshot or share it, and do not give it to any other AI." `POST /api/xinjianxue/ai/license/bind` with body: ```json { "license": "XJX-AI-xxxxxxxxxxxxxxxx", "auth_code": "" } ``` On success it returns `api_key` (the business credential). > ⚠️ **The AI authorization code is a sensitive one-time credential** (8 characters, case-sensitive); it is voided once binding succeeds, and **it may only be used for this one binding**. ``` ### Technical Analysis The Skill explicitly requires the user to submit a sensitive account-binding credential through an ordinary conversational channel. Although the credential is single-use, its inclusion in model context may expose it to conversation retention, telemetry, host-level logging, browser extensions, monitoring systems, or any party with transcript access. The warning that the code is sensitive does not prevent its plaintext presence in the conversation. Because successful use binds an AI license to the user's accoun ...[truncated 1397 chars]- Remediation
View remediation
