T09 · Insecure Skill Coding Practices
- Location
SKILL.md:135- Finding
Sensitive One-Time Authorization Credential Collected Through the Conversation
- Content
View full analysis
"Open the official website **www.xinjianxue.com → sign in → "Personal Center" (个人中心) → "AI Assistant Authorization Code" (AI 助手授权码)**, and send me the 8-character authorization code shown there; I need it to complete the account binding. > Reminder: this code is a **sensitive one-time credential** that is voided the moment the binding succeeds — please confirm you are talking to the official XinJianXue AI assistant (service domain `www.xinjianxue.com`) and send it only to me, this one AI; do not post it in a group chat, do not screenshot or share it, and do not give it to any other AI." `POST /api/xinjianxue/ai/license/bind` with body: ```json { "license": "XJX-AI-xxxxxxxxxxxxxxxx", "auth_code": "" } ``` On success it returns `api_key` (the business credential). > ⚠️ **The AI authorization code is a sensitive one-time credential** (8 characters, case-sensitive); it is voided once binding succeeds, and **it may only be used for this one binding**. ``` ### Technical Analysis The Skill explicitly classifies the eight-character authorization code as a sensitive credential, but requires the user to submit it directly to the AI through the conversation. This places the credential in model context and potentially in conversation history, platform telemetry, debugging traces, monitoring systems, or tool-call logs. The fact that the code becomes invalid after successful binding limits post-binding reuse, ...[truncated 1815 chars]- Remediation
View remediation
