T09 · Insecure Skill Coding Practices
- Location
SKILL.md:74- Finding
Excessive Personal Data Collection and Unsafe API Credential Transport
- Content
View full analysis
", "birth": "1990-01-01 08:30", "gender": "Female", "country": "United States", "place": "New York City", "current_country": "United States", "current_place": "New York City" } ``` ### Technical Analysis The Skill directs the agent to collect and transmit date and time of birth, gender, birthplace, and current location to an external service. These identity-linked attributes are broader than the information ordinarily required to provide workplace communication or manager-relationship advice. Combining these attributes can enable profiling and identity correlation. The report endpoint also requires the `api_key` to be placed in the JSON request body. Request bodies are commonly captured by application diagnostics, HTTP tracing, reverse-proxy logs, observability platforms, and debugging tools. Authentication secrets in bodies are therefore more likely to be retained or disclosed than credentials carried exclusively in protected authorization headers. The onboarding workflow additionally requires the user to send a sensitive one-time authorization code through the c ...[truncated 2185 chars]- Remediation
View remediation
