T09 · Insecure Skill Coding Practices
- Location
SKILL.md:131- Finding
Sensitive One-Time Authorization Code Collected Through Conversation Context
- Content
View full analysis
"Open the official website **www.xinjianxue.com → sign in → "Personal Center" (个人中心) → "AI Assistant Authorization Code" (AI 助手授权码)**, and send me the 8-character authorization code shown there; I need it to complete the account binding. > Reminder: this code is a **sensitive one-time credential** that is voided the moment the binding succeeds — please confirm you are talking to the official XinJianXue AI assistant (service domain `www.xinjianxue.com`) and send it only to me, this one AI; do not post it in a group chat, do not screenshot or share it, and do not give it to any other AI." `POST /api/xinjianxue/ai/license/bind` with body: ```json { "license": "XJX-AI-xxxxxxxxxxxxxxxx", "auth_code": "" } ``` ``` ### Technical Analysis The Skill explicitly classifies the authorization code as a sensitive, one-time credential but requires the user to submit it directly through the AI conversation. This places the secret in model context and potentially in conversation history, application telemetry, diagnostic traces, or platform logs. Although successful binding invalidates the code, there is an exposure window between disclosure and binding. Any party able to access the live conversation or retained logs during that window may recover the code. The binding operation is security-sensitive because it associates an AI-controlled license with the user's external service account and returns ...[truncated 1551 chars]- Remediation
View remediation
