T09 · Insecure Skill Coding Practices
- Location
SKILL.md:131- Finding
Sensitive Account-Binding Credential Solicited Through Chat
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 131–146
Vulnerability Type: Sensitive credential exposure through conversational context
Risk Level: MediumVulnerable Snippet
markdown ### Step 2: Ask the user for the XinJianXue AI authorization code and complete the binding **The AI must stop here and ask the user for the XinJianXue AI authorization code.** It is a one-time credential, **usable only to bind the license above to the user's account**, and for nothing else. Use this fixed wording: > "Open the official website **www.xinjianxue.com → sign in → "Personal Center" (个人中心) → "AI Assistant Authorization Code" (AI 助手授权码)**, and send me the 8-character authorization code shown there; I need it to complete the account binding. > Reminder: this code is a **sensitive one-time credential** that is voided the moment the binding succeeds — please confirm you are talking to the official XinJianXue AI assistant (service domain `www.xinjianxue.com`) and send it only to me, this one AI; do not post it in a group chat, do not screenshot or share it, and do not give it to any other AI." `POST /api/xinjianxue/ai/license/bind` with body: ```json { "license": "XJX-AI-xxxxxxxxxxxxxxxx", "auth_code": "<the 8-character code the user sent>" }On success it returns
api_key(the business credential).⚠️ The AI authorization code is a sensitive one-time credential (8 characters, case-sensitive); it is voided once binding succeeds, and it may only be used for this one binding.
text ### Technical Analysis The Skill explicitly identifies the authorization code as a sensitive, one-time account-binding credential but instructs the user to disclose it directly in the conversation. This places the secret in model context and potentially in chat transcripts, telemetry, application logs, browser history, moderation systems, extensions, or integrations. Although the Skill warns users not to s ...[truncated 2049 chars]- Remediation
View remediation
Remediation Suggestions
- Replace chat-based credential submission with an OAuth-style authorization redirect, device authorization flow, or authenticated confirmation page hosted on the official service domain.
- Ensure the user submits or approves the binding directly with
www.xinjianxue.com; the authorization secret must never enter model context or a chat transcript. - Bind the authorization request to the intended license using a high-entropy, short-lived challenge and verify state, audience, expiration, and single-use status server-side.
- If a device-code flow is used, show only a non-sensitive transaction identifier in chat and require final approval in the user's authenticated browser session.
- Prevent secrets from appearing in logs, telemetry, traces, error messages, or analytics. Apply redaction as defense in depth rather than as the primary control.
- Add expiration, revocation, binding-status inspection, and self-service unbinding or recovery controls to limit damage from intercepted credentials.
- Until a secure flow exists, clearly state that users must not paste account-binding credentials into the conversation and disable automated binding through chat.
