T09 · Insecure Skill Coding Practices
- Location
SKILL.md:22- Finding
Unredacted Collection of Tool Arguments and Results
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill has a coherent tracing purpose, but it encourages broad raw logging of agent tool calls to a network service without enough privacy, security, or deployment safeguards.
Install only if you are comfortable with agent activity being stored in the tracer. Keep it bound to localhost unless you have authentication, TLS, and firewall controls; do not log secrets, credentials, private files, customer data, or personal data without redaction and a retention/deletion plan.
SKILL.md:22Unredacted Collection of Tool Arguments and Results
SKILL.md:16Plaintext Configurable Telemetry Destination and Network-Wide Service Binding
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
# 1. 创建 trace,拿到 trace_id
TRACE_ID=$(curl -s -X POST $TRACER_BASE_URL/traces \
-H 'Content-Type: application/json' \
-d '{"agent":"market-bot","task":"收盘汇总","session_id":"sess-001"}' \
| python3 -c "import sys,json;print(json.load(sys.stdin)['trace_id'])")
The skill is explicitly designed to record every tool call, including agent tasks, session identifiers, arguments, results, model names, and token counts, and send them to a network service. The documentation provides no warning about sensitive-data handling, retention, minimization, access control, or consent, so users may inadvertently transmit confidential prompts, tool outputs, or personal data to the tracer backend.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# 1. 创建 trace,拿到 trace_id
TRACE_ID=$(curl -s -X POST $TRACER_BASE_URL/traces \
-H 'Content-Type: application/json' \
-d '{"agent":"market-bot","task":"收盘汇总","session_id":"sess-001"}' \
| python3 -c "import sys,json;print(json.load(sys.stdin)['trace_id'])")
The example workflow posts detailed execution data to the tracer service, including task names, session IDs, tool arguments, and tool results, but gives no user-facing warning that these fields may expose proprietary, regulated, or personal information. Because this is sample code users are likely to copy directly, it materially increases the chance of accidental data disclosure and long-term retention in the tracing system.
This example transmits raw tool-call arguments and results to the tracer service, which can easily include secrets, internal documents, personal data, or model outputs with sensitive content. In the context of an agent tracing skill, this is especially dangerous because comprehensive logging is encouraged by design, amplifying the blast radius of any backend compromise, misconfiguration, or over-retention.
| python3 -c "import sys,json;print(json.load(sys.stdin)['trace_id'])")
# 2. 每次工具调用记一条 span(model/tokens 可选,带上才有成本分析)
curl -s -X POST $TRACER_BASE_URL/traces/$TRACE_ID/spans \
-H 'Content-Type: application/json' \
-d '{"tool_name":"web_search","arguments":{"query":"上证指数"},
"result":"上证 3200.15 +0.85%","duration_ms":850,
No suspicious patterns detected.