T09 · Insecure Skill Coding Practices
- Location
index.js:604- Finding
Prototype Pollution Through Attacker-Controlled Active-Learning Keys
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly matches its stated data-matching purpose, but it deserves review because it handles sensitive business and HR records while documenting broad triggers and optional HITL-bypass behavior, and its active-learning code has a real unsafe dynamic-key bug.
Install only if you will keep this skill inside a controlled matching workflow, require explicit human approval before creating or updating master records, and fix or isolate the active-learning dynamic-key handling before processing untrusted OCR fields or review payloads. Be especially cautious with HR, finance, tax, bank, and employee identifier data.
index.js:604Prototype Pollution Through Attacker-Controlled Active-Learning Keys
Referenced artifact was not completely inspected
import mdm from './index.js';
Referenced artifact was not completely inspected
import mdm from './index.js';
The trigger list includes broad business phrases such as 'finance matching', 'HR matching', and 'human in the loop', which can cause the skill to activate in contexts far beyond entity resolution. In a production agent, unintended invocation can route sensitive finance or HR data into this skill, increasing the chance of inappropriate processing, privacy exposure, or incorrect workflow automation.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
}
},
"hitl": {
"autoConfirmThreshold": 0.98,
"autoRejectThreshold": 0.3,
"requireHumanReviewBelow": 0.92,
"reviewActions": [
The architecture explicitly supports auto-apply behavior via 'Auto-apply (if skipHitl)' alongside create/update actions that can modify master data records. In a master-data matching system spanning procurement, finance, sales, and HR, silent updates or record creation without an explicit user warning and strong approval controls can cause unauthorized data changes, incorrect entity linkage, and downstream business process corruption.
The example hard-codes locale-specific values such as a China-format phone number and a Beijing address, which nudges the skill toward a specific regional context without documenting that the skill is region-specific or offering locale flexibility. Under the stated policy, locale constraints should be explicitly justified or made optional.
No suspicious patterns detected.