T09 · Insecure Skill Coding Practices
- Location
scripts/generate-project.sh:300- Finding
Generated Application Uses a Hardcoded MySQL Root Password
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent e-commerce project generator, but its templates include unsafe defaults such as hardcoded secrets, default administrator credentials, and weak password-handling guidance.
Install only if you treat the output as a prototype or teaching scaffold. Before using any generated code beyond local development, replace all sample credentials and JWT secrets, remove default accounts, avoid root database access, hash passwords rather than reversibly encrypting them, restrict database users and hosts, review token storage, and add warnings/confirmations around destructive database and API operations.
scripts/generate-project.sh:300Generated Application Uses a Hardcoded MySQL Root Password
scripts/generate-project.sh:361Generated JWT Tokens Use a Publicly Known Static Signing Secret
references/database-schema-continued.md:149Database Template Publishes a Predictable Administrator Account
references/database-schema-continued.md:311Database Security Guidance Creates Remotely Accessible Users with Fixed Passwords
references/database-schema-continued.md:326Template Recommends Reversible Password Encryption with a Hardcoded Key
references/frontend-architecture.md:555Authentication Bearer Tokens Are Persisted in Script-Accessible Local Storage
Undeclared integrity verification, file existence checks, content matching, and report generation indicate operational behavior that differs materially from the advertised code-generation workflow. Such discrepancies are risky because they enable silent inspection of local project contents under a misleading functional label.
Undeclared integrity verification, file existence checks, content matching, and report generation indicate operational behavior that differs materially from the advertised code-generation workflow. Such discrepancies are risky because they enable silent inspection of local project contents under a misleading functional label.
Undeclared integrity verification, file existence checks, content matching, and report generation indicate operational behavior that differs materially from the advertised code-generation workflow. Such discrepancies are risky because they enable silent inspection of local project contents under a misleading functional label.
Undeclared integrity verification, file existence checks, content matching, and report generation indicate operational behavior that differs materially from the advertised code-generation workflow. Such discrepancies are risky because they enable silent inspection of local project contents under a misleading functional label.
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
GET /api/users/{id} # 获取用户详情
POST /api/users # 创建用户
PUT /api/users/{id} # 更新用户
DELETE /api/users/{id} # 删除用户
# 商品相关
GET /api/products # 获取商品列表
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
GET /api/products/{id} # 获取商品详情
POST /api/products # 创建商品
PUT /api/products/{id} # 更新商品
DELETE /api/products/{id} # 删除商品
# 订单相关
GET /api/orders # 获取订单列表
The encryption example stores passwords in a reversibly encrypted form and demonstrates decrypting and returning them, which is fundamentally unsafe for authentication data. Passwords must never be recoverable; if this pattern is implemented, compromise of the key or database exposes all user passwords and enables account takeover across reused credentials.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
│ │ └── UserMgr.vue # 用户管理
│ ├── App.vue # 根组件
│ └── main.js # 入口文件
├── .env # 环境变量
├── .env.development # 开发环境变量
├── .env.production # 生产环境变量
├── vite.config.js # Vite配置
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
│ ├── App.vue # 根组件
│ └── main.js # 入口文件
├── .env # 环境变量
├── .env.development # 开发环境变量
├── .env.production # 生产环境变量
├── vite.config.js # Vite配置
├── package.json # 项目配置
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
│ └── main.js # 入口文件
├── .env # 环境变量
├── .env.development # 开发环境变量
├── .env.production # 生产环境变量
├── vite.config.js # Vite配置
├── package.json # 项目配置
└── README.md # 项目说明
The skill title and the entire README are written in Chinese, and the document does not mention any ability for the user to choose another language or locale. Under the policy, a skill that implicitly enforces a specific language without user opt-in can be a natural-language policy violation.
The skill references shell scripts and project-generation scripts but does not declare any tool scope or permissions boundaries. In a skill that can touch the filesystem and potentially execute shell commands, missing explicit restrictions increases the chance of overbroad or unintended command execution, especially if downstream runners infer capabilities from repository contents.
The skill description is written as a directive in Chinese and presents the behavior in a single language without indicating that users may choose another language. Under the language/locale policy, forcing one language without opt-in is a natural-language policy issue unless the constraint is explicitly justified as region-specific.
The skill is designed to generate payment, authentication, deployment, and security-sensitive application code, yet it does not warn users about the risks of using generated code without security review. In this context, omission of warnings is dangerous because users may deploy insecure JWT, payment callback, or infrastructure configurations directly into production.
A broad trigger condition can cause the skill to activate in contexts beyond narrowly requested e-commerce scaffolding, including prompts involving payments, auth, deployment, or adjacent coding tasks. Overbroad activation raises the risk of the skill offering sensitive code or invoking risky helper behavior without sufficient user intent or review.
The example instructs users to run mysql -u root -p < database/init.sql against a local MySQL instance without any warning that the script can create, drop, or overwrite schema/data in the selected database. In a code-generation skill that encourages quick setup, this can lead users to execute destructive initialization steps on the wrong environment, causing accidental data loss or corruption.
This markdown file documents a DELETE endpoint for removing orders and shows a successful response, but it does not include any warning about data loss, irreversibility, or the impact on user records. For markdown files, destructive behaviors that could affect user data or system integrity should be accompanied by user-facing warnings.
The API spec describes deleting an address with a successful response but provides no caution that this removes stored personal/shipping information. In markdown documentation, actions affecting user data should explicitly warn users about the consequences.
The DELETE product endpoint removes product data, yet the documentation does not mention that the action is destructive or potentially irreversible. For markdown files, SQP-2 applies when descriptions omit warnings about operations that may affect system integrity or user data.
This markdown file describes a destructive operation to clear the shopping cart, but it provides no warning about data loss, confirmation expectation, or irreversible effects. Under the markdown-specific SQP-2 criteria, behaviors affecting user data should include some cautionary disclosure.
The file title and all user-facing documentation are written exclusively in Chinese, which imposes a specific language on readers without any stated opt-in, alternative language option, or region-specific justification. This matches the policy category for language/locale constraints expressed in natural language.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
-- 订单配置
('order_auto_cancel_minutes', '30', '订单自动取消时间(分钟)', 'order'),
('order_auto_confirm_days', '7', '订单自动确认收货时间(天)', 'order'),
('order_auto_complete_days', '3', '订单自动完成时间(天)', 'order'),
-- 支付配置
This markdown file contains a shell backup script that automatically deletes backup files older than 7 days using find ... -delete. While the script prints a completion message, there is no warning in the surrounding documentation that running it will permanently remove existing backups, which could affect data retention and recovery.
The maintenance SQL includes DELETE statements that remove orders older than 3 months and stale cart data. In a markdown skill/documentation file, destructive data operations should be accompanied by a clear warning about data loss, backup expectations, and execution caution, but no such warning is present here.
The guidance says to grant only necessary permissions, but the example creates database users bound to '%' and gives the application account broad read/write access to the entire schema. In a production ecommerce system, exposing remotely accessible credentials with full CRUD over all business data increases blast radius if the app, network perimeter, or credentials are compromised.
No suspicious patterns detected.