T09 · Insecure Skill Coding Practices
- Location
api.py:6- Finding
Unauthenticated API Exposed on All Network Interfaces with Permissive CORS
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill appears to do its stated local intent-classification job, but its optional API can expose household chat classification over the network more broadly than the documentation suggests.
Install only if you are comfortable processing household chat snippets with this local classifier. Prefer the CLI or Python function for local use. If you run the API, bind it to 127.0.0.1, restrict CORS, add authentication for any shared deployment, and avoid sending private family conversations unless you have minimized or redacted them.
api.py:6Unauthenticated API Exposed on All Network Interfaces with Permissive CORS
api.py:15Missing Type and Size Validation for API Input
The skill is explicitly designed to process family chat text, which is highly likely to contain personal, household, and behavioral data. Failing to warn users about the privacy sensitivity, retention expectations, and handling boundaries can lead to unsafe use, accidental over-collection, or disclosure of sensitive conversations.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
python3 intent_classifier.py "想买一台电脑"
curl -X POST http://localhost:5000/intent -H "Content-Type: application/json" -d '{"text": "明天咱们去吃火锅吧"}'
## Python 调用
This code includes the service description, error text, docstrings, and startup messages only in Chinese. Under the policy, forcing a specific language without user opt-in or clear justification is a natural-language policy violation.
This Python file includes natural-language descriptions and expected output conventions entirely in Chinese, which effectively imposes a specific language/locale on users. The file does not indicate that the skill is intentionally limited to a Chinese-language context or provide any user opt-in or language selection.
The natural-language content and examples are all in Chinese, which effectively constrains use to a specific language. Because the file does not offer multilingual support, user opt-in, or a documented justification for the locale restriction, it matches the language/locale policy violation criteria.
No suspicious patterns detected.