T09 · Insecure Skill Coding Practices
- Location
scripts/policy_gov_fetcher.py:91- Finding
Configurable Search Subprocess Inherits the Complete Agent Environment
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This appears to be a real investment-research skill, but it exposes too much of the agent environment to subprocesses and configurable helper code, so it needs user review before installation.
Install only if you are comfortable with investment topics, ticker symbols, and research queries being sent to third-party data/search providers. Avoid using it with confidential holdings or proprietary research themes, and prefer running it in an environment that contains only the specific API keys it needs, because current subprocess handling can expose unrelated environment secrets to helper scripts.
scripts/policy_gov_fetcher.py:91Configurable Search Subprocess Inherits the Complete Agent Environment
scripts/ministry_scanner.py:318Unvalidated Search and Page URLs Can Trigger Server-Side Request Forgery
scripts/insider_transactions.py:16Plaintext HTTP Sources Allow Research-Data Manipulation in Transit
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
from_date = (today - timedelta(days=7)).isoformat()
to_date = today.isoformat()
try:
resp = requests.get(
f"{FINNHUB_URL}/calendar/earnings",
params={"from": from_date, "to": to_date, "token": FINNHUB_KEY},
timeout=15,
Tracking super-investor holdings from undeclared sources and applying them to a watchlist creates a monitoring pipeline that users may not expect from a general research framework. The main risk is undisclosed external data sharing and holdings-focused surveillance behavior, not the data source itself.
Tracking super-investor holdings from undeclared sources and applying them to a watchlist creates a monitoring pipeline that users may not expect from a general research framework. The main risk is undisclosed external data sharing and holdings-focused surveillance behavior, not the data source itself.
Tracking super-investor holdings from undeclared sources and applying them to a watchlist creates a monitoring pipeline that users may not expect from a general research framework. The main risk is undisclosed external data sharing and holdings-focused surveillance behavior, not the data source itself.
Tracking super-investor holdings from undeclared sources and applying them to a watchlist creates a monitoring pipeline that users may not expect from a general research framework. The main risk is undisclosed external data sharing and holdings-focused surveillance behavior, not the data source itself.
Tracking super-investor holdings from undeclared sources and applying them to a watchlist creates a monitoring pipeline that users may not expect from a general research framework. The main risk is undisclosed external data sharing and holdings-focused surveillance behavior, not the data source itself.
Tracking super-investor holdings from undeclared sources and applying them to a watchlist creates a monitoring pipeline that users may not expect from a general research framework. The main risk is undisclosed external data sharing and holdings-focused surveillance behavior, not the data source itself.
Tracking super-investor holdings from undeclared sources and applying them to a watchlist creates a monitoring pipeline that users may not expect from a general research framework. The main risk is undisclosed external data sharing and holdings-focused surveillance behavior, not the data source itself.
Tracking super-investor holdings from undeclared sources and applying them to a watchlist creates a monitoring pipeline that users may not expect from a general research framework. The main risk is undisclosed external data sharing and holdings-focused surveillance behavior, not the data source itself.
Tracking super-investor holdings from undeclared sources and applying them to a watchlist creates a monitoring pipeline that users may not expect from a general research framework. The main risk is undisclosed external data sharing and holdings-focused surveillance behavior, not the data source itself.
Tracking super-investor holdings from undeclared sources and applying them to a watchlist creates a monitoring pipeline that users may not expect from a general research framework. The main risk is undisclosed external data sharing and holdings-focused surveillance behavior, not the data source itself.
Tracking super-investor holdings from undeclared sources and applying them to a watchlist creates a monitoring pipeline that users may not expect from a general research framework. The main risk is undisclosed external data sharing and holdings-focused surveillance behavior, not the data source itself.
Tracking super-investor holdings from undeclared sources and applying them to a watchlist creates a monitoring pipeline that users may not expect from a general research framework. The main risk is undisclosed external data sharing and holdings-focused surveillance behavior, not the data source itself.
Referenced artifact was not completely inspected
| 行业深度研究 | methodology/industry-research.md | templates/01 |
Copying the full parent environment into child processes can leak secrets such as API keys, tokens, proxy settings, or credentials to every fetcher subprocess, including ones that may log or mishandle them. In a data-collection pipeline that runs many external-data fetchers, broad environment inheritance increases blast radius if any child process is compromised or overly verbose.
"--output-dir", output_dir,
]
env = os.environ.copy()
env["PYTHONPATH"] = SCRIPTS_DIR
is_heavy = FETCHERS.get(module_name, {}).get("heavy", False)
This special fetcher also inherits the full process environment before spawning a child interpreter, creating the same unnecessary exposure of credentials and runtime secrets. Because this path executes a custom inline Python command, inherited secrets are available to imported code and any downstream network clients it invokes.
def run_special_fetcher(name: str, today: str, output_dir: str) -> dict:
"""Run policy_gov which has a different entry point."""
env = os.environ.copy()
env["PYTHONPATH"] = SCRIPTS_DIR
if name == "policy_gov":
The user-facing README content is written entirely in Chinese, and there is no indication that users may choose another language or that the skill is intentionally restricted to a Chinese-speaking or region-specific audience. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.
The skill advertises and instructs use of capabilities that imply environment-variable access, local file reads/writes, network access, and shell subprocess execution, but it does not declare any explicit permission scope. That omission weakens reviewability and least-privilege enforcement: users and platforms cannot easily tell what the skill is allowed to do before installation or execution.
The manifest description is written as a Chinese-only operating description for broad investment research use, with no indication that users may choose another language. Because the skill is presented for general use rather than a clearly region-limited compliance context, this appears to impose a language/locale constraint without opt-in.
The trigger conditions are extremely broad ('any investment research request'), which can cause the skill to activate for routine conversations and unnecessarily send user prompts, symbols, or research topics to external tools. Overbroad activation increases accidental data exposure and makes it harder for users to predict when networked data collection or file writes will occur.
The file title and required output template are entirely in Chinese, and the template is marked as mandatory to follow strictly. This imposes a specific language/locale on the skill without any opt-in, alternative language path, or documented region-specific justification, which matches the language-policy violation criteria.
The protocol is written entirely in Chinese and prescribes Chinese-centric output conventions without offering a language-selection mechanism. In a general-purpose agent skill, this can cause the model to ignore the user's preferred language, reducing transparency, increasing misunderstanding risk, and potentially causing users or downstream systems to miss critical limitations, caveats, or safety information.
The entire skill is written only in Chinese and does not indicate any option for the user to choose another language or locale. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation.
SQP-3 covers natural-language policy violations across all file types, including language or locale constraints. The file presents all instructions in Chinese and does not indicate that Chinese is optional, user-selected, or required for a region-specific purpose, which can amount to forcing a language without user opt-in.
The entire skill file is written in Chinese and presents all guidance exclusively in that language, with no indication that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking context. This creates a natural-language policy issue under the language/locale rule because it effectively imposes a specific language without user opt-in.
No suspicious patterns detected.