T09 · Insecure Skill Coding Practices
- Location
references/vpn_config.yaml:2- Finding
Plaintext VPN Credentials Committed to the Project
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This internal admin automation skill is coherent in purpose, but it ships sensitive credentials and can make broad admin, VPN, and moderation changes with weak safeguards.
Review before installing. Do not use the packaged credentials; rotate any real VPN or admin credentials that may have been exposed. Run only in a disposable or dedicated environment unless the VPN helper is rewritten to avoid global /etc changes, shell injection risk, default-route replacement, broad process termination, OTP logging, and unsanitized debug captures.
references/vpn_config.yaml:2Plaintext VPN Credentials Committed to the Project
debug/login_test.py:10Administrative Account Credentials Hard-Coded in Executable Scripts
scripts/vpn_l2tp.py:61Root-Level Shell Command Injection Through VPN Server Configuration
scripts/whitelist.py:15Domain Whitelist Bypassed by All Non-Document Requests
scripts/run.py:257One-Time Password and Account Details Disclosed Through Debug Logging
scripts/run.py:290Authenticated Page Content Persisted in Unprotected Debug Artifacts
scripts/vpn_l2tp.py:29VPN Automation Destructively Reconfigures Host-Wide Networking
scripts/run.py:226TLS Certificate Validation Disabled for Administrative Authentication
Partial or absent whitelist enforcement is a serious issue when the skill explicitly claims to prohibit external access. In a tool designed for internal admin systems, incomplete filtering can permit unexpected outbound requests, data exposure to unapproved domains, or loading of external resources that undermine the claimed security boundary.
Partial or absent whitelist enforcement is a serious issue when the skill explicitly claims to prohibit external access. In a tool designed for internal admin systems, incomplete filtering can permit unexpected outbound requests, data exposure to unapproved domains, or loading of external resources that undermine the claimed security boundary.
Partial or absent whitelist enforcement is a serious issue when the skill explicitly claims to prohibit external access. In a tool designed for internal admin systems, incomplete filtering can permit unexpected outbound requests, data exposure to unapproved domains, or loading of external resources that undermine the claimed security boundary.
Partial or absent whitelist enforcement is a serious issue when the skill explicitly claims to prohibit external access. In a tool designed for internal admin systems, incomplete filtering can permit unexpected outbound requests, data exposure to unapproved domains, or loading of external resources that undermine the claimed security boundary.
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
<link href="/static/admin/css/animate.min.css" rel="stylesheet">
<link href="/static/admin/css/style.min862f.css?v=4.1.0" rel="stylesheet">
<!--[if lt IE 9]>
<meta http-equiv="refresh" content="0;ie.html"/>
<![endif]-->
<script>if (window.top !== window.self) {
The page loads a third-party Cloudflare Insights beacon from an external domain, which directly contradicts the skill's stated prohibition on external network access for internal-admin automation. In an internal admin context, this can leak metadata about access to an internal login page, create undeclared outbound connectivity, and weaken trust boundaries around a supposedly isolated workflow.
The script hardcodes a live-looking internal admin username and password directly in source, which exposes privileged credentials to anyone who can read the repository, logs, backups, or copied files. In the context of an internal admin Playwright skill, this is especially dangerous because the credentials enable direct access to a backend system and exceed what a diagnostic script should embed.
This script does more than menu navigation: it makes autonomous moderation decisions and executes approve/reject actions against a live internal admin system. In the context of a skill described as controlled internal automation, hidden decision-making logic materially increases risk because it can alter production content state at scale without human review.
Hardcoded admin credentials in source code are a direct secret exposure risk. Anyone with access to the skill files, logs, backups, or version history can recover them and gain unauthorized access to the internal staff system, especially dangerous here because the target is an internal administrative interface.
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
data = json.loads(path.read_text(encoding="utf-8"))
rules = [r for r in data["rules"] if r.get("enabled")]
print(f"已加载规则文件: {path}")
return rules
return []
def check_content(text, rules):
The script performs state-changing approval/rejection actions automatically in a live moderation system without user confirmation, warning, or rollback safeguards. If the rules are wrong, tampered with, or overly broad, the automation can rapidly cause censorship errors, policy violations, or loss of legitimate user content at scale.
The code explicitly accesses a repository-local .env file as a credential source, which is a form of credential collection/persistence inside the skill package. For an internal admin automation tool, embedding or auto-loading secrets from local files increases exposure risk and makes compromise of the skill directory materially more damaging.
def _load_dotenv(skill_root: Path) -> None:
env_file = skill_root / "references" / ".env"
if not env_file.exists():
return
for line in env_file.read_text(encoding="utf-8").splitlines():
The debug output prints the OTP, username, and target URL directly to stdout during login. In a controlled internal-admin automation skill, these values are highly sensitive and may be captured by terminal logs, CI runners, shell history wrappers, centralized logging, or other observers, enabling credential replay or account compromise.
This specific debug statement emits the OTP in cleartext with no warning or masking. OTPs are short-lived but still security-sensitive, and disclosure during an active login window can enable immediate unauthorized access or aid monitoring of authentication workflows.
Writing full page HTML to disk on failure can capture login forms, prefilled usernames, hidden tokens, internal URLs, session identifiers, and other sensitive application state. In an internal admin context, debug artifacts stored locally in predictable paths materially increase the risk of credential leakage and unauthorized insight into internal systems.
This is a true tool-parameter abuse issue because the generic shell wrapper accepts arbitrary command strings and is later fed interpolated data. In a skill explicitly designed for internal admin/VPN access and likely run with elevated privileges, command injection has amplified impact: arbitrary code execution, network rerouting, credential theft, and host compromise.
def sh(cmd: str, check: bool = True) -> subprocess.CompletedProcess:
return subprocess.run(cmd, shell=True, text=True, capture_output=True, check=check)
def load_cfg(skill_root: Path) -> dict:
The script overwrites system VPN/IPsec/PPP configuration under /etc and controls daemons without any confirmation, backup, or rollback. In a privileged automation context this can disrupt existing host networking or security configuration and can lock out administrators if run on the wrong machine.
The up/down flows modify the default route and terminate networking processes like pppd and xl2tpd without confirmation or safety checks. On an internal-admin automation skill, this can sever host connectivity, redirect all traffic through the VPN, or disrupt other active tunnels and administrative sessions.
The route guard only enforces the hostname whitelist for document navigations and explicitly allows all non-document requests such as scripts, XHR/fetch, images, fonts, and iframes' subresources to any destination. In an internal-admin automation skill, this can allow a whitelisted internal page to trigger requests to attacker-controlled or external hosts, causing data exfiltration, request smuggling to unapproved endpoints, or bypass of the stated 'no external access' control.
The README explicitly describes the skill as using Chinese command routing, and the command configuration example is presented only in Chinese. Because no user opt-in, alternative language support, or justification for a Chinese-only interface is documented, this is a natural-language locale policy concern.
This markdown file shows users setting STAFF_USERNAME, STAFF_PASSWORD, GOOGLE_OTP, and a login URL to run the skill, which clearly involves sensitive authentication data. While the README later advises not to commit real credentials, it does not explicitly warn users in the run instructions about secret exposure risks in shell history, process listings, or local environment handling.
The skill metadata declares no explicit tool scope even though it describes capabilities involving environment variables, file access, networking, and shell execution. In an automation skill that can manipulate VPN state and access internal admin systems, missing scope declarations weakens containment and can allow broader-than-expected execution in a sensitive environment.
The description and command examples state that routing is based on Chinese instructions and show only Chinese command forms, which indicates a language-specific constraint. Because no user choice, opt-in, or justification for enforcing Chinese is provided in the natural-language description, this is a locale/language policy concern.
Third-party telemetry on an internal administrative login page is unnecessary for the described automation purpose and introduces avoidable data exposure to an external service. Even if it only collects page-view or timing data, it still creates an external reporting channel from a sensitive internal workflow.
The script accesses and uses sensitive authentication data from hardcoded literals without any protection, warning, or justification, which increases the likelihood of accidental exposure and reuse. This is not merely a UX omission: the code itself stores plaintext admin credentials in a retrievable form, making compromise of the repository or workstation sufficient to obtain them.
No suspicious patterns detected.