T09 · Insecure Skill Coding Practices
- Location
scripts/coppa-check.py:358- Finding
Advertised offline preview performs an undisclosed network request
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This COPPA checker mostly matches its stated cloud-scoring purpose, but it needs review because the advertised offline preview still contacts the cloud and HTML reports trust cloud-provided text too much.
Review before installing if you require a truly offline preview or will generate HTML reports. Use the skill only when you are comfortable sending questionnaire answers, an API key or anonymous trial ID, and normal network metadata to compliancehub.cn; avoid opening HTML reports from untrusted cloud responses until output escaping is fixed.
scripts/coppa-check.py:358Advertised offline preview performs an undisclosed network request
scripts/coppa-check.py:317Cloud-controlled report fields are embedded into HTML without escaping
This code presents important user-facing disclosures about anonymous trial mode and cloud submission only in Chinese, while the rest of the skill is largely English. That creates a language/locale policy issue because users are forced into a specific language for critical notices without any opt-in or alternative locale selection.
The skill title and overview switch between English and Chinese, and later usage guidance continues using Chinese terms like '检查' without stating a language preference or offering an opt-in choice. This can violate language/locale policy when a skill imposes mixed or specific language output on users without consent.
No suspicious patterns detected.