T09 · Insecure Skill Coding Practices
- Location
scripts/real_estate_analysis.py:21- Finding
Synthetic randomized estimates are presented as platform-derived market and auction data
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill needs review because it presents generated estimates as real real-estate market and auction data for financial decisions.
Install only if you treat the output as a rough demo or heuristic model, not as verified market or auction data. Do not rely on its prices, coverage ratios, or investment recommendations without independent source checks, and avoid submitting confidential property or debt records until logging, privacy disclosure, and real data provenance are fixed.
scripts/real_estate_analysis.py:21Synthetic randomized estimates are presented as platform-derived market and auction data
scripts/real_estate_analysis.py:936Property addresses and debt information are logged without redaction
The skill description materially misrepresents behavior: it claims live price comparison, external search, and report generation, while the implementation reportedly relies on local defaults/random estimation and returns a fabricated localhost report URL. This is dangerous because users may make financial decisions based on false provenance and fabricated outputs, and the hidden expansion to broad input-handling paths increases the attack surface beyond what the declared purpose suggests.
The module documentation states that the script calls web-search and report-generator skills, but the implementation does not do so and instead returns placeholder or local values. This creates deceptive system behavior and weakens operator trust, especially where downstream users may assume externally validated search and reporting occurred when it did not.
The skill claims to compare real Anjuke intermediary prices and Alibaba auction transaction prices, but it instead generates synthetic values from hardcoded tables and random fluctuations. In a financial decision-support context, fabricated market data can materially mislead investment or debt-recovery decisions, causing users to rely on outputs presented as factual when they are not.
The skill declares execution via a script and documents environment-variable use, file-based configuration, and network-dependent data collection, but it does not declare any explicit tool scope such as allowed tools or permissions. That weakens least-privilege controls and can let the runtime grant broader file, environment, or network access than users expect, which is risky given the skill processes potentially sensitive debt and property data.
The skill states that it uses network search, external data processing, and report generation, but it does not clearly warn users that supplied property and debt information may be sent to external services or written to output files. This is particularly sensitive in the real-estate debt context because addresses, debt principal, and related asset details can be confidential financial information.
The context trigger terms are very broad and include common real-estate vocabulary, making accidental activation likely in unrelated conversations. In a skill that may read files, process extracted content, or contact external services, overbroad triggering can cause unintentional handling or disclosure of user data without sufficiently clear intent.
The collaboration triggers for files, images, audio, and multimodal inputs use everyday phrases like 'help me analyze this file/image,' which can match many benign requests. Because the skill is designed to extract structured debt and property data from multiple media types, these broad phrases raise the chance of unintended ingestion of sensitive content and unexpected cross-skill activation.
The module description, comments, messages, and outputs are all in Chinese, and the parsing logic is tailored to Chinese field names and labels. There is no indication that users can opt into another language or that the Chinese-only behavior is a documented, justified locale constraint.
The manifest presents a specialized analysis skill focused on comparing two real-estate pricing sources. The main docstring and parsing logic expand the skill into a general multi-format, multimodal document ingestion pipeline, which is broader than the stated purpose and adds substantial capability beyond the core comparison task.
The skill processes sensitive property addresses, debt principal amounts, and potentially extracted content from files, images, audio, and multimodal inputs without any visible privacy notice, consent flow, minimization policy, or retention disclosure. In a debt-analysis context, this data can be highly sensitive and may expose individuals or portfolios if logged, reused, or transmitted without clear controls.
No suspicious patterns detected.