T05 · Unauthorized Access and Privilege Escalation
- Location
references/permission-testing.md:12- Finding
Overprivileged Permission Templates Violate Least-Privilege Principles
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This HarmonyOS developer skill is mostly documentation, but some reusable examples encourage broad sensitive permissions and plaintext signing-secret patterns without enough safety guidance.
Install only if you want Chinese-language HarmonyOS development guidance. Treat its code samples as starting points, not secure defaults: remove unused permissions, avoid background location and floating windows unless clearly needed, do not store signing passwords or keys in tracked project files, and review network, distributed sync, remote file, and download examples for consent and data-scope issues.
references/permission-testing.md:12Overprivileged Permission Templates Violate Least-Privilege Principles
references/permission-testing.md:207Release Signing Passwords Are Shown as Plaintext Configuration Values
The skill documentation is presented entirely in Chinese from the title onward, with no indication that other languages are supported or that Chinese is an intentional opt-in choice. Under the policy criteria, forcing a specific language without user choice is a natural-language locale violation unless the locale restriction is clearly documented and justified.
The trigger list includes broad generic terms such as @kit, HAP, HAR, and UIAbility, which can activate the skill during ordinary technical discussion that is not specifically asking for HarmonyOS guidance. Over-broad activation can hijack unrelated conversations, causing the agent to apply this skill's output constraints and content in contexts where it is not appropriate.
The skill mandates a rigid response format and includes language/output behavior requirements without user opt-in, which can override normal assistant behavior once the skill is triggered. In combination with the broad trigger list, this increases the chance that unrelated requests are forced into an unwanted style or language, degrading reliability and potentially bypassing higher-level interaction expectations.
This markdown file is entirely written in Chinese, including the title and instructional content, with no indication that the language is optional or that the document is intended only for a Chinese-specific audience. Under the stated policy, forcing a specific language without user opt-in can constitute a natural-language policy violation.
The example explicitly serializes local application state and sends it to a target device during continuation, but the markdown provides no warning that user or app data may be transmitted across devices. For documentation files, this omission matters because cross-device transfer can affect privacy and user expectations.
The markdown states that data written to the KV store is automatically synced to other devices, but it does not include any caution about privacy, data scope, or user consent. Because this behavior can replicate user or app data beyond the local device, the skill description should warn about the impact.
The example demonstrates reading files from a remote device, which is a privacy-sensitive operation, but the markdown does not warn users or implementers about permissions, user consent, or sensitive data exposure. For markdown files, omission of such a warning is in scope when behavior can affect user data or system integrity.
The examples demonstrate sending bearer tokens, enabling cookies, and configuring client certificates/private-key passwords for HTTP requests. The document does not include any caution that these mechanisms may transmit sensitive credentials or session data and should only be used with trusted endpoints and secure storage practices.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
// 发起请求
httpRequest.request(
'https://api.example.com/data',
{
method: http.RequestMethod.GET, // 默认 GET
header: {
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
// 发起请求
httpRequest.request(
'https://api.example.com/data',
{
method: http.RequestMethod.GET, // 默认 GET
header: {
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
// 发起请求
httpRequest.request(
'https://api.example.com/data',
{
method: http.RequestMethod.GET, // 默认 GET
header: {
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
// 发起请求
httpRequest.request(
'https://api.example.com/data',
{
method: http.RequestMethod.GET, // 默认 GET
header: {
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
// 发起请求
httpRequest.request(
'https://api.example.com/data',
{
method: http.RequestMethod.GET, // 默认 GET
header: {
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
// 发起请求
httpRequest.request(
'https://api.example.com/data',
{
method: http.RequestMethod.GET, // 默认 GET
header: {
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
// 发起请求
httpRequest.request(
'https://api.example.com/data',
{
method: http.RequestMethod.GET, // 默认 GET
header: {
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
// 发起请求
httpRequest.request(
'https://api.example.com/data',
{
method: http.RequestMethod.GET, // 默认 GET
header: {
This markdown file includes download examples that open local files and write HTTP response data to caller-supplied paths, which can affect user data and filesystem state. The surrounding documentation explains how to perform the operation but does not warn that the examples create or overwrite files locally.
The document enumerates a broad set of highly sensitive HarmonyOS permissions, including contacts, location, microphone, storage management, floating window, and background location, but provides no least-privilege guidance, justification requirements, or warnings about privacy implications. In a developer skill, this can normalize over-requesting permissions and lead downstream users to copy insecure manifests, increasing the risk of unnecessary data access and privacy-invasive app behavior.
The release signing example shows plaintext password fields and concrete secret-bearing configuration structure without warning that real credentials must never be committed to source control. Developers may copy this pattern directly into build-profile.json5 with actual keystore and key passwords, leading to credential leakage, unauthorized app signing, and supply-chain compromise if the repository is exposed.
This markdown file includes a permissions section listing sensitive capabilities such as camera, microphone, contacts, location, background location, and storage access, but it provides only functional descriptions and no user-facing warning about privacy, consent, or data impact. Under SQP-2 for markdown files, descriptions should warn when behaviors could affect user data, privacy, or system integrity.
The file provides instructions for creating a global floating window that can remain visible after app exit, which can materially affect user experience and system behavior. Although the required permission is mentioned, there is no warning about the sensitivity of overlay-style UI, when it is appropriate, or the need to clearly inform users.
This markdown file is entirely presented in Chinese and cites a Chinese-source documentation page, but it does not indicate that the language choice is optional or limited to a China-specific audience. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a locale-policy issue.
The entire reference is written in Chinese, including headings, comments, and usage descriptions, with no indication that users may choose another language or that the Chinese-only presentation is required for a region-specific purpose. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.
This markdown file contains user-facing natural-language content exclusively in Chinese, but does not state that the glossary is intended specifically for Chinese-speaking users or offer any language alternative. Under the language/locale policy, forcing a specific language without user opt-in can be a policy concern.
The TTS configuration hard-codes the language to 'zh-CN', which imposes a specific language/locale choice in natural-language content. The document does not indicate that this is optional, user-selectable, or required for a region-specific use case.
No suspicious patterns detected.