T09 · Insecure Skill Coding Practices
- Location
scripts/run.sh:199- Finding
Bearer and Local Administrator Credentials Can Be Sent to Arbitrary Endpoint Overrides
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is coherent for browser-based web collection, but it needs review because it handles authenticated data and credentials with under-scoped endpoint, storage, and install controls.
Install only if you trust the publisher and the Feishu/GitHub sources. Before running, verify the connector and browser extension source, avoid saving cloud tokens in preferences if possible, keep cloud and bridge URLs at the documented defaults, and do not pass an untrusted `--bridge-cmd` or endpoint override.
scripts/run.sh:199Bearer and Local Administrator Credentials Can Be Sent to Arbitrary Endpoint Overrides
scripts/export_preference.sh:191Cloud Bearer Tokens Are Persisted in Plaintext Without Enforced Owner-Only Permissions
SKILL.md:112Mutable and Unverified Sources Are Used for Extension, Connector, and Skill Installation
The skill presents itself mainly as a collection/onboarding helper, but the instructions also include modifying local preference state, applying defaults, and handling cloud credential-related fields. When a skill mutates local state and credential configuration beyond what its description clearly discloses, users and reviewers may underestimate its ability to alter persistent settings or affect future runs.
The skill presents itself mainly as a collection/onboarding helper, but the instructions also include modifying local preference state, applying defaults, and handling cloud credential-related fields. When a skill mutates local state and credential configuration beyond what its description clearly discloses, users and reviewers may underestimate its ability to alter persistent settings or affect future runs.
Referenced artifact was not completely inspected
For collection execution, keep using this `SKILL.md` and the bundled scripts as the agent contract. For complex or ambiguous execution requests, read [reference
Referenced artifact was not completely inspected
For collection execution, keep using this `SKILL.md` and the bundled scripts as the agent contract. For complex or ambiguous execution requests, read [reference
Referenced artifact was not completely inspected
- When authorization is needed, run the normal collection entry point or `scripts/ensure_connector_auth.sh`; it will generate a website login confirmation link.
Referenced artifact was not completely inspected
- When authorization is needed, run the normal collection entry point or `scripts/ensure_connector_auth.sh`; it will generate a website login confirmation link.
Referenced artifact was not completely inspected
- When authorization is needed, run the normal collection entry point or `scripts/ensure_connector_auth.sh`; it will generate a website login confirmation link.
Referenced artifact was not completely inspected
- `run.sh` first tries environment variables, stored preferences, App state, and connector state.
Referenced artifact was not completely inspected
- `run.sh` first tries environment variables, stored preferences, App state, and connector state.
Referenced artifact was not completely inspected
- `run.sh` first tries environment variables, stored preferences, App state, and connector state.
Referenced artifact was not completely inspected
- `run.sh` first tries environment variables, stored preferences, App state, and connector state.
Referenced artifact was not completely inspected
values, ask for the complete set in one message and then persist them through `scripts/export_preference.sh set-key`. Do not introduce a card callback server,
Referenced artifact was not completely inspected
values, ask for the complete set in one message and then persist them through `scripts/export_preference.sh set-key`. Do not introduce a card callback server,
Referenced artifact was not completely inspected
- local mode dispatches only through `scripts/collect_and_export_loop.sh`
Referenced artifact was not completely inspected
- local mode dispatches only through `scripts/collect_and_export_loop.sh`
Referenced artifact was not completely inspected
- `scripts/reexport_task.sh`
The manifest describes a web-collection skill for connector-based data collection and onboarding/troubleshooting, but this script also accepts a caller-supplied command and later executes it to start a bridge. Spawning an arbitrary local process via a free-form command is a powerful capability that is not inherently required for performing collection requests against the connector API.
When --ensure-bridge is enabled, the script executes nohup bash -lc "$BRIDGE_CMD" ... &, which is a direct shell execution sink. If --bridge-cmd is influenced by untrusted input, this becomes arbitrary command execution with the privileges of the script runner and persists as a background process.
The script captures output from an authorization helper and executes it with eval, meaning any compromised helper, tampered file, or unexpected output can run arbitrary shell code in the caller's context. This goes beyond configuration parsing and turns auth-response handling into a local code-execution primitive.
The script accepts a bridge startup command from an environment variable or CLI argument and passes it into downstream execution, enabling arbitrary shell command execution if that value is attacker-controlled. In a data-collection skill, this is unnecessarily broad capability and creates a clear command-injection/RCE path on the local host.
This markdown file states that the skill performs data collection across multiple websites and handles exports, but it does not disclose any user warning about effects on privacy, collected account data, or downstream handling of exported data. For markdown files, SQP-2 applies when the skill description omits warnings about behaviors that could affect user data, privacy, or system integrity.
The skill specifies executable capabilities such as shell, network, and environment access but does not declare an explicit tool scope or permission boundary. That increases the risk of overbroad execution, because the agent can invoke scripts, read environment state, and make outbound requests without an in-file allowlist constraining what is intended.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
- `assets/bitable-step-00-personal-center.png`
- Use when telling the user to open the browser extension, enter `个人中心`, and log in.
- `assets/bitable-step-01-template-copy.png`
- Use when telling the user to open the direct bitable template link and create a copy.
- `assets/bitable-step-02-auth-code.png`
- Use when telling the user to open `多维表格插件` -> `自定义插件` and copy the authorization code.
- `assets/bitable-step-03-config-save.png`
The skill mandates a specific Chinese next-step prompt for users, and similar required Chinese quick-reply templates appear later in the file. This is a natural-language locale policy issue because the skill does not offer the user any language choice or document a justified locale restriction.
These sections prescribe exact Chinese-language prompts for authorization, quick replies, and custom configuration collection. Because the file does not provide an alternative language path or user opt-in, it enforces a specific locale in a way that violates the stated natural-language policy criterion.
Detected: suspicious.dangerous_exec