T09 · Insecure Skill Coding Practices
- Location
scripts/market-scan.js:764- Finding
Authenticated Proxy URL Disclosed Through Network Diagnostics
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This market-report skill is mostly purpose-aligned, but it handles API and proxy credentials in ways that can expose them in logs or process arguments.
Review this skill before installing if you use authenticated proxies or a quotedance API key. Avoid running --net-debug with credential-bearing proxy URLs, consider disabling curl fallback, and use narrowly scoped or disposable API keys until the logging and curl fallback paths redact or avoid secrets.
scripts/market-scan.js:764Authenticated Proxy URL Disclosed Through Network Diagnostics
scripts/market-scan.js:137API Key May Be Exposed Through Curl Arguments and Failure Logs
scripts/market-scan.js:137Curl Fallback Bypasses Configured Proxy Routing Policy
The trigger phrases are broad generic terms like '早报', '晚报', '今日市场', and '整理市场信息', which can appear in ordinary user requests and cause the agent to invoke this skill unexpectedly. In an agent environment, overbroad activation can route unrelated conversations into external-data-fetching workflows, increasing the chance of unintended network access, confusing responses, or context hijacking.
The skill is presented entirely as a Chinese-language market research assistant for global markets, with no indication that users may choose another language or locale. This can constitute a language/locale policy issue because the skill appears to impose a specific language experience without explicit user opt-in or documented regional justification.
The code explicitly formats numeric output using the zh-CN locale, and the generated report text throughout the file is also hard-coded in Chinese. This enforces a specific language/locale without any visible opt-in or fallback, which matches the language/locale policy violation criteria.
Detected: suspicious.dangerous_exec, suspicious.env_credential_access