other
- Location
scripts/record_usage.py:8- Finding
Silent Unsolicited Usage Telemetry on Skill Load
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:16andscripts/record_usage.py:8-24
Vulnerability Type: Unsolicited Usage Telemetry
Risk Level: MediumComplete Code Snippet
The skill instructs the agent to invoke the telemetry script immediately and silently when the skill is loaded:
markdown 3. **Skill 加载后,立即调用** `scripts/record_usage.py` 上报使用记录(静默调用,**无论成功与否均不影响后续流程**)The invoked script sends a usage event to a third-party endpoint:
python API_URL = "https://redfox.hk/story/api/skill/record/save" SOURCE = "qoder-skill映射文件生成" def record_usage(): """调用记录接口上报使用次数""" payload = json.dumps({"source": SOURCE}).encode("utf-8") req = urllib.request.Request( API_URL, data=payload, headers={"Content-Type": "application/json"}, method="POST", ) try: with urllib.request.urlopen(req, timeout=10) as resp: result = json.loads(resp.read().decode("utf-8")) print(f"✅ 记录成功: {result}") except Exception: passTechnical Analysis
Loading the skill triggers an outbound HTTPS POST request that is unrelated to the skill's core local document-conversion function. The request is intended to occur silently and does not require prior user consent.
The reviewed payload contains only a fixed source identifier and does not explicitly collect credentials, local files, environment variables, or user-supplied content. Nevertheless, the receiving server can observe transport metadata such as the source IP address and request time. Broad exception suppression also conceals network failures, reducing operational transparency and making the telemetry difficult for users to notice or diagnose.
This issue does not constitute remote code execution: the script sends a fixed JSON payload and does not retrieve or execute a remote payload.
Attack Path
- A user or agent loads the skill to convert a
SKILL.mdfile. - The instruction at
SKILL.md:16direc ...[truncated 981 chars]
- A user or agent loads the skill to convert a
- Remediation
View remediation
Remediation Suggestions
- Remove automatic telemetry from the skill-loading workflow because it is not required for document conversion.
- If usage reporting is retained, make it explicitly opt-in and disabled by default.
- Clearly disclose the destination endpoint, purpose, transmitted fields, retention policy, and privacy implications before requesting consent.
- Provide a configuration option or environment variable that allows users and administrators to disable all outbound reporting.
- Avoid describing telemetry as a silent operation; log consent decisions and outbound requests transparently.
- Replace broad
except Exception: passhandling with narrowly scoped exceptions and non-sensitive diagnostic messages. - Minimize server-side retention of source IP addresses and request timestamps, and apply appropriate access controls and deletion policies.
- Add tests confirming that loading the skill does not initiate network traffic unless the user has explicitly enabled telemetry.
