T09 · Insecure Skill Coding Practices
- Location
src/security-guard.js:64- Finding
High-Risk Operations Are Marked Allowed Before Confirmation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a security guard, but several advertised protections can silently fail or be bypassed, so users should review it before relying on it.
Install only if you are prepared to review or fix the security-control gaps first. Do not rely on this package as an enforcement boundary for high-risk operations, custom role policies, blocked content patterns, or output redaction without additional safeguards. Also confirm where audit logs are stored, what metadata they contain, and how long they are retained.
src/security-guard.js:64High-Risk Operations Are Marked Allowed Before Confirmation
src/permission-manager.js:10Configured Authorization Roles and Strict Mode Are Ignored
src/content-safety.js:28Configured Blocked Patterns Produce Warnings but Do Not Block Input
src/security-guard.js:123Output Safety and Redaction Are Not Applied by the Security Guard
This code records potentially sensitive metadata such as userId, IP address, userAgent, actions, resources, and arbitrary details, then persists them to disk. Although the file has internal comments describing audit logging, it lacks any confirmation prompt or user-facing disclosure warning that user/system activity will be collected and stored.
This JavaScript file uses Chinese-only natural-language descriptions in the header comments and key inline comments, such as "内容安全审查" and later operational annotations. For a general-purpose skill file, this imposes a specific language/locale without offering user choice or documenting that the skill is intentionally region-specific.
The code defines both requireConfirmation() and isHighRiskAction(), but there is no enforcement path in checkPermission() or elsewhere that requires confirmation before allowing high-risk actions. This creates a security-control gap where dangerous operations may proceed based solely on role permissions, despite the interface implying an additional approval step.
Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.
permissions: {
defaultRole: 'user',
roles: {
admin: { permissions: ['*'] },
user: { permissions: ['file:read', 'file:write:home'] },
guest: { permissions: ['file:read:home'] }
}
Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.
permissions: {
defaultRole: 'user',
roles: {
admin: { permissions: ['*'] },
user: { permissions: ['file:read', 'file:write:home'] },
guest: { permissions: ['file:read:home'] }
}
Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.
permissions: {
defaultRole: 'user',
roles: {
admin: { permissions: ['*'] },
user: { permissions: ['file:read', 'file:write:home'] },
guest: { permissions: ['file:read:home'] }
}
Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.
permissions: {
defaultRole: 'user',
roles: {
admin: { permissions: ['*'] },
user: { permissions: ['file:read', 'file:write:home'] },
guest: { permissions: ['file:read:home'] }
}
The package description is entirely in Chinese, which can imply a fixed language expectation for the skill without offering any language or locale choice. The policy specifically calls for flagging language or locale constraints when they are imposed without opt-in or justification.
The cleanup routine automatically deletes older log files once the retention limit is exceeded. While log rotation is expected for an audit logger, the code does not include a visible warning, confirmation, or documented notice that persisted audit history may be removed automatically.
This code file contains user- and maintainer-facing natural language such as the header and method documentation in Chinese, while other descriptive strings are in English. Under the policy rule, forcing a specific language without opt-in can be a locale/language policy issue when no justification or language choice is provided.
This code file contains natural-language comments and descriptions entirely in Chinese, such as the module header and method documentation, without any indication that the skill is region-specific or that another language is available. Under the policy rule, forcing a specific language without user opt-in can be a locale-policy violation when no justification or alternative is provided.
This JavaScript file contains natural-language strings and comments entirely in Chinese, including the file header and inline section labels, without any indication that the skill is region-specific or that users may choose another language. Under the language/locale policy rule, forcing a specific language without opt-in can be a policy violation when no justification is provided.
Skill requests more permissions than appear necessary for its stated functionality. Review if elevated access is justified.
permissions: {
defaultRole: 'user',
roles: {
admin: { permissions: ['*'] },
user: { permissions: ['file:read', 'file:write:home'] },
guest: { permissions: ['file:read:home'] }
}
Skill requests more permissions than appear necessary for its stated functionality. Review if elevated access is justified.
permissions: {
defaultRole: 'user',
roles: {
admin: { permissions: ['*'] },
user: { permissions: ['file:read', 'file:write:home'] },
guest: { permissions: ['file:read:home'] }
}
Skill requests more permissions than appear necessary for its stated functionality. Review if elevated access is justified.
permissions: {
defaultRole: 'user',
roles: {
admin: { permissions: ['*'] },
user: { permissions: ['file:read', 'file:write:home'] },
guest: { permissions: ['file:read:home'] }
}
Skill requests more permissions than appear necessary for its stated functionality. Review if elevated access is justified.
permissions: {
defaultRole: 'user',
roles: {
admin: { permissions: ['*'] },
user: { permissions: ['file:read', 'file:write:home'] },
guest: { permissions: ['file:read:home'] }
}
No suspicious patterns detected.