T09 · Insecure Skill Coding Practices
- Location
references/deploy-config.md:61- Finding
Deployment Credentials and Artifacts Transmitted over Plaintext FTP
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly matches a Vue 2 to Vite migration workflow, but its optional deployment instructions include plaintext FTP credential use and remote production upload behavior that users should review carefully.
Install only if you are comfortable with a migration assistant that may delete old build files after confirmation. Avoid using the bundled FTP deployment recipe as written; replace it with SFTP/HTTPS/CI deployment, least-privilege credentials, and explicit production approval.
references/deploy-config.md:61Deployment Credentials and Artifacts Transmitted over Plaintext FTP
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 临时设置(单次部署)
STAGE_FTP_USER=myuser STAGE_FTP_PASSWORD=mypass STAGE_FTP_HOST=ftp.example.com STAGE_FTP_REMOTE_ROOT=/staging/ pnpm run upload:stage
# 或通过 .env.local 文件(需已加入 .gitignore)
# 在 .env.local 中写入:
# STAGE_FTP_USER=myuser
# STAGE_FTP_PASSWORD=mypass
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 临时设置(单次部署)
STAGE_FTP_USER=myuser STAGE_FTP_PASSWORD=mypass STAGE_FTP_HOST=ftp.example.com STAGE_FTP_REMOTE_ROOT=/staging/ pnpm run upload:stage
# 或通过 .env.local 文件(需已加入 .gitignore)
# 在 .env.local 中写入:
# STAGE_FTP_USER=myuser
# STAGE_FTP_PASSWORD=mypass
The skill includes destructive file-deletion commands (git rm -rf build/ config/) that can modify or remove project files when followed by an agent or user. Although the instructions add some safety checks and use Git to make recovery easier, this is still dangerous in an agent skill because it encourages automated destructive actions based on path assumptions and current working directory state.
# 删除 Webpack 构建目录
git rm -rf build/ config/
# 删除 Babel/PostCSS 配置
git rm -f .babelrc .postcssrc.js babel.config.js
# 删除旧锁文件(pnpm 项目不需要 npm/yarn 锁文件)
The raw rm -rf build/ config/ instructions are irreversible and can cause substantial data loss if executed in the wrong directory or against a misidentified project. In a skill context, this is more dangerous because agents may operationalize the commands without sufficient environmental validation, turning documentation into an unsafe action recipe.
如果项目未纳入 Git 版本控制,使用以下命令(不可撤销,执行前务必确认):
rm -rf build/ config/
rm -f .babelrc .postcssrc.js babel.config.js
rm -f package-lock.json yarn.lock
The document title and all instructional content are written exclusively in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the policy, a skill that implicitly forces a specific language without opt-in is a natural-language policy concern.
The manifest describes this skill as upgrading Vue 2 + Webpack projects to Vite and handling related build/env compatibility issues. The documented scripts add packaging and remote deployment actions (upload:*, deploy:*) that publish build artifacts to an FTP server, which is a separate deployment capability not implied by migration-to-Vite work.
The skill includes remote artifact upload and credential-driven deployment logic that is not necessary for a Vite migration task, increasing the attack surface and enabling unintended publication of build artifacts. Although credentials are read from environment variables rather than hardcoded, bundling deployment capability into an upgrade skill can normalize risky execution of remote operations without strong justification or safeguards.
This markdown file imposes a specific language for all instructions, examples, and warnings, and does not provide any user opt-in, alternative language, or justification that it is intended only for a Chinese-speaking audience. That matches the language/locale policy concern for natural-language content.
This markdown file contains user-facing operational instructions exclusively in Chinese, including deployment steps and safety guidance. Under the policy rule for language/locale constraints, forcing a single language without user opt-in or justification can be considered a natural-language policy violation.
This markdown file is natural-language content, so locale-policy checks apply. The title and all surrounding instructional text are presented only in Chinese, which can imply a fixed language expectation without user opt-in or any documented justification for a Chinese-only scope.
No suspicious patterns detected.