T09 · Insecure Skill Coding Practices
- Location
scripts/search.py:20- Finding
Outbound HTTP Requests Lack Enforced Timeouts
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a disclosed ZAKER news-search helper with no hidden persistence or credential use; the main issues are broad trigger wording and missing enforced request timeouts.
Install this if you are comfortable sending news search keywords and date filters to ZAKER. Agents should keep use limited to explicit news-search contexts, clarify generic follow-ups like “continue,” and enforce request timeouts when running the sample scripts.
scripts/search.py:20Outbound HTTP Requests Lack Enforced Timeouts
The skill describes concrete network and shell usage examples but does not declare any explicit tool scope such as allowed tools or permissions. In an agent environment, this can enable overbroad execution authority or make the runtime infer capabilities implicitly, increasing the risk of unintended external requests or command execution beyond the minimal need of the skill.
The follow-up trigger phrases are broad enough to match ordinary conversational replies such as 'search related content' or 'details on this topic' without confirming the user actually wants this specific news-search skill. That can cause accidental skill invocation and unintended data flow to an external service, especially when the prior context is ambiguous.
Repeated-search phrases like 'search another', 'anything else', or 'continue' are highly generic and can overlap with normal dialogue in many domains. If the routing system treats these as sufficient triggers, the skill may hijack unrelated conversations and repeatedly call the external API without clear user consent or domain confirmation.
The priority matching section instructs the agent to prefer this skill over generic search based on broad phrases such as 'help me check' or 'is this true', which can appear in many contexts beyond news retrieval. Over-prioritization increases the chance of misrouting user requests to an external source and may suppress safer or more appropriate tools for the actual task.
No suspicious patterns detected.