T08 · Insecure Dependencies
- Location
SKILL.md:18- Finding
Unpinned SDK Installation from Mutable Package Repositories
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill matches its Famou experiment-management purpose, but it needs Review because it installs mutable packages, stores API keys insecurely, and can delete or resubmit experiments without clear confirmation.
Review before installing. Use this only in a controlled environment, prefer a pinned and verified famou-sdk install, avoid entering API keys through command-line arguments, check permissions on ~/.famou-ctl/settings.json, and require explicit confirmation before canceling, deleting, modifying, or resubmitting experiments.
SKILL.md:18Unpinned SDK Installation from Mutable Package Repositories
SKILL.md:45API Key Exposed Through Command-Line Arguments
scripts/config.py:48API Credential File Created Without Explicit Restrictive Permissions
声明描述的是一个面向 famou 实验任务生命周期管理的技能,触发场景集中在‘提交实验’、‘查看实验状态’、‘删除实验’、‘获取实验结果’等操作。但给出的代码只是在本地用户目录下读写配置文件 ~/.famou-ctl/settings.json,并输出 api_url、掩码后的 api_key,以及缺失字段检查结果。write 命令还会写入默认 api_url 和 user_id。整个代码没有任何与实验任务相关的网络请求、任务 ID 处理、状态查询、结果下载、删除操作或 config.yaml 上传逻辑。因此其实际主要用途与声明的核心用途明显不一致,属于实质性描述-行为不匹配。
The skill instructs actions that can modify local state, including installing packages and writing API configuration via scripts/config.py write, but it does not declare any tool restrictions or explicit permissions. In an agent environment, missing scope boundaries increases the chance the skill is invoked with broader-than-necessary file write capability, enabling unintended local changes or secret persistence.
The trigger phrases are overly broad, including generic terms like “提交” or “跑实验” whenever context mentions the platform, which can cause unintended invocation of a skill that performs installation, configuration, and potentially destructive experiment actions. Overbroad triggering increases the risk of the wrong workflow being activated and sensitive or state-changing commands being suggested or executed inappropriately.
The skill instructs the user to provide an API key and then passes it directly on the command line to a local script. Command-line arguments can be exposed through shell history, process listings, logs, or telemetry, making credential leakage more likely in shared or monitored environments.
The skill includes experiment deletion as a supported operation without requiring an explicit warning, confirmation, or verification step. In a workflow management context, deletion is destructive and may irreversibly remove experiment records, logs, or results if executed from mistaken context or against the wrong experiment ID.
This file includes natural-language docstrings, CLI help text, and status/error messages only in Chinese. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.
This skill includes credential configuration management even though the manifest describes experiment workflow management. Expanding scope to read and write local API credentials increases the trust and attack surface of the skill: a workflow-triggered skill can become a persistence point for secrets and may be invoked in broader contexts than users expect.
The code persistently stores the API key in ~/.famou-ctl/settings.json without any permission hardening, encryption, or use of the OS credential store. If the local machine is multi-user, backed up, synced, or otherwise accessible to other processes, the plaintext credential can be recovered and used to access the remote Famou service.
The natural-language instructions and user-facing behavior are entirely specified in Chinese, with no indication that the user may choose another language or locale. Under the language/locale policy, forcing a specific language without user opt-in is a policy concern unless the restriction is explicitly justified.
No suspicious patterns detected.