T09 · Insecure Skill Coding Practices
- Location
scripts/query-knowledge.py:32- Finding
API Credential May Be Disclosed to an Unintended External Provider
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a plausible water-equipment knowledge assistant, but it needs review because it stores sensitive interaction data and has an under-disclosed third-party credential/query data flow.
Review before installing. Use provider-specific credentials, do not place a real OpenAI key in this configuration unless the embedding endpoint is corrected, and assume quote details, prompts, tool data, and retrieval snippets may be written to local logs. Enable cron only if you want recurring background updates, and restrict the configured file paths and log access to trusted users.
scripts/query-knowledge.py:32API Credential May Be Disclosed to an Unintended External Provider
scripts/audit-logger.py:58Unredacted User Inputs and Tool Data Are Stored in Plaintext Audit Logs
The logger persists raw user input, tool inputs, tool outputs, user identifiers, and retrieval metadata directly to disk, which can capture sensitive data such as personal information, secrets, internal documents, and model/tool outputs. In an agent skill context this is particularly risky because these fields may include prompts, credentials, proprietary retrieval results, or regulated data, and the code provides no minimization, redaction, consent, retention control, or access protection.
The audit configuration states that user input, output, session identifiers, user identifiers, and tool activity are logged, but the skill provides no visible warning to users that their interactions are being recorded at this granularity. This creates a privacy and compliance risk because sensitive prompts, personal data, or business information may be captured and retained unexpectedly.
The skill explicitly asks users to provide personal and business contact details such as company, contact person, and phone number to generate a quote draft, but it does not present any privacy notice, purpose limitation, retention policy, or handling instructions. In the same file, the skill also enables detailed audit logging, which increases the chance that submitted personal data will be stored and processed without informed user consent or clear safeguards.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
# 在Linux/macOS上
crontab -e
# 添加以下内容
0 2 * * * python /path/to/water-knowledge-assistant/scripts/knowledge_base_import.py
0 3 * * * python /path/to/water-knowledge-assistant/scripts/tavily_update.py
Natural-language content throughout the file, including comments, docstrings, and printed messages, is written exclusively in Chinese. Under the policy, forcing a single language without opt-in or clear region-specific justification is a locale/language policy issue.
With no manifest available, the skill's intended scope is unknown, so external network access and likely use of API credentials from environment variables are not justified by any declared purpose. The code creates OpenAI-compatible embeddings against an Alibaba DashScope endpoint, which transmits user queries off-box and depends on secrets loaded from the environment.
The script sends user-supplied query text to an external embedding API without any warning, consent flow, or data-sensitivity check. If users enter proprietary, personal, or regulated data, that content may be disclosed to a third party unexpectedly, creating confidentiality and compliance risk.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
def tavily_search(query, max_results=5, time_range="year", include_domains=None):
"""调用 Tavily API 进行搜索"""
url = "https://api.tavily.com/search"
headers = {
"Content-Type": "application/json",
}
This code transmits query data to an external API endpoint, which is expected behavior for a search integration, but it still creates a real data-exposure boundary. In this skill, the danger is increased because the same function can be reached with user-derived input and there are no safeguards around sensitive data, consent, or logging of what was sent.
}
try:
response = requests.post(url, headers=headers, json=data)
response.raise_for_status()
return response.json()
except Exception as e:
The on_demand_update function forwards raw user_query content to the external Tavily API whenever trigger words are present, without user notice, consent, or minimization. This can expose sensitive user-entered data to a third party unexpectedly, especially in an assistant or skill context where users may not realize their prompt is being transmitted off-platform.
The description forces a specific language/locale presentation without indicating user choice or that the skill is intentionally limited to a Chinese-speaking or region-specific audience. Under the stated policy, language constraints should either be optional for the user or clearly justified.
The entire skill file is written in Chinese and does not indicate that language selection is optional or that the content is intentionally limited to a Chinese-speaking or region-specific audience. Under the stated policy, forcing a specific language without user opt-in can constitute a natural-language policy violation.
This markdown file presents all headings, field names, and descriptions exclusively in Chinese, which can amount to a language policy violation if users are not given a choice of locale. There is no indication that the file is intentionally region-specific or that non-Chinese users can opt into another language.
This markdown file contains user-facing natural language only in Chinese, which can amount to a language/locale policy issue when no opt-in or alternative language is provided. The content does not indicate that the skill is region-specific or that the user can choose another language.
This code contains natural-language strings and comments exclusively in Chinese, including status and error messages shown to the user. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.
The script's visible output, usage instructions, and error messages are all fixed in Chinese. This creates a language/locale constraint without any opt-in, fallback, or documentation indicating that the skill is intentionally region-specific.
Comments, status prints, and returned messages are written in Chinese throughout the script, which effectively forces a specific language for user-visible behavior. There is no opt-in, language selection, or documented justification that this skill is intended only for a Chinese-language context.
No suspicious patterns detected.