T09 · Insecure Skill Coding Practices
- Location
reference/account-auth.md:123- Finding
Authentication Token Exposure Through Custom URLs and Process Arguments
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This documentation-only skill is coherent for Ziniao SSO integration, but it needs review because it normalizes sensitive SSO tokens in URLs and command arguments without adequate safety guidance.
Review this before installing or using it in an agent workflow. Treat API_Key, appAuthToken, and openapiToken as secrets; do not log full Schema URLs, paste them into shared channels, store them in command history, screenshots, support bundles, or analytics, and prefer the documented no-token local-login path where available. Require explicit user/admin approval before using debug ports, forced download paths, or no-prompt download behavior, and handle returned employee/account data as sensitive business data.
reference/account-auth.md:123Authentication Token Exposure Through Custom URLs and Process Arguments
The manifest description is written as an instruction in Chinese and does not indicate that other languages are supported or that the user may choose a preferred language. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.
This markdown file includes example requests that transmit Authorization: Bearer {API_Key} and later describes retrieval of a user login token, but it does not warn readers that these credentials are sensitive secrets that should not be logged, shared, or embedded insecurely. Because the document directly instructs users how to obtain and use auth tokens, a user-facing warning about credential handling is expected under the missing-warning criteria for markdown files.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl --location 'https://sbappstoreapi.ziniao.com/openapi-router/auth/get_app_token' \
--header 'Authorization: Bearer {API_Key}' \
--header 'Content-Type: application/json' \
--data-raw ''
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl --location 'https://sbappstoreapi.ziniao.com/openapi-router/superbrowser/rest/v1/token/user-login' \
--header 'Authorization: Bearer {API_Key}' \
--header 'Content-Type: application/json' \
--data-raw '{"companyId":"15393571083459","userId":"15393571087094"}'
This document describes APIs that enumerate employees, user IDs, phone numbers, account names, device IPs, and platform login identifiers, but provides no privacy, data-minimization, or access-control handling guidance. In an agent skill context, this can normalize collection and propagation of sensitive organizational data and increase the risk of unauthorized querying or mishandling by downstream users or agents.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl --location 'https://sbappstoreapi.ziniao.com/openapi-router/superbrowser/rest/v1/erp/staff/list' \
--header 'Authorization: Bearer {API_Key}' \
--header 'Content-Type: application/json' \
--data-raw '{
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl --location 'https://sbappstoreapi.ziniao.com/openapi-router/superbrowser/rest/v1/erp/store/list' \
--header 'Authorization: Bearer {API_Key}' \
--header 'Content-Type: application/json' \
--data-raw '{
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl --location 'https://sbappstoreapi.ziniao.com/openapi-router/superbrowser/rest/v1/erp/user/stores' \
--header 'Authorization: Bearer {API_Key}' \
--header 'Content-Type: application/json' \
--data-raw '{
The documentation explicitly describes a mode that suppresses the download path prompt and can force files into a specified directory. In an agent-consumable skill, this lowers user visibility and consent around filesystem writes, which can enable silent download behavior if an integrator or downstream automation uses these parameters without additional safeguards.
No suspicious patterns detected.