T09 · Insecure Skill Coding Practices
- Location
skill.md:18- Finding
Caller-Controlled API Endpoint Allows Signed Requests to Be Sent to Untrusted Hosts
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This UCloud resource-creation skill is mostly coherent, but it asks the agent to handle powerful cloud credentials and caller-provided API URLs in ways that need careful review before use.
Install only if you are comfortable letting an agent create UCloud resources after confirmation. Use a restricted sub-account key, rotate it after testing, avoid entering broad account private keys in chat or ordinary tool arguments, and ensure the endpoint is fixed or validated to the real UCloud API host before signing requests.
skill.md:18Caller-Controlled API Endpoint Allows Signed Requests to Be Sent to Untrusted Hosts
skill.md:26Long-Lived Cloud Private Key May Be Exposed Through Agent Inputs, Transcripts, or Telemetry
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
- name: api_endpoint
type: string
required: true
description: "UCloud API 的完整请求 URL。示例:https://api.ucloud.cn/?Action=CreateUHostInstance"
- name: public_key
type: string
required: true
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
- name: api_endpoint
type: string
required: true
description: "UCloud API 的完整请求 URL。示例:https://api.ucloud.cn/?Action=CreateUHostInstance"
- name: public_key
type: string
required: true
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
- name: api_endpoint
type: string
required: true
description: "UCloud API 的完整请求 URL。示例:https://api.ucloud.cn/?Action=CreateUHostInstance"
- name: public_key
type: string
required: true
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
- name: api_endpoint
type: string
required: true
description: "UCloud API 的完整请求 URL。示例:https://api.ucloud.cn/?Action=CreateUHostInstance"
- name: public_key
type: string
required: true
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
- name: api_endpoint
type: string
required: true
description: "UCloud API 的完整请求 URL。示例:https://api.ucloud.cn/?Action=CreateUHostInstance"
- name: public_key
type: string
required: true
The skill supports high-risk actions such as creating API keys, but the description does not prominently warn that these operations can create durable credentials and expand access. Without explicit risk messaging and stricter confirmation, a user or upstream agent may treat key creation like a routine action and accidentally mint secrets with broad privileges.
The trigger phrases are broad enough that ordinary user requests containing '创建' or similar wording could invoke this skill even when the user did not clearly intend UCloud resource creation. In an agent environment with tool auto-selection, that can lead to unintended provisioning actions, cost-incurring operations, or creation of sensitive resources such as API keys.
No suspicious patterns detected.