T09 · Insecure Skill Coding Practices
- Location
vwu-chat.sh:7- Finding
Configurable API Endpoint Can Disclose Bearer Credentials and Prompt Data
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a simple vwu.ai chat API wrapper, but it can send your API key and prompt to an arbitrary endpoint if the environment sets a custom base URL.
Use this only if you are comfortable sending prompts to vwu.ai. Keep VWU_BASE_URL unset unless you intentionally trust the alternate HTTPS endpoint, avoid putting secrets in prompts, and rotate the API key if the script may have run with an untrusted base URL. Expect problems with quotes or multiline prompts until the script uses proper JSON serialization.
vwu-chat.sh:7Configurable API Endpoint Can Disclose Bearer Credentials and Prompt Data
vwu-chat.sh:31Unescaped Input Allows JSON Request-Body Injection
The file’s instructional content and examples are presented only in Chinese, which effectively forces a specific language for users without any opt-in or alternative. Under the stated policy, language constraints should either be optional for users or clearly documented as justified for a region-specific skill.
The script's comments and all user-facing output are written in Chinese, including error and usage messages. This imposes a specific language on users without offering a language choice or documenting that the tool is intentionally region-specific, which matches the language/locale policy violation criteria.
The script sends user-supplied prompt data and an API bearer token to an external service endpoint via curl. External transmission is expected for an API client, but it still creates real security risk because prompts may contain sensitive data and the destination URL is overridable through VWU_BASE_URL, which could exfiltrate both prompts and the API key to an unintended host if misconfigured or manipulated.
fi
# 调用 API
response=$(curl -s "$VWU_BASE_URL/v1/chat/completions" \
-H "Content-Type: application/json" \
-H "Authorization: Bearer $VWU_API_KEY" \
-d "{
No suspicious patterns detected.