T09 · Insecure Skill Coding Practices
- Location
vwu-chat.sh:7- Finding
Arbitrary API Endpoint Can Receive Credentials and Prompt Data
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a straightforward vwu.ai chat client, but it can send the user's API key and prompt to any endpoint named in an undocumented environment variable.
Review this skill before installing. It appears intended to call vwu.ai models, but only use it in an environment where VWU_BASE_URL cannot be tampered with, avoid putting secrets in prompts, and consider removing the endpoint override and API-key-prefix logging before routine use.
vwu-chat.sh:7Arbitrary API Endpoint Can Receive Credentials and Prompt Data
vwu-chat.sh:31Unescaped User Input Is Interpolated into a JSON Request
vwu-chat.sh:44API Key Prefix Is Disclosed in Error Output
Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.
# 调用模型
vwu-chat --model gemini-2.5-flash "你的问题"
The markdown content is written entirely in Chinese and does not state that the skill is region-specific or that users may choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.
The script's comments and all user-facing messages are written in Chinese, including usage and error guidance. This imposes a specific language on users without offering a language choice or documenting that the tool is intentionally region-specific, which matches the locale-policy concern for natural-language policy violations.
The script transmits user-supplied prompt data and an API bearer token to a remote service via curl. This is expected for an API client, but it still creates a real data-exposure boundary: sensitive prompts may be sent off-host, and allowing the base URL to be overridden means credentials could be exfiltrated to an unintended endpoint if the environment is tampered with.
fi
# 调用 API
response=$(curl -s "$VWU_BASE_URL/v1/chat/completions" \
-H "Content-Type: application/json" \
-H "Authorization: Bearer $VWU_API_KEY" \
-d "{
No suspicious patterns detected.