Back to skill

Security audit

vwu.ai gemini Models

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward vwu.ai chat client, but it can send the user's API key and prompt to any endpoint named in an undocumented environment variable.

Review this skill before installing. It appears intended to call vwu.ai models, but only use it in an environment where VWU_BASE_URL cannot be tampered with, avoid putting secrets in prompts, and consider removing the endpoint override and API-key-prefix logging before routine use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
vwu-chat.sh:7
Finding

Arbitrary API Endpoint Can Receive Credentials and Prompt Data

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
vwu-chat.sh:31
Finding

Unescaped User Input Is Interpolated into a JSON Request

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
vwu-chat.sh:44
Finding

API Key Prefix Is Disclosed in Error Output

Content
View full analysis
/dev/null; then echo "" echo "⚠️ API key 额度不足!" echo "" echo "解决方法:" echo "1. 访问 https://vwu.ai 控制台" echo "2. 为当前 key 充值,或" echo "3. 生成新的 API key 并更新环境变量" echo "" echo "当前 key: ${VWU_API_KEY:0:8}***" fi ``` ### Technical Analysis When an API error message matches quota-related terms, the script prints the first eight characters of `VWU_API_KEY`. Terminal output is frequently captured by shell transcripts, CI/CD logs, orchestration systems, monitoring agents, or support bundles. Masking only the suffix does not eliminate credential exposure. The disclosed prefix reduces the unknown credential space and may reveal account, environment, or token-format information. It can also allow the credential to be correlated across otherwise separate logs. When combined with the unvalidated `VWU_BASE_URL`, an attacker-controlled endpoint can deliberately return a quota-related error to cause this partial disclosure in captured output. ### Attack Path 1. A quota-related API error occurs naturally, or an attacker controlling the configured endpoint returns an error whose message includes a matching term such as `quota`. 2. The script identifies the response as a quota error. 3. It prints the first eight API-key characters to standard output. 4. A user, process, log collector, or attacker with access to execution logs reads the disclosed prefix. ### Impact Assessment The issue discloses only a prefix rather than the complete API key, so it does not independently prove that an attacker can authenticate. Nevertheless, it weakens credential confidentiality, facilitates token correlation, and may assist guessing attacks depending on the credential format and remaining ...[truncated 189 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

bash
# 调用模型
vwu-chat --model gemini-2.5-flash "你的问题"

API 兼容性

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The markdown content is written entirely in Chinese and does not state that the skill is region-specific or that users may choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script's comments and all user-facing messages are written in Chinese, including usage and error guidance. This imposes a specific language on users without offering a language choice or documenting that the tool is intentionally region-specific, which matches the locale-policy concern for natural-language policy violations.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The script transmits user-supplied prompt data and an API bearer token to a remote service via curl. This is expected for an API client, but it still creates a real data-exposure boundary: sensitive prompts may be sent off-host, and allowing the base URL to be overridden means credentials could be exfiltrated to an unintended endpoint if the environment is tampered with.

Content

Scanner excerpt · vwu-chat.sh (reported line 32)May include surrounding context.

sh
fi

# 调用 API
response=$(curl -s "$VWU_BASE_URL/v1/chat/completions" \
    -H "Content-Type: application/json" \
    -H "Authorization: Bearer $VWU_API_KEY" \
    -d "{

Static analysis

No suspicious patterns detected.