T09 · Insecure Skill Coding Practices
- Location
scripts/extract.js:104- Finding
Arbitrary File Write Through Untrusted Download Filenames and Weak Path Containment
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This TeraBox skill is mostly purpose-aligned, but its download mode can write untrusted remote files outside the intended folder and its third-party data sharing is inconsistently disclosed.
Review before installing. Use this only with non-sensitive TeraBox links unless you are comfortable sending the full URL and your XAPIverse API key to xapiverse.com. Avoid CLI --download mode until filenames, output-path containment, allowed download hosts, redirect limits, and size/time limits are fixed.
scripts/extract.js:104Arbitrary File Write Through Untrusted Download Filenames and Weak Path Containment
scripts/extract.js:40Unrestricted API-Provided Download URLs and Redirects Enable SSRF and Resource Exhaustion
The README promotes browser-less direct extraction and streaming through the XAPIverse API but does not disclose that user-provided TeraBox URLs will be sent to a third-party service. This omission is dangerous because such URLs may contain sensitive file references, access tokens, or private content identifiers, and users or operators are not warned about the privacy and data-sharing implications.
The README says the skill is 'automatically triggered by the agent' for 'any valid TeraBox URL' without defining narrow invocation conditions, confirmation requirements, or trust boundaries. In an agent environment, this broad trigger can cause unintended transmission of user-supplied links to an external service, increasing the chance of accidental data disclosure or misuse.
The skill declares access to sensitive environment data (TERABOX_API_KEY) but does not define an explicit tool scope such as permissions or allowed-tools. This weakens least-privilege controls and makes it easier for the skill to access or expose secrets through code paths that are not clearly constrained or reviewable.
The skill states that the full target URL and the API key are transmitted to xapiverse.com, but only promises to disclose this 'if asked'. Because URLs may contain private file identifiers, tokens, or personal data, failing to proactively warn users undermines informed consent and can lead to unintended third-party disclosure of both user data and a sensitive credential.
The changelog explicitly records a version that optimized the skill to make the LLM trigger extraction automatically, which conflicts with informed-consent expectations for sending user-provided URLs to a third-party API. In this skill's context, automatic transmission is more dangerous because the skill handles external links and may disclose user-shared content to an external service without a clear permission step.
The script sends the user-supplied TeraBox URL to xapiverse.com, a third-party service, without any in-script disclosure, consent prompt, or data-minimization checks. If the URL contains sensitive share tokens, identifiers, or private content references, users may unknowingly disclose that data to an external provider.
The manifest description is narrowly framed around extracting high-speed download and stream links from TeraBox URLs. In addition to extraction, the implementation includes a full file-download path that fetches remote content and writes it to disk, which is a materially broader behavior than link extraction alone.
The handler reads ctx.env.TERABOX_API_KEY, which is access to a credential-like environment variable. In this code file there is no confirmation prompt, user-facing log, or explanatory comment/docstring disclosing that the skill uses an API key.
The manifest presents the skill as a direct-link extractor for user-supplied TeraBox URLs, but the implementation depends on a TERABOX_API_KEY secret loaded from the environment. Using service credentials may be a valid implementation detail, but it is still an additional capability not evident from the stated scope and could matter for deployment trust assumptions.
In download mode, the script writes files from externally supplied download URLs and uses file.name from remote API output directly in the destination path. Although the output directory is constrained under Downloads, an attacker-controlled filename containing path separators could traverse outside that directory, causing arbitrary file overwrite within the user's permissions.
No suspicious patterns detected.