T09 · Insecure Skill Coding Practices
- Location
scripts/understand_image.py:13- Finding
Configurable MiniMax Endpoint Can Exfiltrate Image Data and API Credentials
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This image-understanding skill is mostly purpose-aligned, but it needs Review because it can upload any chosen local file to external APIs and can send MiniMax data and credentials to an unvalidated custom host.
Install only if you are comfortable sending selected images and prompts to MiniMax, OpenAI, or Anthropic. Do not use it on confidential screenshots, credentials, regulated documents, or private files unless your policy permits that upload. Avoid setting MINIMAX_API_HOST to anything other than the intended trusted MiniMax endpoint, and prefer a version that validates image files, limits file size and path scope, and confirms before upload.
scripts/understand_image.py:13Configurable MiniMax Endpoint Can Exfiltrate Image Data and API Credentials
scripts/understand_image.py:18Missing Image Validation Allows Arbitrary Local File Transmission
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
"max_tokens": 1000
}
resp = requests.post("https://api.openai.com/v1/chat/completions", headers=headers, json=payload, timeout=60)
data = resp.json()
if "choices" in data and data["choices"]:
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
]
}
resp = requests.post("https://api.anthropic.com/v1/messages", headers=headers, json=payload, timeout=60)
data = resp.json()
if "content" in data:
The skill documents code execution that can access environment variables, invoke a Python script, and send data over the network, but it does not declare any explicit tool scope or permissions. This weakens reviewability and least-privilege controls, making it easier for an agent or operator to invoke capabilities beyond what is clearly disclosed.
The skill instructs users to submit local images to external providers such as MiniMax, OpenAI, or Anthropic, but gives no warning that screenshots, documents, or photos may contain sensitive data that will leave the local environment. In this context, the skill is specifically intended for screenshots, charts, and document photos, which often contain confidential business or personal information, so omission of a privacy warning materially increases the risk of inadvertent data exfiltration.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
"-d", json.dumps(payload)
]
result = subprocess.run(cmd, capture_output=True, text=True, timeout=35)
data = json.loads(result.stdout)
if data.get("base_resp", {}).get("status_code") == 0:
The MiniMax path sends the full image to an external API via curl with no disclosure or confirmation, creating a direct path for unintended data sharing. This is especially risky in the skill context because screenshots and document photos often contain secrets, internal metrics, customer data, or other sensitive business information.
The command arguments include API_HOST sourced from an environment variable, so the script can be induced to send the full image payload and bearer token to an attacker-controlled endpoint. This is not classic code execution because shell expansion is not used, but it is still a real SSRF/data-exfiltration style issue when untrusted environment configuration is possible.
"-d", json.dumps(payload)
]
result = subprocess.run(cmd, capture_output=True, text=True, timeout=35)
data = json.loads(result.stdout)
if data.get("base_resp", {}).get("status_code") == 0:
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"max_tokens": 1000
}
resp = requests.post("https://api.openai.com/v1/chat/completions", headers=headers, json=payload, timeout=60)
data = resp.json()
if "choices" in data and data["choices"]:
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"max_tokens": 1000
}
resp = requests.post("https://api.openai.com/v1/chat/completions", headers=headers, json=payload, timeout=60)
data = resp.json()
if "choices" in data and data["choices"]:
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"max_tokens": 1000
}
resp = requests.post("https://api.openai.com/v1/chat/completions", headers=headers, json=payload, timeout=60)
data = resp.json()
if "choices" in data and data["choices"]:
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"max_tokens": 1000
}
resp = requests.post("https://api.openai.com/v1/chat/completions", headers=headers, json=payload, timeout=60)
data = resp.json()
if "choices" in data and data["choices"]:
The function base64-encodes the supplied image and transmits it to OpenAI without any user-facing disclosure, consent check, or sensitivity gating. For a skill designed to process screenshots, charts, and document photos, this can expose confidential business data, personal data, credentials, or regulated content to a third-party processor unexpectedly.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
]
}
resp = requests.post("https://api.anthropic.com/v1/messages", headers=headers, json=payload, timeout=60)
data = resp.json()
if "content" in data:
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
]
}
resp = requests.post("https://api.anthropic.com/v1/messages", headers=headers, json=payload, timeout=60)
data = resp.json()
if "content" in data:
The Anthropic path uploads raw image content to an external model provider without warning the user that the file leaves the local environment. Because the skill's purpose is image understanding of potentially sensitive business artifacts, the lack of notice and approval materially increases privacy and data-handling risk.
The visible user-facing description and instructions are entirely in Chinese, which can impose a language constraint on users without opt-in. The file does not indicate that the skill is region-specific or offer alternative language support.
The module description and user-facing strings are written in Chinese, and the default prompt also enforces Chinese output behavior, without indicating that other languages are supported or that Chinese is a required locale. Under the policy, forcing a specific language without opt-in can be a natural-language policy concern.
No suspicious patterns detected.