T09 · Insecure Skill Coding Practices
- Location
scripts/run.py:25- Finding
API credential disclosure through an attacker-controlled service endpoint
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is not plainly malicious, but it should be reviewed because it sends user image materials and an API key to a remote service while its diagnostic-versus-generation purpose and invocation scope are unclear.
Install only if you trust ai-skills.ai and the publisher with API-key-authenticated requests, uploaded/reference image materials, prompts, brand requirements, and profile context. Review or remove AISKILLS_BASE_URL overrides, use a limited-scope API key, and treat this as an externally processed image-generation/diagnosis workflow rather than a purely local image quality checker.
scripts/run.py:25API credential disclosure through an attacker-controlled service endpoint
ai-gpt-image-2/scripts/run.py:25Duplicated runner forwards API credentials to an unrestricted configurable endpoint
A second aspect of the mismatch is that the skillId-driven remote call is not verifiably tied to the specific promised visual-diagnostics function, so the real remote behavior is opaque. In security terms, opaque remote delegation plus credentialed access can enable unexpected data handling, billing actions, or outputs beyond user expectations.
A second aspect of the mismatch is that the skillId-driven remote call is not verifiably tied to the specific promised visual-diagnostics function, so the real remote behavior is opaque. In security terms, opaque remote delegation plus credentialed access can enable unexpected data handling, billing actions, or outputs beyond user expectations.
The manifest advertises a diagnostic skill that helps decide whether an existing image is ready to publish, but the actual form is built around generating new images with GPT Image 2. This mismatch can mislead users into providing the wrong inputs, receiving outputs they did not intend, and potentially bypassing review or approval workflows because the skill’s safety expectations do not match its real behavior.
The stated user intent asks whether an image is suitable for publication, but the form instructs users to submit generation requirements, reference images, and prompts for GPT Image 2. This contradiction creates a deceptive interaction surface where users may believe they are getting a compliance or quality assessment when they are actually invoking content generation, increasing the chance of unsafe publication decisions or unauthorized derivative content creation.
The schema solicits inputs for generating images (prompt text, reference uploads, public URLs, style/brand requirements), while the skill metadata describes an image quality diagnosis assistant. This mismatch can mislead users into providing different content than expected and can cause the agent to perform a materially different action than its declared purpose, undermining trust, consent, and review controls.
The skill advertises use of environment variables and an external API but does not declare any explicit tool scope or allowed-tools boundary. That makes the capability surface less transparent to reviewers and downstream users, increasing the chance that network access and secret-backed operations are invoked without informed approval.
The trigger language is broad enough that the skill may activate for loosely related image-quality questions without clear consent boundaries. In this context, over-broad activation is risky because activation can cause user-supplied images, URLs, and text to be forwarded to an external service unexpectedly.
The entire skill description, usage guidance, and examples are written only in Chinese, with no indication that users may interact in another language or that the skill is intentionally limited to a Chinese-language audience. Under the stated policy, forcing a specific language without opt-in can be a natural-language policy issue.
The 'when to use' section describes expansive, ambiguous conditions that could capture many marketing, media, and e-commerce image tasks. Because the skill relies on an external API, ambiguous boundaries raise the likelihood of accidental invocation and unintended disclosure of business-sensitive creative assets or campaign materials.
The documentation asks users to provide image URLs, files, and text materials but does not clearly warn that these inputs are sent to an external API for processing. This omission creates a meaningful privacy and confidentiality risk, especially for unpublished creatives, customer data, licensed assets, or internal brand materials.
The metadata and default prompt are entirely in Chinese and orient the skill toward a single locale without indicating user choice or fallback behavior. This can cause the system to respond in an unexpected language, mis-handle user intent, or silently reduce transparency and usability for non-Chinese users, especially if the skill is invoked implicitly.
The skill enables implicit invocation without any visible trigger constraints or scoping, which increases the chance the assistant will auto-select this skill in situations the user did not clearly request. Because this skill is an image-quality diagnostic assistant, unintended invocation could cause inappropriate routing of user input, privacy-sensitive image handling, or confusing outputs without explicit user consent.
The top-level skill description is broad enough to match many common image-related requests without clear limits, which can cause the agent to invoke this skill in situations the user did not specifically intend. Over-broad activation increases the chance of unnecessary external API use and accidental disclosure of user-provided image content, prompts, or business materials.
The 'when to use' section covers very common marketing, media, and ecommerce image tasks in a way that is too expansive, making accidental or excessive routing likely. In a tool that can accept links, files, and text for external processing, broad activation criteria increase the risk of sending sensitive assets or proprietary campaign materials when a narrower local response would suffice.
The skill instructs users to provide accessible URLs and uploaded materials that are sent to an external API, but it does not clearly warn that these materials will leave the local environment or may contain sensitive business, personal, copyright, or licensed content. This creates a real data-handling risk because users may share confidential images, product drafts, or internal brand assets without informed consent.
The manifest presents the skill name and description only in Chinese while the default prompt is written in English, but nowhere indicates that the user can choose or opt into a language/locale. This creates a language-policy concern because the skill appears to impose language behavior implicitly rather than documenting or offering a locale choice.
This JSON schema contains user-facing labels, placeholders, descriptions, and validation messages exclusively in Chinese. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified, which is not present here.
The user-facing question, skill name, placeholders, labels, and descriptions are all written in Chinese, indicating the skill is intended to operate in a fixed language. There is no visible opt-in, locale selector, or justification that this is a region-specific skill, which can violate language/locale policy requirements.
This code emits a billing error message in Chinese only: "余额不足,请前往 ... 充值后重试". That imposes a specific language on all users without any locale selection or documented regional justification, which is a natural-language policy violation.
This JSON schema contains user-facing placeholder text, labels, descriptions, and validation messages entirely in Chinese. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified, which is not present here.
The manifest question and description position the skill as a visual quality diagnostic assistant that evaluates existing images and produces conclusions and action advice. However, the input fields and placeholder repeatedly describe 'GPT 图片生成需求', '用于直接生成图片', and using reference materials '用于 GPT Image 2 参考生成或风格改写', which indicates image generation/prompt construction rather than publication-readiness diagnosis of an existing image.
This manifest uses Chinese for the user-facing question, skill name, placeholders, labels, and descriptions, which effectively forces a specific language experience. There is no indication that users can opt into another language or that the skill is intentionally restricted to a Chinese-speaking region or audience.
The HTTP error handler emits a fixed Simplified Chinese message for insufficient billing balance. This imposes a specific language on all users and there is no nearby opt-in, locale detection, or documentation showing that the skill is intentionally region-specific.
No suspicious patterns detected.