T09 · Insecure Skill Coding Practices
- Location
scripts/evaluate_project.py:6- Finding
API Credential Disclosure Through Unbound and Attacker-Controlled API Endpoint
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill does what it claims, but its API configuration can send credentials and project details to an unintended or arbitrary LLM endpoint.
Review this skill before installing. Use it only with non-sensitive project descriptions unless you trust the configured LLM endpoint, and avoid running it in an environment containing unrelated OPENAI_API_KEY values. Prefer setting a provider-specific key intentionally and verify the destination before use.
scripts/evaluate_project.py:6API Credential Disclosure Through Unbound and Attacker-Controlled API Endpoint
The script reads both the API key and the API endpoint from environment variables, then sends the bearer token to whatever URL is in API_BASE. If an attacker can influence the environment, they can redirect requests to a malicious server and capture the credential, causing secret exfiltration and unauthorized API use. In this skill’s context, outbound LLM access is expected, but allowing an untrusted base URL makes the credential flow significantly more dangerous than a fixed vendor endpoint.
], "temperature": 0.7}).encode()
req = urllib.request.Request(f"{API_BASE}/chat/completions", data=payload,
headers={"Content-Type": "application/json", "Authorization": f"Bearer {API_KEY}"})
with urllib.request.urlopen(req, timeout=90) as r:
return json.loads(r.read())["choices"][0]["message"]["content"]
def build_prompt(idea, context=""):
The skill title and description are entirely in Chinese and present the interaction mode as fixed, with no indication that other languages are supported or that the user can choose their preferred language. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.
The skill advertises executable tool usage via a Python command that can write files and potentially access environment/networked resources, but it does not declare any explicit tool scope or permissions. This weakens containment and reviewability because the runtime capabilities are broader than what the manifest communicates, increasing the chance of unintended file writes, data exposure, or network misuse if the backing script is unsafe.
The display name, description, usage instructions, and output examples are all presented only in Chinese, which effectively imposes a language constraint through the skill's natural-language interface. The file does not indicate that users may choose another language or that the Chinese-only behavior is a documented, justified regional requirement.
The trigger language is very broad, inviting activation whenever a user merely describes a project idea. Overly generic invocation criteria can cause unintended skill routing, which may expose user input to tooling or scripted processing when the user only expected normal conversation.
The example phrase '帮我评估这个项目' is generic and likely to overlap with normal conversational requests. That ambiguity can trigger the skill unexpectedly, reducing user control and potentially invoking script-backed behavior without clear consent.
The manifest describes an idea-evaluation assistant that produces market/technical/business/risk analysis. While calling an LLM API is expected implementation detail, directly reading provider API keys and base URL from environment variables introduces credential access capability that is not stated or obviously inherent from the manifest text itself.
The system prompt explicitly instructs the model to '请用中文输出', which imposes a specific language regardless of user preference. Under the policy, forced language/locale behavior is a natural-language policy violation unless the user is given an opt-in choice or the restriction is clearly justified.
No suspicious patterns detected.