T09 · Insecure Skill Coding Practices
- Location
scripts/app.py:18- Finding
Hard-Coded Payment and AI Provider Credentials
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent short-video script generator, but its payment and AI web app ships exposed credentials and unsafe payment/session controls that users should review before running.
Do not run this as-is with real users or real billing. Require rotated provider keys loaded from secrets, server-side payment verification per billable action, explicit disclosure before sending prompts to SiliconFlow, safe DOM rendering, debug disabled, and private binding or production deployment controls.
scripts/app.py:18Hard-Coded Payment and AI Provider Credentials
scripts/app.py:13Payment Verification Bypass Through a Forgeable Flask Session
templates/index.html:119Stored and AI-Sourced DOM Cross-Site Scripting
${script.hook}
${script.voiceover}
${script.subtitle}
${script.bgm}
${script.cta}
scripts/app.py:243Flask Development Debugger Exposed on All Network Interfaces
The skill description understates important behaviors: external AI API calls, payment interactions, and persistent local storage. This mismatch is dangerous because users and reviewers may authorize a simple script generator without realizing it performs billing and stores user data, creating consent, privacy, and financial risk.
The documentation contains a live-looking payment API key in plaintext. Embedded secrets can be harvested from the repository or package and abused for unauthorized charges, fraudulent payment operations, or account takeover of the payment integration.
The skill declares no explicit tool scope or permissions even though its documented behavior requires network access for AI generation and payment processing. Missing permission boundaries reduces transparency and can allow unexpected external communications, making review and user consent harder.
The skill advertises save, delete, and export functionality without clearly warning users that their data will be persisted and modified. In a content-generation context, this can lead to silent storage of user-provided ideas or business content and unexpected destructive actions on saved scripts.
The text explicitly states '全中文界面' (Chinese-only interface), which is a language constraint. The file does not indicate user opt-in, optional language selection, or a documented region-specific justification for restricting the skill to Chinese.
The file contains a hardcoded API key for the external AI provider. Embedded secrets in source code are easily leaked through repository access, deployments, logs, or package distribution, allowing unauthorized use of the account, billing abuse, and potential access to associated data.
# 硅基流动API配置
SILICONFLOW_API_KEY = 'sk-ggfjehtmwgthcdyajhpipxhurytmnmqsnvpfzoripdgdmzar'
SILICONFLOW_API_URL = 'https://api.siliconflow.cn/v1/chat/completions'
AI_MODEL = 'Doubao-ai/doubao-seed-v2-18k'
# 初始化数据库
The prompt hard-codes Chinese instructions and output expectations for generated scripts, which imposes a language choice without user opt-in. The file does not indicate that this is a region-specific or Chinese-only skill, nor does it provide an option to select another language.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
'max_tokens': 2000,
'response_format': {"type": "json_object"}
}
resp = requests.post(SILICONFLOW_API_URL, headers=headers, json=payload, timeout=30)
data = resp.json()
content = data['choices'][0]['message']['content']
return json.loads(content)
The generate_script flow sends the user-provided topic and platform data to the SiliconFlow API via an outbound HTTP request. Although there is error logging, there is no confirmation prompt, user-facing notice, or explanatory comment/docstring warning that user content will leave the local system and be processed by a third-party service.
This code transmits billing requests to an external payment service automatically using a generated session user_id, without stronger user binding or explicit transaction confirmation in the charge path. In context, the danger is not the transmission itself but unauthorized or surprise charging behavior caused by how it is invoked.
if TEST_MODE:
return {"ok": True, "balance": 1000}
try:
resp = requests.post(f"{BILLING_URL}/charge", headers=HEADERS, json={
"user_id": user_id, "skill_id": SKILL_ID, "amount": 0.001,
}, timeout=10)
data = resp.json()
The before_request hook automatically attempts to charge the user before most routes, including API actions, based only on session state and without an explicit per-action confirmation in this code path. This can lead to surprise billing, repeated charge attempts across sessions, and user harm if requests are triggered unintentionally or cross-site.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
if TEST_MODE:
return redirect(url_for('index', test_payment='success'))
try:
resp = requests.post(f"{BILLING_URL}/payment-link", headers=HEADERS, json={
"user_id": user_id, "amount": 0.001,
}, timeout=10)
payment_url = resp.json().get("payment_url")
The document language is hard-coded to zh-CN and the visible interface text is entirely Chinese, with no indication that users can choose another language or that the skill is intentionally region-specific. This can violate language/locale policy when a skill imposes a specific locale without user opt-in.
Backend-provided script fields are interpolated directly into innerHTML in renderScript(), including topic, hook, voiceover, subtitle, bgm, cta, and shot descriptions. If any of that content is attacker-controlled or model-generated with embedded HTML/JavaScript, it can trigger stored or reflected XSS when viewed from history or immediately after generation; in this skill context, user input and generated content flow through the backend, making this especially plausible.
The DELETE route permanently removes stored script records from the database. The code contains no confirmation step, user-visible warning, or explanatory comment indicating that the action is destructive and irreversible.
The HTML document explicitly sets lang="zh-CN", and all visible UI text is presented only in Chinese. This creates a natural-language locale restriction without any opt-in, alternative language path, or documented region-specific justification in the file.
No suspicious patterns detected.