T09 · Insecure Skill Coding Practices
- Location
scripts/llm_semantic_match.py:39- Finding
Unrestricted LLM Endpoint Override Exposes API Credentials and User Data
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly matches a construction-costing purpose, but it needs Review because it can send sensitive project text and API credentials to configurable third-party endpoints and can mutate local pricing/history databases without strong guardrails.
Install only if you are comfortable with third-party LLM processing of construction/project descriptions. Before use, restrict HUNYUAN_URL to trusted HTTPS provider hosts, avoid putting confidential bid or supplier data into LLM-backed flows unless approved, back up any local quota/history databases, and review dependencies or pin them in your own environment.
scripts/llm_semantic_match.py:39Unrestricted LLM Endpoint Override Exposes API Credentials and User Data
scripts/ai_quota_engine.py:617AI Quota Parser Sends API Key and Bill-Item Data to an Unvalidated Endpoint
scripts/requirements.txt:2Unpinned Third-Party Dependencies Permit Unreviewed Future Releases
The code sends user-provided list descriptions to an external endpoint and includes a bearer token from an environment variable in the request headers. Although the API key itself is not exfiltrated to the model payload, this still creates a real data egress path for potentially sensitive project or procurement data and trusts a runtime-configurable URL, which could redirect requests to an unintended host.
"特征": "碳钢、法兰连接"
}}
清单描述:{text}"""
resp = requests.post(
os.environ.get("HUNYUAN_URL", "https://tokenhub.tencentmaas.com/v1/chat/completions"),
headers={"Authorization": f"Bearer {api_key}", "Content-Type": "application/json"},
json={"model": os.environ.get("HUNYUAN_MODEL", "hy3-preview"),
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
"Content-Type": "application/json",
"Authorization": f"Bearer {api_key}"
}
response = requests.post(url, headers=headers, json=payload, timeout=30)
result = response.json()
if "choices" in result and len(result["choices"]) > 0:
代码的主功能是一个 LLM 辅助的定额语义匹配脚本,而不是完整的工程造价技能实现。它通过外部 API 将用户的“工作内容”发送给腾讯混元或豆包,要求模型判断所属安装分册、提取搜索关键词、设备类型和参数;随后用本地搜索器搜索/验证真实定额结果。这与声明中的一小部分“定额子目查询”相关,但与更核心、更宽泛的宣称能力存在明显落差:声明覆盖安装/建筑/市政/园林多专业、组价计算、取费计算、报价表生成、山东/济南价目表查询、唯一来源模式等,而本代码均未体现。尤其是代码的专业知识硬编码仅为“安装工程13分册”,与声明的多专业范围不符;并且实际资源访问包括外部 LLM 服务,声明虽提到“默认模式:大模型推理数据”,但该代码是明确的网络 API 依赖实现,而非本地数据库/费率标准主导。综合来看,描述与该代码块的实际行为存在实质性不匹配。
The description presents a full-featured engineering costing skill with multiple engineering domains, fee standards, quotation generation, and configurable data-source modes. The supplied code chunk, however, is a narrower search component: a local JSON-backed matcher for installation-engineering quota items. It does accurately align with part of the declared purpose—installation quota lookup for the 2025 13-volume standard and Jinan-derived data—but it does not implement many of the prominent declared capabilities. The code's primary behavior is retrieval/matching, not full costing, fee computation, or document generation. It also uses different concrete resources than advertised and exposes extra behavior (BIM matching helper, CLI interaction) not mentioned in the description. Therefore the description materially overstates and partly misstates what this code chunk actually does.
The supplied code chunk does not implement the core end-user capabilities promised in the description, such as定额查询交互逻辑, 组价计算, 取费计算, Excel报价表生成, or enforcement of the claimed '唯一来源模式' and unit-checking workflow. Instead, it is an internal maintenance/build script whose primary purpose is to migrate two local JSON files into a SQLite database, create indexes/full-text search structures, and benchmark query speed. While this could support the broader skill, the chunk itself is materially different in primary purpose and includes undeclared capabilities around database creation, schema management, and performance testing. Therefore the description does not accurately represent what this code chunk actually does.
从代码看,主用途是“定额/材料检索”,而不是完整的“工程造价组价与报价生成”技能。其实现包括:定额名称/章节 LIKE 搜索、多关键词搜索、编号精确查找、分册筛选、材料价格查询、DN 映射口径查询、以及多后端降级(SQLite、FAISS、Chroma、文本倒排)。这些与声明中的“定额查询、山东/济南价目表查询”部分一致,但声明列出的多项核心能力在该代码块中没有体现,尤其是组价、取费、Excel 报价表生成、单位校验、价格自检、指标引擎等。因此,描述相对代码行为明显夸大且主能力范围更广,构成描述与实际行为不一致。
The skill declares environment-variable use, local file/database access, and external LLM/network behavior, but it does not define an explicit tool scope such as permissions or allowed-tools. That creates an authorization ambiguity where the runtime may permit broader access than users expect, especially given the documented use of API keys, local databases, and Excel file generation.
The documentation instructs network-based LLM use and Excel file generation without clearly disclosing that user inputs may be transmitted to third-party providers or that files will be written locally. This creates a material consent and data-handling risk, especially in a cost-estimation context where project names, quantities, and commercial pricing data may be sensitive.
Elsewhere the file repeatedly states Step 0 must run before Step 1, but L490 says unit comparison is executed '在 Step 1 定额查询之后、Step 2 组价计算之前'. This is an active contradiction in the operational instructions, not merely an omission, and it can change how the skill is implemented or used.
The trigger phrases are broad enough to activate the skill for common requests, increasing the chance of unintended invocation. In a skill that may read files, use environment-backed API keys, perform network calls, and generate local output, overbroad activation can cause unnecessary data exposure or undesired side effects from ordinary conversation.
The file title and all instructional content are written exclusively in Chinese, and there is no natural-language indication that the user may choose another language or that Chinese is optional. Under the policy, forcing a specific language without user opt-in is a locale/language policy concern unless the regional constraint is explicitly documented and justified.
The file instructs the LLM to answer user queries by following a fixed reply logic written entirely in Chinese for a general query about how to calculate '其他项目费'. There is no indication that the user can choose another language, nor a clear justification that the skill is restricted to Chinese-only interactions as a locale-specific compliance requirement.
This markdown file is entirely written as a Chinese-language reference and does not provide any indication that users may request another language or locale. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is clearly documented and justified.
This script transmits raw user input to a third-party LLM service without any explicit user-facing notice or consent mechanism at the point of use. In this skill's context, inputs may contain confidential bill-of-quantities, supplier, pricing, or project details, so silent transmission increases privacy, compliance, and data-handling risk.
This code opens the SQLite database in write mode and inserts project-derived indicator records, permanently modifying local data. Although there is a success print after the write, there is no prior warning, confirmation, or explicit disclosure in the command flow that running this path will store data into project_history.db.
The dynamic_adjust path performs an UPDATE against the indicators table, changing the stored info_price for an existing record. The function returns data after the fact, but there is no advance warning or confirmation that the adjust command mutates persistent state rather than only calculating a temporary adjusted value.
This code performs external transmission of prompt contents to remote APIs. In a cost-estimation and quotation skill, that data can include commercially sensitive project details, so the network call is security-relevant even if functionally intended.
"Content-Type": "application/json",
"Authorization": f"Bearer {api_key}"
}
response = requests.post(url, headers=headers, json=payload, timeout=30)
result = response.json()
if "choices" in result and len(result["choices"]) > 0:
The script transmits user-supplied construction/project text to third-party LLM services without any consent flow, warning, redaction, or policy gate. In this skill context, user prompts may contain sensitive commercial data such as project scope, pricing assumptions, supplier details, or bid information, making silent exfiltration materially risky.
The function documentation says it generates a temporary bearer token using Tencent Cloud signature v3, but the implementation merely concatenates SecretId and SecretKey. This can cause operators to misuse long-lived cloud credentials as if they were safe temporary tokens, increasing the chance of credential exposure to logs, downstream HTTP auth headers, or incompatible endpoints.
The module docstring specifies the skill entirely in Chinese and ties it to Chinese regional standards and source material, with no indication that users can choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.
The script unconditionally deletes the existing quota.db before recreating it, which can cause irreversible local data loss if the database contains important or manually modified data. While this is not a code execution issue, it is a real destructive behavior and becomes more risky because the skill manages reference/pricing data that users may expect to preserve.
Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.
copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT.
The description presents the skill as a Chinese engineering-costing skill and the entire instruction set, triggers, and examples are Chinese-only, with no indication that users may choose another language. This can violate a language-choice policy when a skill implicitly forces a locale without opt-in or explicit justification.
The manifested purpose is to query quotas, calculate pricing, and generate quotation sheets. Embedding a direct 'contact the author' distribution path for a proprietary database adds an out-of-band acquisition capability that is not needed to execute the skill itself and is not part of the stated functional scope.
This markdown file is entirely written in Chinese and scoped to a specific Chinese provincial standard, with no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.
Detected: suspicious.dynamic_code_execution