T09 · Insecure Skill Coding Practices
- Location
scripts/runtime-auth.mjs:6- Finding
Caller-Controlled Base URL Can Expose API Credentials Over Arbitrary or Plaintext Network Destinations
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent gateway integration, but it handles credentials, account actions, telemetry, and local file uploads with under-scoped controls that warrant Review before use.
Install only if you trust BinaryWorks and your agent runtime will restrict invocations to the intended gateway domains. Disable or constrain telemetry if possible, do not pass untrusted base_url or SKILL_TELEMETRY_BASE_URL values, avoid raw file_path inputs for sensitive files, and treat the face/person-recognition capabilities and portal account actions as sensitive.
scripts/runtime-auth.mjs:6Caller-Controlled Base URL Can Expose API Credentials Over Arbitrary or Plaintext Network Destinations
scripts/telemetry.mjs:12Opt-Out Telemetry Can Send API Keys and Stable Identifiers to an Unvalidated Destination
scripts/attachment-normalize.mjs:145Unrestricted file_path Processing Can Read and Upload Files Outside the Workspace
Referenced artifact was not completely inspected
- Local current version source: this installed `SKILL.md` frontmatter `version`.
Referenced artifact was not completely inspected
- `portal-action.mjs` defaults `include_files=true` for `portal.skill.presentation` unless explicitly disabled.
Referenced artifact was not completely inspected
- `portal-action.mjs` defaults `include_files=true` for `portal.skill.presentation` unless explicitly disabled.
Referenced artifact was not completely inspected
- `portal-action.mjs` defaults `include_files=true` for `portal.skill.presentation` unless explicitly disabled.
Referenced artifact was not completely inspected
- `portal-action.mjs` defaults `include_files=true` for `portal.skill.presentation` unless explicitly disabled.
Referenced artifact was not completely inspected
- `portal-action.mjs` defaults `include_files=true` for `portal.skill.presentation` unless explicitly disabled.
Referenced artifact was not completely inspected
- `scripts/execute.mjs` (CLI args: `[api_key] [capability] [input_payload] [base_url] [agent_uid] [owner_uid_hint]`)
Referenced artifact was not completely inspected
- `scripts/execute.mjs` (CLI args: `[api_key] [capability] [input_payload] [base_url] [agent_uid] [owner_uid_hint]`)
Referenced artifact was not completely inspected
- `scripts/poll.mjs` (CLI args: `[api_key] <run_id> [base_url] [agent_uid] [owner_uid_hint]`)
Referenced artifact was not completely inspected
- `scripts/poll.mjs` (CLI args: `[api_key] <run_id> [base_url] [agent_uid] [owner_uid_hint]`)
Referenced artifact was not completely inspected
- `scripts/feedback.mjs` (CLI args: `[api_key] [payload_json] [base_url] [agent_uid] [owner_uid_hint]`)
Referenced artifact was not completely inspected
- `scripts/feedback.mjs` (CLI args: `[api_key] [payload_json] [base_url] [agent_uid] [owner_uid_hint]`)
Referenced artifact was not completely inspected
- `scripts/runtime-auth.mjs` (shared auto-bootstrap helper)
Referenced artifact was not completely inspected
- `scripts/portal-auth.mjs` (api-key -> user session bridge)
Referenced artifact was not completely inspected
- `scripts/portal-auth.mjs` (api-key -> user session bridge)
Referenced artifact was not completely inspected
- `scripts/attachment-normalize.mjs` (attachment URL/path normalization + upload)
Referenced artifact was not completely inspected
- `scripts/attachment-normalize.mjs` (attachment URL/path normalization + upload)
The capabilities catalog exposes a very broad set of services that materially exceeds the skill's stated purpose as a gateway for async execute/poll, portal user closure, and telemetry feedback. This unnecessary expansion increases the attack surface and enables misuse of the skill as a generic AI/vision broker, including access to sensitive image, audio, and document processing workflows unrelated to the declared function.
The listed capabilities include facial attribute, action, quality, emotion, physical, and social classification features that are unrelated to the gateway purpose and process sensitive biometric inferences. In context, this makes the skill more dangerous because users and reviewers could reasonably expect only workflow-routing behavior, not covert access to emotion or attribute analysis.
The file exposes face recognition and person-identification capabilities such as political-figure, designated-person, and exhibit recognition without any justification tied to the gateway's declared workflows. These capabilities are highly sensitive because they can enable surveillance, identification, and downstream privacy harms if a broadly described gateway skill is used as cover for biometric processing.
This code sends sensitive API keys to telemetry via emitTelemetry on both the explicit-auth and bootstrap-success paths. Telemetry systems commonly have broader access, longer retention, and weaker secret-handling guarantees than primary auth stores, so exporting live credentials can lead to credential disclosure, account compromise, and downstream abuse if logs, dashboards, or processors are accessed by unauthorized parties.
The skill documents networked scripts, environment-controlled behavior, authentication bootstrap, file upload, and telemetry, but it does not declare any explicit tool scope or allowed-tools boundary. That omission weakens least-privilege controls and makes it easier for an agent runtime to grant broader env/network access than users or operators expect, increasing the blast radius if the skill or its dependencies are abused.
The skill describes best-effort telemetry and feedback submission, enabled by default, but does not present a clear user-facing disclosure of what data may be transmitted, when transmission occurs, or how to disable it. Because the same skill handles auth, execution, polling, feedback, and metadata fields like agent_uid and owner_uid_hint, this can lead to silent outbound data exposure and unexpected sharing of operational or user-derived information.
The skill documents automatic upload of local files referenced by file_path to a remote site, but does not prominently warn that local filesystem content may be transmitted externally. Because this gateway normalizes attachments and can auto-upload as part of normal execution, users may unintentionally send sensitive local data to a remote service.
The documentation states that telemetry and feedback are sent off-host and include runtime metadata such as agent_uid and owner_uid_hint, but it does not present a clear user-facing warning or explicit consent requirement. In a skill that acts as a gateway and performs networked operations by default, silent metadata exfiltration can expose operational identifiers and usage context to a remote service without the operator fully realizing it.
Detected: suspicious.env_credential_access, suspicious.exposed_secret_literal