T09 · Insecure Skill Coding Practices
- Location
happyhorse_video_creator.py:34- Finding
Hard-Coded DashScope API Credential in Documentation and Executable Code
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is for video generation, but it includes and automatically uses an exposed API key and can submit external paid requests and write files without enough user control.
Install only after the exposed DashScope key is removed and rotated, the skill requires your own securely supplied API key, direct script execution cannot submit jobs without explicit confirmation, and downloads are restricted to trusted video URLs and safe output paths. Do not send private prompts or image URLs unless you are comfortable sharing them with Alibaba DashScope.
happyhorse_video_creator.py:34Hard-Coded DashScope API Credential in Documentation and Executable Code
happyhorse_video_creator.py:297Direct Script Execution Automatically Submits an External Billable Task
happyhorse_video_creator.py:199Unrestricted Video Download URL and Output Path
The declared purpose says the skill generates videos, but the content also embeds a hard-coded API credential and describes saving generated artifacts to the local filesystem without clearly declaring those behaviors. This mismatch reduces informed consent and hides sensitive capabilities that materially change the risk profile of the skill.
The skill documentation includes a live-looking Alibaba DashScope API key directly in the file and in example Authorization headers. Exposed credentials can be copied and abused by anyone with access to the skill, leading to unauthorized API usage, billing fraud, quota exhaustion, and possible access to associated account resources.
The skill not only exposes a hard-coded API key but instructs the agent to use it as a default credential, without warning users that it is sensitive. This encourages insecure credential handling and normalizes redistribution of secrets, increasing the chance of unauthorized use and account compromise.
The file embeds a default DashScope API key in source code and uses it automatically when no key is supplied. Hardcoded secrets are dangerous because they can be extracted by anyone with code access, abused for unauthorized API usage, billing fraud, and account compromise, and they encourage insecure secret distribution.
A hardcoded API credential is used in outbound authenticated requests without secure handling or user disclosure. This creates an immediate secret-exposure risk and can let third parties impersonate the service account, consume paid resources, or access associated account capabilities.
The skill clearly documents network-capable behavior through direct HTTP requests to an external API, but it does not declare any tool scope such as permissions or allowed-tools. This weakens policy enforcement and user transparency, making it easier for the skill to perform outbound requests without explicit governance.
The primary description fields are written only in Chinese, and the workflow text throughout the file is also exclusively Chinese. Under the language/locale policy, this is a violation unless the skill offers a language choice or clearly documents that it is intentionally restricted to a Chinese-speaking context, which it does not.
The skill asks users for prompts and image URLs and sends them to a third-party cloud API, but it does not clearly warn users that their content will leave the local environment. In a media-generation workflow, prompts and reference images may contain confidential or proprietary material, so lack of disclosure creates privacy and compliance risk.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
} }
response = requests.post(url, headers=headers, json=payload, timeout=30) task_id = response.json()["output"]["task_id"]
The module title and user-facing natural-language strings are written exclusively in Chinese, indicating a fixed language choice rather than offering locale selection. The file does not document that the language restriction is optional or region-specific, so it may violate language/locale policy expectations.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
print(f" 提示词:{prompt[:50]}...")
try:
response = requests.post(VIDEO_ENDPOINT, headers=headers, json=payload, timeout=30)
if response.status_code == 200:
result = response.json()
The manifest says the skill generates videos using the HappyHorse model, including text-to-video and image-to-video modes. In addition to generation, the implementation retrieves the returned video URL and writes the video file under a local workspace directory, which is a broader behavior than the description states.
The download_video function fetches remote content and writes it to a local path under /root/.openclaw/workspace or a caller-supplied path. While it logs the destination path, there is no confirmation prompt or prior warning that the skill will create files on disk, which is a safety-relevant side effect for code handling user content.
No suspicious patterns detected.