T09 · Insecure Skill Coding Practices
- Location
scripts/products_from_ticket_system.py:38- Finding
Cloud credentials may be used with arbitrary attacker-controlled API endpoints
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent Alibaba Cloud discovery workflow, but it uses cloud credentials with unvalidated endpoint variables and has a constrained output-path escape risk, so it deserves careful review before installation.
Use this only with short-lived, least-privilege read-only Alibaba Cloud credentials. Set endpoints only to documented Alibaba Cloud domains, avoid running it with untrusted environment variables or untrusted products JSON, and run it in an isolated workspace until endpoint and path validation are added.
scripts/products_from_ticket_system.py:38Cloud credentials may be used with arbitrary attacker-controlled API endpoints
scripts/apis_from_openapi_meta.py:77Untrusted product metadata can escape the intended output directory
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
def fetch_json(url: str) -> dict:
try:
with urllib.request.urlopen(url, timeout=60) as resp:
payload = resp.read().decode("utf-8")
except urllib.error.URLError as exc:
print(f"Failed to fetch {url}: {exc}", file=sys.stderr)
The declared description describes a broad pipeline: gather product catalogs from multiple Alibaba Cloud sources, reconcile them, retrieve OpenAPI metadata, and summarize API coverage for new skill planning. This code chunk implements only a downstream comparison step: it assumes merged_products.json already exists, reads local SKILL.md files, matches products to skills by simple substring search, and outputs uncovered products. That supports part of 'coverage/gap reports for skill generation,' but it does not implement the major declared behaviors around source discovery, reconciliation, or OpenAPI metadata retrieval. Therefore the description does not accurately represent what this specific code chunk actually does.
The declared description promises a multi-source catalog discovery and reconciliation workflow plus downstream metadata collection and coverage analysis. The actual code chunk is much narrower: it uses Alibaba Cloud credentials to call only the BssOpenApi QueryProductList API, paginates through results, and saves products.json locally. There is no interaction with Ticket System or Support & Service, no product-to-API mapping, no OpenAPI version/API metadata retrieval, and no coverage/gap summarization. While the code is related to one subset of the declared purpose, it materially underdelivers relative to the description, so this is a description-versus-behavior mismatch.
The code is much narrower than the declared description. It performs a single task: downloading products.json from api.aliyun.com, extracting product codes and versions, and saving the results. There is no logic for querying Ticket System, Support & Service, or BSS OpenAPI, no cross-source reconciliation, no API metadata collection beyond versions, and no coverage/gap analysis. While this script partially aligns with the 'complete product list' theme, it does not implement most of the declared functionality, so the description materially overstates the skill's behavior.
The skill instructs execution of Python scripts that read environment credentials, write files, and make network requests, but it declares no explicit tool scope or permission boundaries. In an agent setting, missing scope increases the chance the skill can access broader files, credentials, or network targets than intended, making review and runtime enforcement weaker.
The generated markdown headings and labels are hard-coded in Chinese (产品覆盖分析, 未覆盖产品, etc.), which imposes a specific language on output without any user opt-in or explanation. This matches the locale/language policy concern for natural-language content embedded in code.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"""Fetch Alibaba Cloud product list from OpenAPI metadata endpoints.
Downloads:
https://api.aliyun.com/meta/v1/products.json?language=EN_US
Optional env vars:
- OPENAPI_META_LANGUAGE (default: EN_US)
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"""Fetch Alibaba Cloud product list from OpenAPI metadata endpoints.
Downloads:
https://api.aliyun.com/meta/v1/products.json?language=EN_US
Optional env vars:
- OPENAPI_META_LANGUAGE (default: EN_US)
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"""Fetch Alibaba Cloud product list from OpenAPI metadata endpoints.
Downloads:
https://api.aliyun.com/meta/v1/products.json?language=EN_US
Optional env vars:
- OPENAPI_META_LANGUAGE (default: EN_US)
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"""Fetch Alibaba Cloud product list from OpenAPI metadata endpoints.
Downloads:
https://api.aliyun.com/meta/v1/products.json?language=EN_US
Optional env vars:
- OPENAPI_META_LANGUAGE (default: EN_US)
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"""Fetch Alibaba Cloud product list from OpenAPI metadata endpoints.
Downloads:
https://api.aliyun.com/meta/v1/products.json?language=EN_US
Optional env vars:
- OPENAPI_META_LANGUAGE (default: EN_US)
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"""Fetch Alibaba Cloud product list from OpenAPI metadata endpoints.
Downloads:
https://api.aliyun.com/meta/v1/products.json?language=EN_US
Optional env vars:
- OPENAPI_META_LANGUAGE (default: EN_US)
The code accesses access keys and optional security tokens from environment variables to authenticate with the remote service. Although the module docstring lists the required variables, it does not clearly warn users that credentials will be consumed for authenticated API access, and there is no runtime disclosure.
This code performs a remote API call using credentials and optional query data such as product name and language, but there is no runtime notice, confirmation, or user-facing warning that data will be sent to the endpoint. The header documents required environment variables for developers, but it does not clearly disclose the outbound network action itself to the user at execution time.
The skill description and workflow consistently present this skill as read-oriented discovery and summarization of Alibaba Cloud product and OpenAPI metadata. Line L100 says to ask the user before running mutating operations, which implies the skill may perform writes against cloud resources even though no such operations are described elsewhere in the file.
The script writes analysis results to skill_gap.json and skill_gap.md, but the code provides no prior user-facing warning, confirmation, or inline comment/docstring disclosing that it will create or overwrite these files. For code-file review under this rule, file writes should have some visible disclosure unless clearly documented as part of the skill behavior.
The generated report headings and labels are hard-coded in Chinese, which imposes a specific language choice on all users of the skill. There is no visible option to select output language or documentation explaining that the tool is intentionally limited to a Chinese-speaking context.
The generated markdown headings and table labels are hard-coded in Chinese, such as '产品Code', '产品名', and 'OpenAPI 产品分类汇总'. This imposes a specific language/locale on all users without opt-in or justification, which matches the natural-language locale policy violation criteria.
No suspicious patterns detected.