T09 · Insecure Skill Coding Practices
- Location
references/ezviz-api-docs.md:54- Finding
Credential-Shaped Secrets Embedded in API Documentation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly matches its stated camera phone-detection purpose, but it handles surveillance images and device playback while shipping realistic credential examples and a duplicate alert path that warrant manual review.
Review before installing. Use only with explicit authorization for the monitored area, create restricted Ezviz credentials limited to the required APIs/devices, rotate any exposed-looking sample credentials if they were ever real, and remove or patch the duplicate alert block and undisclosed fallback downloads before production use.
references/ezviz-api-docs.md:54Credential-Shaped Secrets Embedded in API Documentation
scripts/phone_detection_alert.py:655Duplicate Alert Workflow and Full Signed Voice URL Logging
scripts/phone_detection_alert.py:305Predictable Files in a Shared Temporary Directory
SKILL.md:26Unpinned Runtime Dependencies
scripts/phone_detection_alert.py:345Undeclared and Unvalidated Audio Download from an Unrelated Domain
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
def get_access_token(app_key, app_secret):
"""
Get access token using appKey and appSecret.
API: POST /api/lapp/token/get
Content-Type: application/x-www-form-urlencoded
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
def get_access_token(app_key, app_secret):
"""
Get access token using appKey and appSecret.
API: POST /api/lapp/token/get
Content-Type: application/x-www-form-urlencoded
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
def get_access_token(app_key, app_secret):
"""
Get access token using appKey and appSecret.
API: POST /api/lapp/token/get
Content-Type: application/x-www-form-urlencoded
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
def get_access_token(app_key, app_secret):
"""
Get access token using appKey and appSecret.
API: POST /api/lapp/token/get
Content-Type: application/x-www-form-urlencoded
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
def get_access_token(app_key, app_secret):
"""
Get access token using appKey and appSecret.
API: POST /api/lapp/token/get
Content-Type: application/x-www-form-urlencoded
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
def get_access_token(app_key, app_secret):
"""
Get access token using appKey and appSecret.
API: POST /api/lapp/token/get
Content-Type: application/x-www-form-urlencoded
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
def get_access_token(app_key, app_secret):
"""
Get access token using appKey and appSecret.
API: POST /api/lapp/token/get
Content-Type: application/x-www-form-urlencoded
The file consistently presents its operational description, setup guidance, warnings, and outputs in Chinese, which effectively imposes a specific language on users. The policy allows locale constraints only when clearly justified or when users are given a language choice, neither of which is present here.
The document outlines a pipeline that captures live camera images, analyzes human behavior, uploads audio, and pushes voice playback to a device. For markdown files, these are user-data, privacy, and system-impacting behaviors that should be accompanied by an explicit warning so operators understand the monitoring and device-control implications before use.
The document includes live-looking app credentials and access tokens in example requests without any warning that these values must be treated as secrets. Even if intended as samples, realistic-looking secrets are often copied, tested, or accidentally left valid, which can lead to unauthorized API access, token reuse, account abuse, or downstream compromise of connected surveillance devices and data.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl --location --request POST 'https://open.ys7.com/api/service/intelligence/algo/analysis/play_phone_detection' \
--header 'accessToken: at.3xwsj8em6p28dw3t92nf4itq4mote8qr-6t75j5aq2m-1i7rkyf-pwz8z7rfi' \
--header 'Content-Type: application/json' \
--data-raw '{
The module docstring says the workflow starts by capturing a camera snapshot and then performing detection, implying direct camera-based acquisition. In practice, main() calls get_access_token() and capture_device_image() to remotely capture images from Ezviz devices using the vendor cloud API, and the local capture_snapshot() path is never used.
Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.
}
try:
response = requests.post(
DEVICE_CAPTURE_API_URL,
headers=headers,
data=data,
The script sends image URLs representing surveillance snapshots to an external analysis service. Even though this is core functionality, it is still a real external transmission of potentially sensitive visual data and is dangerous if deployed without clear authorization, privacy controls, and data-governance review.
}
try:
response = requests.post(
PHONE_DETECTION_API_URL,
headers=headers,
json=payload,
The script transmits captured surveillance images to an external phone-detection cloud API without any explicit notice, consent gate, or configurable privacy control. Because the data may contain people and sensitive scenes, silent third-party transmission increases privacy, compliance, and data-handling risk.
The TTS voice is fixed to zh-CN-XiaoxiaoNeural and the fallback gTTS language is fixed to zh-cn, forcing a specific locale. This is a natural-language policy issue because the skill does not offer any language selection, opt-in, or documented justification for enforcing Chinese output.
Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.
data = {
'voiceName': voice_name
}
response = requests.post(
VOICE_UPLOAD_API_URL,
params=params,
files=files,
Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.
}
try:
response = requests.post(
VOICE_SEND_API_URL,
headers=headers,
data=data,
After processing all devices, the code reuses the last detection_result/device_serial in a duplicated alert block, which can trigger a second unintended upload/send operation. In a security/automation context, duplicated actions against surveillance devices can cause unauthorized repeated playback, operator confusion, and actions on the wrong target device.
The spoken alert message is fixed as Chinese text, which enforces a specific language for end users and device recipients. The file provides no mechanism for selecting another language or confirming that Chinese is desired.
The step descriptions say '调用接口 1/2/3' for phone detection, voice upload, and voice send, but in this document those capabilities are actually documented as sections 2, 3, and 4 respectively. This is an active documentation contradiction that could cause implementers to call the wrong APIs in a security-sensitive workflow involving image analysis and device voice playback.
Alert text is sent to third-party TTS services (edge-tts or gTTS) without a clear privacy notice or consent path. While the current fixed text is not highly sensitive, the function accepts arbitrary text and could expose sensitive operational content if reused.
Detected: suspicious.exposed_secret_literal