T09 · Insecure Skill Coding Practices
- Location
SKILL.md:276- Finding
Local images are uploaded to permanent, unsigned public URLs without an explicit consent or deletion workflow
- Content
View full analysis
" \ --max-time 120 \ -F "file=@./product.png" ``` The documented response demonstrates that the uploaded file receives a public cloud-storage URL: ```json { "code": 200, "data": { "relativePath": "cos_ai_agent/2026-08-11/3f2a9c1b7d84e6f5a012.png", "fullPath": "https://agent-1404002717.cos.ap-guangzhou.myqcloud.com/cos_ai_agent/2026-08-11/3f2a9c1b7d84e6f5a012.png" } } ``` ### Technical Analysis The skill instructs the agent to upload local user images to third-party Flyelep infrastructure whenever a public image URL is required. The returned object URL is explicitly described as public, permanently valid, and unsigned. An unsigned public URL is a bearer capability: anyone who obtains the URL can retrieve the image without authentication. Because the URL does not expire, exposure persists after the image-generation operation has finished. The skill provides no deletion endpoint, retention limit, post-processing cleanup, access-control mechanism, or explicit informed-consent checkpoint before upload. Although the URL contains a likely high-entropy object identifier and may not be practically enumerable, confidentiality still depends entirely on keepi ...[truncated 1457 chars]- Remediation
View remediation
