T09 · Insecure Skill Coding Practices
- Location
SKILL.md:105- Finding
Local Images Are Uploaded to Permanent Public URLs Without Required Privacy Consent or Deletion Controls
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 105-118
Vulnerability Type: Uncontrolled public disclosure and indefinite retention of user-provided files
Risk Level: MediumVulnerable Code Snippet
The relevant instructions, translated into English, state:
markdown ## Local File Upload When the user provides a local file path rather than a public direct link, upload the file to obtain a direct link before invoking this API. - URL: POST https://www.flyelep.cn/prod-api/poster-design/api/v1/file/upload - Request type: multipart/form-data - The fixed file field name is file. - Authentication: Send secretKey in the request header. - Do not manually set the Content-Type header. - Supported image formats include bmp, gif, jpg, jpeg, and png. On success, use data.fullPath as the public direct link. It is permanently valid and has no signature.Technical Analysis
The skill instructs the agent to transfer a user-selected local image to a third-party Flyelep upload endpoint. The resulting object is explicitly described as a permanently valid, unsigned public URL.
An unsigned public URL has no authentication or authorization check associated with retrieval. Anyone who obtains the URL can access the image. Permanent validity also means that exposure continues after the image-enlargement task and potentially after the user's session ends.
The workflow does not require the agent to:
- Explain that the local file will be sent to Flyelep and stored by an external cloud provider.
- Obtain explicit confirmation immediately before upload.
- Warn that the resulting URL is public and does not expire.
- Detect or reject images containing sensitive information.
- Delete the uploaded source image after processing.
- Provide a retention period, revocation mechanism, or deletion endpoint.
Although the upload is part of the declared image-processing workflow, automatically turning a l ...[truncated 1566 chars]
- Remediation
View remediation
Remediation Suggestions
- Require explicit, informed user confirmation immediately before uploading any local file. State the destination service, purpose, public-access characteristics, and expected retention period.
- Replace permanent public objects with private storage and short-lived signed URLs. Limit each signed URL to the minimum processing period required.
- Add an authenticated deletion endpoint and automatically remove both source and generated objects after processing or after a short documented retention interval.
- Do not expose source-image URLs in normal user output, diagnostic logs, telemetry, or error messages.
- Warn users not to upload identity documents, medical images, credentials, confidential business data, or other sensitive content unless the service provides appropriate contractual and technical safeguards.
- Require the agent to verify that the requested file is one explicitly selected by the user rather than inferring or expanding local paths.
- Document the third-party processor, storage region, retention policy, access controls, and deletion process.
- If private or expiring storage cannot be implemented, disable automatic local-file uploads and accept only public URLs that the user intentionally provides.
