Back to skill

Security audit

image-enlarge

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but it can upload local images to Flyelep as permanent public links without clearly requiring an explicit privacy confirmation.

Review this skill before installing if you may process private or sensitive images. Use it only for files you are comfortable sending to Flyelep and potentially exposing through a permanent public URL; avoid identity documents, confidential business images, screenshots with secrets, medical images, or customer data unless you have separate privacy assurances from the service.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:105
Finding

Local Images Are Uploaded to Permanent Public URLs Without Required Privacy Consent or Deletion Controls

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 105-118
Vulnerability Type: Uncontrolled public disclosure and indefinite retention of user-provided files
Risk Level: Medium

Vulnerable Code Snippet

The relevant instructions, translated into English, state:

markdown
## Local File Upload

When the user provides a local file path rather than a public direct link,
upload the file to obtain a direct link before invoking this API.

- URL: POST https://www.flyelep.cn/prod-api/poster-design/api/v1/file/upload
- Request type: multipart/form-data
- The fixed file field name is file.
- Authentication: Send secretKey in the request header.
- Do not manually set the Content-Type header.
- Supported image formats include bmp, gif, jpg, jpeg, and png.

On success, use data.fullPath as the public direct link.
It is permanently valid and has no signature.

Technical Analysis

The skill instructs the agent to transfer a user-selected local image to a third-party Flyelep upload endpoint. The resulting object is explicitly described as a permanently valid, unsigned public URL.

An unsigned public URL has no authentication or authorization check associated with retrieval. Anyone who obtains the URL can access the image. Permanent validity also means that exposure continues after the image-enlargement task and potentially after the user's session ends.

The workflow does not require the agent to:

  • Explain that the local file will be sent to Flyelep and stored by an external cloud provider.
  • Obtain explicit confirmation immediately before upload.
  • Warn that the resulting URL is public and does not expire.
  • Detect or reject images containing sensitive information.
  • Delete the uploaded source image after processing.
  • Provide a retention period, revocation mechanism, or deletion endpoint.

Although the upload is part of the declared image-processing workflow, automatically turning a l ...[truncated 1566 chars]

Remediation
View remediation

Remediation Suggestions

  1. Require explicit, informed user confirmation immediately before uploading any local file. State the destination service, purpose, public-access characteristics, and expected retention period.
  2. Replace permanent public objects with private storage and short-lived signed URLs. Limit each signed URL to the minimum processing period required.
  3. Add an authenticated deletion endpoint and automatically remove both source and generated objects after processing or after a short documented retention interval.
  4. Do not expose source-image URLs in normal user output, diagnostic logs, telemetry, or error messages.
  5. Warn users not to upload identity documents, medical images, credentials, confidential business data, or other sensitive content unless the service provides appropriate contractual and technical safeguards.
  6. Require the agent to verify that the requested file is one explicitly selected by the user rather than inferring or expanding local paths.
  7. Document the third-party processor, storage region, retention policy, access controls, and deletion process.
  8. If private or expiring storage cannot be implemented, disable automatic local-file uploads and accept only public URLs that the user intentionally provides.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill’s natural-language description and all operational instructions are written entirely in Chinese, with no indication that the user can choose another language or locale. Under the policy, a skill that effectively imposes a specific language without opt-in should be flagged unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The skill instructs the agent to upload user-provided local files and image URLs to third-party Flyelep endpoints, which is an external data transmission of potentially sensitive content and credentials (secretKey). In the context of an agent skill, this is security-relevant because local files may contain private data and the skill normalizes sending them off-platform without explicit per-file consent, classification, or domain trust validation.

Content

Scanner excerpt · SKILL.md (reported line 135)May include surrounding context.

判断成功只看 code,业务失败时 HTTP 状态码仍是 200,code 为 500 或 9999,原因在 msg 里。

bash
# Windows/PowerShell(用 curl.exe,PowerShell 里的 curl 是 Invoke-WebRequest 的别名)
curl.exe -X POST "https://www.flyelep.cn/prod-api/poster-design/api/v1/file/upload" -H "secretKey: 你的密钥" --max-time 120 -F "file=@C:/path/to/product.png"

# macOS/Linux

Static analysis

No suspicious patterns detected.