T08 · Insecure Dependencies
- Location
SKILL.md:35- Finding
Third-Party Python Dependencies Installed Without Integrity Verification
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This appears to be a legitimate livestream overlay generator, but it uploads prompts or product photos to Volcano Engine and saves generated assets locally.
Before installing, be comfortable sending livestream copy and any product photos you provide to Volcano Engine under your own API key. Avoid using unreleased or sensitive product imagery unless that third-party processing is acceptable, and run the Python dependencies in a dedicated virtual environment if possible. Expect generated files to be saved locally, possibly in a desktop folder when chat file delivery is unavailable.
SKILL.md:35Third-Party Python Dependencies Installed Without Integrity Verification
The skill claims it will not locally store, record, or cache user inputs, but later workflow steps explicitly remove backgrounds from user product photos, position them on canvas, and describe outputting derivative assets locally. That is a transparency and privacy defect: users may provide proprietary product imagery under a false assumption that no local retention or derivative file creation occurs.
The README tells users they can simply say "按戴森案例来" to invoke full generation. This phrase is short, generic, and could overlap with ordinary conversation about examples, without clear exclusion conditions or tighter trigger scope.
The API request template hard-codes the prompt as "<中文prompt>", and the surrounding guidance is written as if generation must be conducted in Chinese. There is no user opt-in, language choice, or explicit statement that the skill is intentionally limited to Chinese-speaking users for a documented reason.
The file makes contradictory privacy claims: earlier sections explicitly state that user-supplied product photos may be sent to Volcano Engine, while this API note says no images or personal data are transmitted. This can mislead users into sharing proprietary or sensitive images under false assumptions, undermining informed consent and privacy transparency.
The request schema explicitly requires the generated prompt to be "", which imposes a specific language/locale. The file does not present this as an opt-in choice or document a justified region-specific requirement, so it conflicts with the language/locale policy criteria.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl -s "https://ark.cn-beijing.volces.com/api/v3/images/generations" \
-H "Content-Type: application/json" \
-H "Authorization: Bearer $VOLCENGINE_ARK_API_KEY" \
-d '{
This repeated statement again claims that no images are transmitted, directly conflicting with the documented optional upload of user product photos. Repetition increases the chance that users and integrators will rely on the inaccurate statement, causing unintentional external disclosure of business-sensitive assets.
The API request schema hard-codes the prompt as "<中文prompt>", indicating the skill expects all generated prompts to be in Chinese. The document does not offer an alternative language or ask for user preference, so it imposes a locale/language constraint without opt-in.
The skill sends prompts and potentially user-supplied product information/images to an external image-generation API. External transmission is expected for this type of skill, but it remains a real privacy and data-handling risk if users are not clearly informed what data leaves the local environment and under what provider controls.
curl -s "https://ark.cn-beijing.volces.com/api/v3/images/generations" \
-H "Content-Type: application/json" \
-H "Authorization: Bearer <API_KEY>" \
-d '{
The skill instructs invoking shell commands to zip files and using local OS actions like creating folders and opening files on the desktop. That expands behavior beyond pure image generation into local filesystem manipulation, which can cause unintended file creation/exposure and is risky if file names or paths are later influenced by untrusted input.
The skill directs the agent to create files on the user's desktop and open them automatically without an explicit warning or consent step. In an agent environment, silent local file creation and opening can violate user expectations, expose sensitive paths or filenames, and normalize unsafe filesystem side effects.
The skill makes a concrete privacy assurance that it will not store, record, or cache user text prompts or product photos, but later workflow steps save a user-supplied product image after background removal and save generated assets locally. This creates a transparency and consent failure: users may disclose proprietary product imagery under a no-storage promise when the implementation actually persists derived copies to disk.
The markdown explicitly tells users they can say "按戴森案例来" and the skill will directly generate from a preset example. This is ambiguous because it does not clearly constrain when that phrase should activate the skill versus ordinary conversational reference to an example, and it provides no negative examples or scope limits.
The API request schema hard-codes the prompt as "<中文prompt>", indicating a Chinese-only language requirement. Elsewhere the file includes English description text, but the operational instructions do not offer user opt-in or a language choice, which is a natural-language locale policy issue.
The skill sends user prompts and potentially user product photos to an external image-generation API. External transmission is expected for this type of skill, but it remains security-relevant because users may provide proprietary brand assets or sensitive commercial materials, and the skill relies on a third-party processor outside the local environment.
curl -s "https://ark.cn-beijing.volces.com/api/v3/images/generations" \
-H "Content-Type: application/json" \
-H "Authorization: Bearer <API_KEY>" \
-d '{
The document gives conflicting instructions about whether a user product image is delivered as a separate file. Contradictory handling rules for user-provided images can lead to accidental over-sharing, retention, or packaging of sensitive product photos beyond what the user expects.
The manifest-style field only states that the skill is user-invocable, but the surrounding description does not define specific trigger phrases, activation boundaries, or exclusion cases. For a text/manifest-like file, this can lead to overly broad invocation because it is unclear exactly when the skill should activate versus when similar ecommerce-design requests should not.
The document states in one section that a separate processed user product image may be delivered, but the delivery section later says the user product image is not separately output. This inconsistency can mislead users and integrators about what artifacts are produced and retained, increasing the chance of accidental overexposure or mishandling of user-provided images.
Section 5.7 states a new deliverable 用户商品图.png is added when a user product photo is supplied. Later, the packaging section claims delivery is a fixed 7 files and says the user product image is not output separately, creating a behavior/description mismatch within the documented workflow.
The comment block under '新增交付物' explicitly says 用户商品图.png is a deliverable. Later documentation at L432 states that when a user product image is provided, it is composited into the product area and 'not separately output', which directly contradicts the earlier stated intent.
The manifest describes generating livestream visual assets, including preview and packaged delivery. While saving outputs is expected, L481-L484 go further by creating a desktop folder and invoking the OS open command to launch the preview image and folder. Launching local applications or folders is not a direct requirement of image generation itself and introduces extra system-interaction capability beyond the core design function.
The natural-language instructions are presented only in Chinese for API key acquisition, with no indication that users may choose another language. This creates a locale/language policy concern because the skill appears to enforce a specific language without opt-in or an explicitly documented regional requirement.
No suspicious patterns detected.