T09 · Insecure Skill Coding Practices
- Location
scripts/temu_image_search.py:258- Finding
Unrestricted API origin allows sensitive image transmission to untrusted or plaintext endpoints
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears to do the advertised Temu image-search task, but it stores login tokens in multiple local places and allows images or requests to be sent to overly broad network destinations.
Review before installing. This skill will upload product images to GeekBI and reuse a local GeekBI login. Install only if you are comfortable with those images leaving your environment, and avoid using it on private/internal image URLs. The publisher should restrict API destinations to the declared GeekBI HTTPS origin and store tokens in one protected user-level location rather than mirroring them into project or skill directories.
scripts/temu_image_search.py:258Unrestricted API origin allows sensitive image transmission to untrusted or plaintext endpoints
scripts/temu_image_search.py:185User-controlled image URLs enable server-side request forgery
scripts/geekbi_auth.py:68Bearer authentication state is unnecessarily replicated into Skill and workspace directories
The skill claims to perform image upload and visual product search, but the reported implementation instead queries site-list resources and lacks the advertised image-processing and filtering functionality. This is dangerous because operators and users may grant network and shell privileges based on a false understanding of purpose, while the actual code path does something else and evades meaningful review or policy controls.
The skill claims to perform image upload and visual product search, but the reported implementation instead queries site-list resources and lacks the advertised image-processing and filtering functionality. This is dangerous because operators and users may grant network and shell privileges based on a false understanding of purpose, while the actual code path does something else and evades meaningful review or policy controls.
The README says "安装后直接用中文描述目标即可", which directs users to interact in Chinese only. Under the policy criteria, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly justified or alternatives are offered.
The skill instructs use of file reads, network access, and shell execution but does not declare any explicit tool scope or permission boundaries. This is dangerous because an agent may invoke powerful capabilities implicitly, increasing the chance of overbroad file access, unintended command execution, or network exfiltration without clear policy gating.
该 markdown 文件适用 SQP-1。L03 在调用描述中列出“根据商品图片判断选品机会”等较宽泛的触发语义,且整段触发表述为长串场景枚举,没有明确排除条件或负例,容易与一般商品分析/选品讨论重叠,导致技能在并非明确要求图搜时被调用。
L14 明确规定“面向用户使用中文业务名称”,属于对输出语言/语言风格的强制约束。根据规则,若未提供语言或地区选择、也无清晰的合规性理由,则构成自然语言层面的语言/locale 政策违反。
The instruction requires using the server-returned Chinese msg to prompt the user, which imposes a specific language on all users. Under the policy, forcing a language without user opt-in or a documented, justified locale constraint is a natural-language policy violation.
The document explicitly instructs all Temu skills to share one authentication state and to persist credentials in multiple locations, including a shared system path and per-skill/current-working-directory copies. That broadens credential exposure beyond the minimum scope of this image-search skill and increases the chance of unintended cross-skill access, token leakage, or reuse by less-trusted skills operating under the same environment.
This Python file contains user-facing natural-language strings entirely in Chinese, beginning with the module docstring and continuing throughout exceptions and CLI messages. Under the policy, forcing a specific language without user opt-in is a locale-policy violation unless the constraint is explicitly documented and justified, which is not present in this file.
When given an http/https image URL, the script fetches the image from a remote host and then uploads the image to an external API service, but there is no explicit user-facing consent or warning at the point of transmission. This can leak sensitive internal URLs, metadata, or private image contents and is more concerning in an agent context where inputs may come indirectly from users or other tools.
This file contains natural-language strings for the module docstring, CLI description, argument help text, and error messages exclusively in Chinese. Under the policy, forcing a specific language without opt-in or justification is a natural-language policy violation applicable to all file types.
The display name, description, and default prompt are written entirely in Chinese, with no indication that language selection is optional or that the skill is limited to a Chinese-speaking context. This can violate a language/locale policy when users are not given an explicit opt-in or alternative locale.
The module docstring and user-facing messages are written in Chinese, and the file does not indicate that language is configurable or user-selectable. This can violate a language or locale policy when skills must not force a specific language without opt-in.
The manifest says the skill supports local images, session attachments, image URLs, Data URI, Base64, and standard input for Temu image search. The implementation additionally accepts generic file:// URIs and arbitrary http/https URLs directly from the CLI, which broadens input acquisition behavior beyond the manifest's explicitly stated user-facing sources such as session attachments and may reach arbitrary local or remote content.
No suspicious patterns detected.