T09 · Insecure Skill Coding Practices
- Location
SKILL.md:293- Finding
Generated User Media Is Public by Default
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:293-294
Vulnerability Type: Insecure privacy configuration
Risk Level: MediumVulnerable Code
text | image | file or string | ✓ | Unified image input. Can be multipart file upload, http/https URL, or base64/data URL | | public | boolean | | Whether the video appears in the public feed (default: true) |Technical Analysis
The Skill accepts potentially sensitive user content, including portrait images, base64-encoded images, and scripts. However, the documented API behavior makes generated videos public when the optional
publicfield is omitted.Although the initial JSON example explicitly specifies
"public": false, the general workflow and request schema do not require agents to preserve that setting or obtain explicit consent before enabling public publication. An agent-generated request that omits the field will therefore rely on the API's public-by-default behavior.This violates privacy-by-default principles. Security-sensitive visibility controls should fail closed, especially when processing personal images or user-authored content.
Attack Path
- A user provides a portrait image and script for video generation.
- The agent constructs a request to the LovelyBots API.
- The agent omits the optional
publicfield because the workflow does not require it. - The API applies its documented default value of
true. - The generated video is published to the service's public feed without an explicit publication decision from the user.
Impact Assessment
This issue may expose user-submitted images, generated likenesses, scripts, and resulting videos to the public. The affected scope is limited to content submitted through this Skill and generated by the external service; it does not grant local system privileges or access to unrelated files.
Potential consequences include unintended disclosure of personal media, reputati ...[truncated 54 chars]
- Remediation
View remediation
Remediation Suggestions
- Require
"public": falsein every request template and agent workflow. - Instruct agents never to omit the
publicfield. - Set
"public": trueonly after obtaining explicit, informed user consent for that specific video. - Add a prominent warning explaining that public videos may appear in the LovelyBots public feed.
- If the API is under the project owner's control, change the server-side default to
false. - Reject or pause ambiguous requests rather than assuming that publication is authorized.
- Add tests verifying that requests without explicit publication consent are always submitted with
"public": false.
- Require
