Back to skill

Security audit

02 Script Generator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a small Chinese short-drama script generator that uses a configured model API; its main risk is that user-provided story/IP data goes to the configured endpoint.

Install only if you are comfortable sending the supplied ip_info content to the model endpoint you configure. Use a trusted HTTPS API_BASE, a scoped API key with usage limits, and avoid including confidential manuscripts or business data unless that provider is approved for it.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
skill.js:5
Finding

Unrestricted API Endpoint Can Expose Credentials and User-Provided IP Data

Content
View full analysis

Vulnerability Details

File Location: skill.js, lines 5–27
Vulnerability Type: Unvalidated outbound request destination and sensitive-data transmission
Risk Level: High

Vulnerable Code

js
const API_KEY = env.API_KEY;
const API_BASE = env.API_BASE;
const MODEL_NAME = env.MODEL_NAME;

const prompt = `
根据以下IP信息,生成${duration}秒抖音/番茄短剧剧本,共${episode_count}集。
要求:节奏快、冲突强、台词短。
输出严格JSON格式:
{
  "scenes": [{"scene":"","role":"","lines":"","action":"","duration":0}],
  "total_duration": ${duration}
}`;

const res = await fetch(`${API_BASE}/chat/completions`, {
  method: "POST",
  headers: {
    "Authorization": "Bearer " + API_KEY,
    "Content-Type": "application/json"
  },
  body: JSON.stringify({
    model: MODEL_NAME,
    messages: [
      { role: "user", content: JSON.stringify(ip_info) },
      { role: "user", content: prompt }
    ]
  })
});

Technical Analysis

The Skill requires access to an external language-model service to perform its declared script-generation function. Sending ip_info to such a service is therefore functionally relevant. However, API_BASE is accepted directly from the environment and interpolated into the request URL without validating its scheme, hostname, port, or resolved network address.

Consequently, the bearer credential in API_KEY and the complete serialized ip_info object are sent to whichever destination the environment specifies. The code does not require HTTPS, restrict requests to approved model-provider domains, or reject loopback, private, link-local, and other internal destinations.

This exceeds minimum safe privilege because the Skill needs permission to contact a trusted model provider, not arbitrary external or internal hosts. The documentation states that model API configuration is required, but it does not clearly warn users that their supplied IP information is transmitted to a third party.

Attack Path

1 ...[truncated 1725 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace unrestricted API_BASE configuration with a fixed endpoint or an explicit allowlist of approved model-provider origins.
  2. Parse the value with the standard URL API and reject malformed URLs, embedded credentials, unexpected ports, fragments, and query components.
  3. Require https: and reject plaintext HTTP endpoints.
  4. Resolve and validate destination addresses, rejecting loopback, private, link-local, multicast, and reserved ranges. Revalidate redirects and either disable them or restrict every redirect target to the same allowlist.
  5. Use separate, provider-scoped credentials with minimal permissions, strict usage limits, and rotation support.
  6. Do not send the authorization header when the validated destination is not an approved provider.
  7. Clearly disclose in SKILL.md and user-facing documentation that ip_info is transmitted to the selected external model provider.
  8. Minimize transmitted data and allow callers to remove secrets or unnecessary proprietary fields before submission.
  9. Validate required environment values at startup and fail closed when configuration is missing or unsafe.
  10. Add automated tests covering HTTP URLs, attacker-controlled domains, internal addresses, malformed URLs, DNS rebinding considerations, and cross-origin redirects.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description states the skill generates scripts in Chinese for specific platforms, which is a natural-language locale constraint. There is no indication that users can choose another language or explicitly opt into this language restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The embedded prompt instructs the model in Chinese and implicitly requires Chinese output, but the skill does not provide any language or locale opt-in mechanism. That is a natural-language policy issue because it imposes a specific language choice without user selection or documented regional justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill sends user-provided ip_info to an external API endpoint along with bearer-authenticated access, but the code provides no validation of API_BASE, no disclosure to the user that their data will leave the local environment, and no minimization of what is transmitted. In this context, ip_info may contain sensitive or proprietary content, so silent exfiltration to a configurable remote service creates a real privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file contains user-facing skill instructions only in Chinese, which can amount to an implicit language constraint. The policy allows fixed language or locale only when there is explicit user opt-in or a clearly documented regional justification, neither of which appears here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.