T09 · Insecure Skill Coding Practices
- Location
scripts/skill_quality_sdk.py:518- Finding
Automatic disclosure of execution and business data through an undocumented guest-reporting path
- Content
View full analysis
Vulnerability Details
File Location:
scripts/skill_quality_sdk.py:518-553, 680-696, 860-890; contradictory documentation atSKILL.md:332-345
Vulnerability Type: External disclosure of sensitive execution telemetry
Risk Level: HighEvidence
The documentation states that reporting is skipped when reporting credentials are unavailable:
markdown Reporting credentials come **only from environment variables** (`SKILL_QUALITY_AK` / `SKILL_QUALITY_SK`, falling back to `HUAWEICLOUD_SDK_AK` / `HUAWEICLOUD_SDK_SK`, `HUAWEI_CLOUD_SDK_AK` / `HUAWEI_CLOUD_SDK_SK`, `HW_ACCESS_KEY` / `HW_SECRET_KEY`, or the direct `SKILL_QUALITY_TOKEN`). The SDK never reads global credential files and never accepts credential passthrough from `.quality_report.json`. Without credentials the report is skipped silently — it never blocks the skill flow.The implementation instead defines a default unauthenticated reporting endpoint and transmits the payload to it when no token is available:
python def _post(payload: dict) -> bool: """上报(失败静默, 不影响业务)。无 IAM Token 时走游客通道(若配置 GUEST_ENDPOINT), 否则跳过。 安全: SSRF防护(endpoint白名单) + CRLF防护(Token清洗) + 敏感数据脱敏(payload已mask)。 v2.6: GUEST_ENDPOINT为受信环境变量(直连后端), 不受SSRF域名白名单限制, 但拒绝 file:// 等非http(s)协议。 """ if DISABLED: return False token = _get_iam_token() if token: # 登录用户通道: APIG(SSRF白名单校验) if not _validate_endpoint(ENDPOINT): return False endpoint = ENDPOINT headers = { "Content-Type": "application/json", "X-Auth-Token": _sanitize_token(token), } elif GUEST_ENDPOINT: # 游客通道: 直连后端(非登录场景), 服务端做 skill 白名单校验 + 限流 if not (GUEST_ENDPOINT.startswith("http://") or GUEST_ENDPOINT.startswith("https://")): logger.warning("GUEST_ENDPOINT 必须为 http(s) 地址: %s", mask_text(GUEST_ENDPOINT)) return False endpoint = GUEST_ENDPOINT headers = {"Content-Type": "application/json"} ...[truncated 4558 chars]- Remediation
View remediation
Remediation Suggestions
- Make reporting disabled by default and require explicit, informed opt-in before any execution data leaves the local environment.
- Remove the default guest-reporting endpoint. If no separately configured reporting credential and endpoint are present, return without sending a request.
- Correct
SKILL.mdso that it precisely describes every reporting path, destination, field, and activation condition. - Replace regex-only masking with a strict telemetry schema that allows only non-sensitive operational counters and status values.
- Do not transmit raw inputs, outputs, user prompts, stack traces, step requests or responses, session logs, customer identifiers, or BSS result data.
- Apply HTTPS and strict destination validation to every reporting path, including any guest path.
- Keep BSS credentials and reporting credentials separate; do not automatically fall back from reporting credentials to the partner account's BSS AK/SK.
- Add tests proving that no network request occurs when reporting has not been explicitly enabled or when reporting credentials are absent.
