T09 · Insecure Skill Coding Practices
- Location
_env.sh:4- Finding
Arbitrary Shell Execution Through Unsafe .env Loading
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly does what it says, but it has unsafe credential/config handling and webhook helper behaviors that deserve manual review before installation.
Install only if you trust this publisher and memelord.com with the prompts, template data, generated media metadata, and API-backed requests you send. Do not use a `.env` file from an untrusted source, avoid putting webhook secrets directly on the command line, and treat downloaded media URLs and output paths as untrusted unless you control them.
_env.sh:4Arbitrary Shell Execution Through Unsafe .env Loading
scripts/ai-video-meme.sh:46Webhook Secrets Exposed Through Process Arguments
scripts/verify-webhook.sh:61Failed Webhook Verification Reveals the Correct HMAC
The documented behavior and declared metadata do not cleanly match the operational capabilities described in the markdown, especially around external API use and helper operations. When a skill understates or misstates what it can do, users and policy layers may approve it under false assumptions, increasing the chance of unexpected network access, credential use, or file operations.
The documented behavior and declared metadata do not cleanly match the operational capabilities described in the markdown, especially around external API use and helper operations. When a skill understates or misstates what it can do, users and policy layers may approve it under false assumptions, increasing the chance of unexpected network access, credential use, or file operations.
The documented behavior and declared metadata do not cleanly match the operational capabilities described in the markdown, especially around external API use and helper operations. When a skill understates or misstates what it can do, users and policy layers may approve it under false assumptions, increasing the chance of unexpected network access, credential use, or file operations.
Referenced artifact was not completely inspected
| `scripts/ai-meme.sh` | `POST /api/v1/ai-meme` | Generate fresh image memes |
Referenced artifact was not completely inspected
| `scripts/ai-meme.sh` | `POST /api/v1/ai-meme` | Generate fresh image memes |
Referenced artifact was not completely inspected
| `scripts/ai-meme.sh` | `POST /api/v1/ai-meme` | Generate fresh image memes |
Referenced artifact was not completely inspected
| `scripts/ai-meme.sh` | `POST /api/v1/ai-meme` | Generate fresh image memes |
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# shellcheck shell=bash
# Auto-loads local environment overrides for the Memelord skill.
ENV_FILE="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)/.env"
if [[ -f "$ENV_FILE" ]]; then
# Export everything defined in .env so child processes inherit the values.
set -a
At this point the script enables automatic export and sources the .env file, causing any credentials or sensitive values in that file to become environment variables for child processes. In an agent skill, this increases the chance of unintended credential exposure to invoked tools, logs, plugins, or remote services, and also lets a tampered .env alter execution through environment-driven behavior.
# Auto-loads local environment overrides for the Memelord skill.
ENV_FILE="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)/.env"
if [[ -f "$ENV_FILE" ]]; then
# Export everything defined in .env so child processes inherit the values.
set -a
# shellcheck disable=SC1090
source "$ENV_FILE"
The skill explicitly instructs use of shell commands and networked helper scripts but does not declare any tool scope such as permissions or allowed-tools. This creates a trust and enforcement gap: a host may allow broader execution than users expect, including external API calls and file writes, which is risky for a skill that handles API keys and downloads remote content.
The skill encourages webhook callbacks to arbitrary external URLs without warning users about data exposure, request forgery risks, or the sensitivity of job metadata sent off-platform. In contexts where prompts, asset URLs, or identifiers may be sensitive, silent exfiltration to third-party endpoints is a meaningful privacy and security risk.
The script automatically sources a local .env file and exports all variables to child processes without any validation, scoping, or user disclosure. This can expose secrets to downstream commands and allows a locally modified .env file to influence the behavior of any subprocess launched by the skill, which is risky in an agent context where external tools or networked commands may run.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
process.stdout.write(JSON.stringify(body));
NODE
curl -sS -X POST 'https://www.memelord.com/api/v1/ai-meme/edit' \
-H "Authorization: Bearer $MEMELORD_API_KEY" \
-H 'Content-Type: application/json' \
--data-binary @"$TMP_BODY" \
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
process.stdout.write(JSON.stringify(body));
NODE
curl -sS -X POST 'https://www.memelord.com/api/v1/ai-video-meme/edit' \
-H "Authorization: Bearer $MEMELORD_API_KEY" \
-H 'Content-Type: application/json' \
--data-binary @"$TMP_BODY" \
The script explicitly supports a user-supplied webhook URL and states that generated results will be posted there, but it provides no warning, validation, or restriction around where those results may be sent. In an agent or automation context, this creates a real data egress risk because prompts, generated content, job metadata, or follow-up results could be transmitted to arbitrary third-party endpoints without meaningful user awareness.
This script sends user-provided prompt data, optional webhook details, and authentication-backed requests to an external service at memelord.com. While external API calls are expected for this skill, it is still a true security-relevant data transmission finding because the script exports potentially sensitive input off-host and can initiate downstream delivery to attacker-controlled webhook infrastructure if those options are used.
process.stdout.write(JSON.stringify(body));
NODE
curl -sS -X POST 'https://www.memelord.com/api/v1/ai-video-meme' \
-H "Authorization: Bearer $MEMELORD_API_KEY" \
-H 'Content-Type: application/json' \
--data-binary @"$TMP_BODY" \
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
node -p 'JSON.stringify({prompt: process.argv[1]})' "$PROMPT" > "$TMP_BODY"
fi
curl -sS -X POST 'https://www.memelord.com/api/v1/ai-meme' \
-H "Authorization: Bearer $MEMELORD_API_KEY" \
-H 'Content-Type: application/json' \
--data-binary @"$TMP_BODY" \
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
node -p 'JSON.stringify({prompt: process.argv[1]})' "$PROMPT" > "$TMP_BODY"
fi
curl -sS -X POST 'https://www.memelord.com/api/v1/ai-meme' \
-H "Authorization: Bearer $MEMELORD_API_KEY" \
-H 'Content-Type: application/json' \
--data-binary @"$TMP_BODY" \
The fallback image retrieval logic performs an HTTPS GET to whatever URL the remote API returns, including one redirect hop, with no allowlist or host validation. This expands the skill from 'send prompt to meme API' into arbitrary outbound fetching directed by API-controlled data, which can be abused for SSRF-like network access, unexpected data egress, or downloading untrusted content to disk.
This shell script performs a network call to a remote service with a bearer token from an environment variable, and optionally writes the returned JSON to a user-specified file. While the behavior is inferable from the script, there is no confirmation prompt or explicit user-facing warning in comments or usage text that sensitive credentials are used and that data is sent to an external service and may be saved locally.
This markdown skill description says the skill is for 'AI-powered meme generation, meme editing, meme video generation for your projects' but does not define any trigger phrases, scope boundaries, or negative examples. In a skill catalog, such broad natural-language descriptions can overlap with many casual meme-related requests and make invocation conditions unclear.
The instructions tell users to download remote assets directly into the workspace with curl, but omit warnings about trusting the source URL, overwriting files, or handling untrusted content. While the downloaded files are expected media, this still introduces a path for bringing attacker-controlled content into the local environment without cautionary guidance.
This shell script sends the instruction, template data, and template identifier to an external HTTPS endpoint and authenticates with MEMELORD_API_KEY. Although comments describe the API call for readers of the source, there is no runtime warning, confirmation, or user-facing notice that local meme/template content is being uploaded to a remote service.
The manifest describes meme generation and editing functionality, but the script additionally sources a local _env.sh file, which can import arbitrary environment variables or shell-side configuration. While loading an API key is needed, executing a general environment bootstrap script is a broader capability than the stated meme-generation purpose itself justifies.
This shell skill writes image data to a user-specified path via fs.writeFileSync when --png is used, but the code itself provides no confirmation prompt or runtime notice before creating files. The top-of-file comments describe the behavior, but there is no direct user-facing warning at the point of execution about local file creation.
No suspicious patterns detected.