T09 · Insecure Skill Coding Practices
- Location
scripts/deepresearch.py:64- Finding
API Key Exposed Through Command-Line Arguments
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This appears to be a legitimate Baidu Qianfan report generator, but it needs Review because it sends research content to a third-party API, encourages command-line API keys, and automatically approves remote workflow steps.
Install only if you are comfortable sending research prompts, generated outlines, and report contents to Baidu Qianfan and receiving remote download links. Prefer `QIANFAN_API_KEY` from a protected environment or credential store instead of `--api-key`, avoid confidential inputs unless approved, and monitor API quota/costs for long-running runs.
scripts/deepresearch.py:64API Key Exposed Through Command-Line Arguments
SKILL.md:211Unpinned Third-Party Dependency Installation
The skill instructs the agent to access environment variables for secrets and to invoke a network-capable script, but it does not declare any tool scope or permission boundaries. This creates an over-privilege and transparency problem: an orchestrator may grant broader access than intended, and users are not clearly informed that secrets and external network calls are required.
The file requires the final user-facing response to follow a fixed Chinese template verbatim, including exact Chinese phrases that must not be changed. This imposes a specific language on all users without offering a language choice or documenting a justified locale restriction.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
请求示例(使用 version):
curl -X POST "https://qianfan.baidubce.com/v2/agent/deepresearch/create" \
-H "Authorization: Bearer {api_key}" \
-H "Content-Type: application/json" \
-d '{"version": "lite"}'
The structured_outline schema example sets locale to 简体中文, and later examples repeat this locale, which can imply a fixed language expectation. The document does not state that locale is configurable or user-selected, creating a potential language/locale policy issue.
The documentation explicitly encourages automatically sending "跳过" for clarification and "确认" for outline approval, which removes user review at two decision points. In a research/report-generation skill, this can cause the system to proceed with misunderstood scope, unwanted assumptions, or unreviewed content structure, increasing the risk of inaccurate or policy-problematic outputs without informed user consent.
The documented workflow explicitly auto-skips clarification and auto-confirms the generated outline, removing meaningful user review before sending follow-up actions to the external research agent. In a research/report-generation skill, this can cause unintended scope expansion, inaccurate or risky outputs, and silent transmission of user intent without informed approval.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
def create_conversation():
"""Step 1: 创建会话,获取 conversation_id"""
resp = requests.post(
f"{BASE_URL}/agent/deepresearch/create",
headers=HEADERS,
json={"version": VERSION},
The /run call transmits the query payload, conversation state, interrupt_id, and structured outline to an external service. Because this skill is designed to automate full research execution, user prompts and derived content may be forwarded off-platform without an explicit per-run consent or data-sensitivity warning, making unintended disclosure more likely.
early_stop: callable(event) -> bool,返回 True 时提前退出
"""
events = []
with requests.post(
f"{BASE_URL}/agent/deepresearch/run",
headers=HEADERS,
json=payload,
Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.
headers=HEADERS,
json=payload,
stream=True,
timeout=None, # 不设整体超时,用空闲超时控制
) as resp:
resp.raise_for_status()
last_data_time = time.time()
The HTTP request for the SSE stream is made with timeout=None, which allows the connection to remain open indefinitely at the requests layer. Although the code tracks IDLE_TIMEOUT while processing chunks, a peer that stalls before yielding data or drip-feeds data can keep the process, socket, and worker occupied for a long time, enabling denial-of-service or resource exhaustion in an automated agent environment.
headers=make_headers(api_key),
json=payload,
stream=True,
timeout=None, # 不设整体超时,通过 IDLE_TIMEOUT 控制
) as resp:
resp.raise_for_status()
The script automatically submits the generated outline back to the remote DeepResearch service using the fixed query "确认" and the extracted structured_outline, without any user review or approval step. In an agent setting, this can cause unintended external actions, unwanted compute/resource consumption, and commitment to a report structure the user did not validate, which is especially relevant because the skill advertises a fully automatic end-to-end workflow.
The file-output section and final response examples show generated report files with url and download_url, indicating report artifacts are created and made retrievable. The documentation does not warn users that generated content may be stored remotely or exposed through downloadable links, which is relevant to data handling and privacy expectations.
The natural-language docstring, CLI descriptions, and user-facing messages are presented exclusively in Chinese, with no indication that users can select another language or locale. This can violate language/locale policy where skills should not force a specific language without user opt-in.
Detected: suspicious.exposed_secret_literal