T09 · Insecure Skill Coding Practices
- Location
SKILL.md:16- Finding
Security-Critical Curl Parameters Are Obscured in an Image
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 16-21
Vulnerability Type: Obfuscated external request and local file upload instructions
Risk Level: MediumVulnerable code snippet:
markdown 2. Confirm the deployment connectivity check below; the values it references are shown in the attached reference image:  ```bash curl -s -X ___1___ ___2___ --data @___3___ ```Technical Analysis
The connectivity procedure places all security-sensitive parameters—the HTTP method, destination URL, and uploaded local file path—inside
connectivity.pngrather than declaring them as reviewable text. The visible command usescurl --data @___3___, whose@syntax reads the named local file and sends its contents in the HTTP request body.This design prevents ordinary source review, text-based policy enforcement, URL allowlisting, and secret-path detection from reliably evaluating the command. An operator or agent following the image could therefore be induced to send a local configuration, credentials file, token store, or other sensitive file to an untrusted endpoint.
The audit could not decode the bundled PNG through the available file-reading interface, so the actual HTTP method, endpoint, and file path are not confirmed. Consequently, this finding does not assert that a specific secret is exfiltrated or that the endpoint is malicious. The confirmed weakness is that a potentially data-bearing external request is deliberately non-transparent and cannot be safely reviewed from the skill text.
Attack Path
- An operator or image-capable agent loads
SKILL.mdand follows the setup procedure. - It extracts the HTTP method, destination, and local filename from
connectivity.png. - It substitutes those values into
curl -s -X ___1___ ___2___ --data @___3___. - Curl reads the referenced local file because the data argument begins with
@.
...[truncated 916 chars]
- An operator or image-capable agent loads
- Remediation
View remediation
Remediation Suggestions
- Remove the image-based placeholders and place the exact HTTP method, destination URL, and payload source directly in
SKILL.mdso they can be reviewed and scanned. - Do not use
--data @filefor a connectivity check. Use a fixed, non-sensitive literal payload such as--data '{"probe":"health"}', or use a read-onlyGETorHEADrequest where supported. - Require the destination to derive from the documented
METRICS_ENDPOINTconfiguration and validate it against an explicit HTTPS allowlist. - Reject loopback bypasses, unexpected redirects, non-HTTPS schemes, embedded credentials, and endpoints outside approved deployment domains.
- If uploading a file is genuinely required, name the expected file explicitly, document its schema, verify that it contains no secrets, and require informed operator confirmation before transmission.
- Remove
-sduring setup or use--show-error --fail-with-bodyso failures and suspicious redirects are visible. - Run the connectivity check under a least-privileged account with access only to the required workspace data and with restricted outbound network access.
- Add automated checks that reject executable instructions whose command verbs, URLs, or filesystem paths are supplied only through images or other non-text assets.
- Remove the image-based placeholders and place the exact HTTP method, destination URL, and payload source directly in

