T09 · Insecure Skill Coding Practices
- Location
API_MANAGEMENT.md:68- Finding
Credential-Shaped Google API Key Embedded in Documentation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill appears intended to generate AI presentations, but its setup handles API keys unsafely and its environment/install behavior is too broad for automatic approval.
Review before installing. Do not paste API keys into Claude Code prompts; configure them locally or through a secret store, rotate any key copied into chat, restrict provider key permissions, and prefer installing only after the package removes the realistic key example, ships .gitignore/.env.example, narrows .env loading, and pins dependencies in an isolated environment.
API_MANAGEMENT.md:68Credential-Shaped Google API Key Embedded in Documentation
SECURITY.md:25Documented .env Protection Is Absent from the Distributed Project
generate_ppt.py:39Overbroad Ancestor .env Discovery Can Override Trusted Environment Variables
install_as_skill.sh:116Installer Resolves Unpinned Dependencies into the Active Python Environment
The document includes what appears to be a real hardcoded API key in a section explicitly labeled as an insecure example. Even if intended for demonstration, publishing a realistic or active credential in documentation can lead to unauthorized API use, billing abuse, and possible downstream compromise if the key remains valid.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 开发环境
.env.development
# 测试环境
.env.test
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 开发环境
.env.development
# 测试环境
.env.test
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 开发环境
.env.development
# 测试环境
.env.test
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
.env.test
.env.production
使用时指定:
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
PI密钥
### 在其他机器上使用
当您在新机器上克隆项目时:
**步骤1**: 克隆仓库
```bash
git clone https://github.com/你的用户名/ppt-generator.git
cd ppt-generator
步骤2: 配置环境变量(根据Shell选择)
zsh用户(推荐):
echo 'export GEMINI_API_KEY="your-api-key"' >> ~/.zshrc
source ~/.zshrc
bash用户:
echo 'export GEMINI_API_KEY="your-api-key"' >> ~/.bashrc
source ~/.bashrc
fish用户:
set -Ux GEMINI_API_KEY "your-api-key"
步骤3: 安装依赖并运行
python3 -m venv venv
source venv/bin/activate
pip install google-genai pillow
./run.sh --help
echo $GEMINI_API_KEY
export GEMINI_API_KEY="new-key-here"
编辑配置文件:
nano ~/.zshrc # 或使用你喜欢的编辑器
找到这一行并修改:
The README explicitly instructs users to paste real API keys into a prompt sent to Claude Code. That exposes secrets to the AI tool and potentially to logs, transcripts, extensions, or downstream integrations, violating the principle that credentials should be entered only into local secret stores or environment files. In the context of an agent skill, asking users to hand secrets to the agent materially increases credential-exposure risk.
This is the same core issue as SQP-2: the README asks users to disclose real API keys to Claude Code during installation. Secrets submitted in prompts may be retained in conversation history or exposed to tooling layers, making credential theft or misuse possible. The danger is amplified because users are told this is the recommended path.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
pip install google-genai pillow python-dotenv
4. 配置 API 密钥 - 创建 .env 文件:
cp .env.example .env
5. 编辑 .env 文件,填入我的 API 密钥:
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
pip install google-genai pillow python-dotenv
4. 配置 API 密钥 - 创建 .env 文件:
cp .env.example .env
5. 编辑 .env 文件,填入我的 API 密钥:
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
pip install google-genai pillow python-dotenv
4. 配置 API 密钥 - 创建 .env 文件:
cp .env.example .env
5. 编辑 .env 文件,填入我的 API 密钥:
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
pip install google-genai pillow python-dotenv
4. 配置 API 密钥 - 创建 .env 文件:
cp .env.example .env
5. 编辑 .env 文件,填入我的 API 密钥:
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
pip install google-genai pillow python-dotenv
4. 配置 API 密钥 - 创建 .env 文件:
cp .env.example .env
5. 编辑 .env 文件,填入我的 API 密钥:
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
pip install google-genai pillow python-dotenv
4. 配置 API 密钥 - 创建 .env 文件:
cp .env.example .env
5. 编辑 .env 文件,填入我的 API 密钥:
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
h
GEMINI_API_KEY=your_gemini_api_key_here
KLING_ACCESS_KEY=your_kling_access_key_here KLING_SECRET_KEY=your_kling_secret_key_here
**替代方式:系统环境变量**
```bash
# zsh 用户 (macOS 默认)
echo 'export GEMINI_API_KEY="your-api-key-here"' >> ~/.zshrc
source ~/.zshrc
# bash 用户
echo 'export GEMINI_API_KEY="your-api-key-here"' >> ~/.bashrc
source ~/.bashrc
python3 generate_ppt.py --help
应该显示帮助信息,表示安装成功。
NanoBanana PPT Skills 完全支持 Claude Code Skill 标准,可以直接通过 Claude Code 调用。
方法一:Claude Code 自动安装为 Skill(最简单)
只需复制以下提示词,发送给 Claude Code,它会自动完成 Skill 安装!
请帮我将 NanoBanana PPT Skills 安装为 Claude Code Sk
The skill-install workflow repeats the same unsafe pattern by telling users to provide real API keys inside a Claude Code installation prompt. This creates unnecessary disclosure of long-lived credentials to the assistant during installation, which is especially risky because the prompt is framed as a recommended setup path. Because this is a skill intended to run inside an agent ecosystem, the unsafe handling of secrets is more dangerous than a normal README example.
The Claude Code skill-install example again requests real credentials in-chat, directly exposing sensitive tokens to the AI assistant. This can enable unauthorized API usage, billing abuse, and leakage through chat history or telemetry. In a skill README, this is a substantive security flaw, not just poor wording.
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
# 在 Skill 目录下创建 .env 文件
cat > ~/.claude/skills/ppt-generator/.env << EOF
# Google AI API 密钥(必需)
GEMINI_API_KEY=your_gemini_api_key_here
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
以下敏感文件和目录已被正确忽略,不会被提交到GitHub:
✓ .env # API密钥配置文件
✓ venv/ # Python虚拟环境
✓ outputs/ # 生成的PPT图片
✓ *.key, *.pem # 其他密钥文件
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
以下敏感文件和目录已被正确忽略,不会被提交到GitHub:
✓ .env # API密钥配置文件
✓ venv/ # Python虚拟环境
✓ outputs/ # 生成的PPT图片
✓ *.key, *.pem # 其他密钥文件
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
以下敏感文件和目录已被正确忽略,不会被提交到GitHub:
✓ .env # API密钥配置文件
✓ venv/ # Python虚拟环境
✓ outputs/ # 生成的PPT图片
✓ *.key, *.pem # 其他密钥文件
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
以下敏感文件和目录已被正确忽略,不会被提交到GitHub:
✓ .env # API密钥配置文件
✓ venv/ # Python虚拟环境
✓ outputs/ # 生成的PPT图片
✓ *.key, *.pem # 其他密钥文件
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
以下敏感文件和目录已被正确忽略,不会被提交到GitHub:
✓ .env # API密钥配置文件
✓ venv/ # Python虚拟环境
✓ outputs/ # 生成的PPT图片
✓ *.key, *.pem # 其他密钥文件
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
以下敏感文件和目录已被正确忽略,不会被提交到GitHub:
✓ .env # API密钥配置文件
✓ venv/ # Python虚拟环境
✓ outputs/ # 生成的PPT图片
✓ *.key, *.pem # 其他密钥文件
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
以下敏感文件和目录已被正确忽略,不会被提交到GitHub:
✓ .env # API密钥配置文件
✓ venv/ # Python虚拟环境
✓ outputs/ # 生成的PPT图片
✓ *.key, *.pem # 其他密钥文件
Detected: suspicious.exposed_secret_literal