T09 · Insecure Skill Coding Practices
- Location
scripts/image_translate.py:43- Finding
Translation credentials exposed through process command-line arguments
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a straightforward cloud translation helper, but users should understand that text, images, image URLs, and translation-service keys are sent to Xiangji/Tosoiot APIs.
Install only if you are comfortable sending the text, images, image URLs, and Xiangji/Tosoiot API credentials you provide to the listed third-party translation endpoints. Avoid regulated, confidential, or internal-only images/URLs unless approved, and prefer environment variables or another secret-handling wrapper instead of putting keys directly in shell commands or CI logs.
scripts/image_translate.py:43Translation credentials exposed through process command-line arguments
The skill instructs users to submit local image files, image URLs, and text for translation to third-party endpoints, but it does not clearly warn users that this content leaves the local environment and is transmitted to external services. This can lead to inadvertent disclosure of sensitive documents, personal data, or proprietary content, especially because translation use cases often involve user-supplied materials.
This finding identifies an explicit external API endpoint used for translation. External transmission is expected for a cloud translation skill, but it remains security-relevant because user-provided text and files may be sent off-platform to a third party, creating confidentiality and compliance risks if users are not adequately informed.
| 功能 | 端点 |
|------|------|
| 文本翻译 | `POST https://api.tosoiot.com/task/v1/text/translate` |
| 图片翻译(文件) | `POST https://api2.tosoiot.com/` |
| 图片翻译(URL 批量) | `POST https://api.tosoiot.com/` |
This endpoint is used for URL-based batch image translation, which means externally hosted image references and potentially their contents are sent to a third-party service. In context, this is intended functionality rather than a hidden exfiltration channel, but it is still dangerous if users are unaware that image data and referenced resources are processed outside their environment.
|------|------|
| 文本翻译 | `POST https://api.tosoiot.com/task/v1/text/translate` |
| 图片翻译(文件) | `POST https://api2.tosoiot.com/` |
| 图片翻译(URL 批量) | `POST https://api.tosoiot.com/` |
---
This markdown file presents all headings and explanatory text in Chinese, which can amount to a language-policy issue when users are not given an opt-in or alternative locale. The file does not indicate that the language restriction is intentional for a region-specific audience or that other language versions are available.
The script uploads a user-specified local image file to a third-party remote API, but it does not present any explicit warning, confirmation, or data-handling notice before transmission. This can expose sensitive local images or embedded metadata to an external service, especially in agent or automation contexts where users may not realize the privacy boundary being crossed.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
cmd.extend(["-F", f"EngineType={engine_type}"])
try:
result = subprocess.run(cmd, capture_output=True, text=True, timeout=120)
if result.returncode == 0:
return json.loads(result.stdout)
else:
This code file contains natural-language instructions that force a specific language/locale for users, including the module docstring and command help text context. The policy allows locale constraints only when user choice is offered or the restriction is clearly documented and justified, which is not present here.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
import urllib.request
import urllib.error
API_URL = "https://api.tosoiot.com/task/v1/text/translate"
def translate_text(api_key: str, texts: list, source_language: str, target_language: str, vendor: str = None) -> dict:
The natural-language documentation and command help examples are written only in Chinese, with no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without opt-in can be a natural-language policy concern unless the locale restriction is clearly justified.
No suspicious patterns detected.