Back to skill

Security audit

Image Translator 1.0.0

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward cloud translation helper, but users should understand that text, images, image URLs, and translation-service keys are sent to Xiangji/Tosoiot APIs.

Install only if you are comfortable sending the text, images, image URLs, and Xiangji/Tosoiot API credentials you provide to the listed third-party translation endpoints. Avoid regulated, confidential, or internal-only images/URLs unless approved, and prefer environment variables or another secret-handling wrapper instead of putting keys directly in shell commands or CI logs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/image_translate.py:43
Finding

Translation credentials exposed through process command-line arguments

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs users to submit local image files, image URLs, and text for translation to third-party endpoints, but it does not clearly warn users that this content leaves the local environment and is transmitted to external services. This can lead to inadvertent disclosure of sensitive documents, personal data, or proprietary content, especially because translation use cases often involve user-supplied materials.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This finding identifies an explicit external API endpoint used for translation. External transmission is expected for a cloud translation skill, but it remains security-relevant because user-provided text and files may be sent off-platform to a third party, creating confidentiality and compliance risks if users are not adequately informed.

Content

Scanner excerpt · SKILL.md (reported line 192)May include surrounding context.

md
| 功能 | 端点 |
|------|------|
| 文本翻译 | `POST https://api.tosoiot.com/task/v1/text/translate` |
| 图片翻译(文件) | `POST https://api2.tosoiot.com/` |
| 图片翻译(URL 批量) | `POST https://api.tosoiot.com/` |

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This endpoint is used for URL-based batch image translation, which means externally hosted image references and potentially their contents are sent to a third-party service. In context, this is intended functionality rather than a hidden exfiltration channel, but it is still dangerous if users are unaware that image data and referenced resources are processed outside their environment.

Content

Scanner excerpt · SKILL.md (reported line 194)May include surrounding context.

md
|------|------|
| 文本翻译 | `POST https://api.tosoiot.com/task/v1/text/translate` |
| 图片翻译(文件) | `POST https://api2.tosoiot.com/` |
| 图片翻译(URL 批量) | `POST https://api.tosoiot.com/` |

---

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file presents all headings and explanatory text in Chinese, which can amount to a language-policy issue when users are not given an opt-in or alternative locale. The file does not indicate that the language restriction is intentional for a region-specific audience or that other language versions are available.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script uploads a user-specified local image file to a third-party remote API, but it does not present any explicit warning, confirmation, or data-handling notice before transmission. This can expose sensitive local images or embedded metadata to an external service, especially in agent or automation contexts where users may not realize the privacy boundary being crossed.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/image_translate.py (reported line 64)May include surrounding context.

python
cmd.extend(["-F", f"EngineType={engine_type}"])
    
    try:
        result = subprocess.run(cmd, capture_output=True, text=True, timeout=120)
        if result.returncode == 0:
            return json.loads(result.stdout)
        else:

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code file contains natural-language instructions that force a specific language/locale for users, including the module docstring and command help text context. The policy allows locale constraints only when user choice is offered or the restriction is clearly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/text_translate.py (reported line 15)May include surrounding context.

python
import urllib.request
import urllib.error

API_URL = "https://api.tosoiot.com/task/v1/text/translate"


def translate_text(api_key: str, texts: list, source_language: str, target_language: str, vendor: str = None) -> dict:

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The natural-language documentation and command help examples are written only in Chinese, with no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without opt-in can be a natural-language policy concern unless the locale restriction is clearly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.