T09 · Insecure Skill Coding Practices
- Location
scripts/venice.py:437- Finding
Unrestricted Audio URL Fetching Enables SSRF and Resource Exhaustion
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill mostly does what it says, but it can fetch arbitrary URLs and upload local or fetched media to Venice AI without strong scoping, size limits, or consent checks.
Review before installing in shared, enterprise, or agent-autonomous environments. Use it only with data you are willing to send to Venice AI and any model/search providers involved. Avoid passing internal URLs, localhost addresses, cloud metadata URLs, private files, secrets, or untrusted prompts that will be rendered in generated HTML. Prefer sandboxing or network egress rules if URL inputs remain enabled.
scripts/venice.py:437Unrestricted Audio URL Fetching Enables SSRF and Resource Exhaustion
scripts/venice-upscale.py:114Image Upscaling URL Input Enables SSRF, Internal-Content Upload, and Memory Exhaustion
scripts/venice-image.py:181Unescaped Image Prompts Permit Stored HTML Injection in Generated Galleries
Output: {out_dir.as_posix()}
The code chunk is narrowly focused on image editing via Venice AI and does not implement the broad set of platform features described. Its primary purpose is a CLI utility for single-image and multi-image edit operations, including file/URL handling and writing output images. While 'AI editing' is accurately represented, the description materially overstates the skill's capabilities by claiming many unrelated functions not present in this code.
The description substantially overstates the capabilities represented by this code chunk. The script is narrowly focused on Venice image APIs: image generation, style/model listing, optional web-search-assisted image generation, and background removal. It does not implement the broad multi-modal platform described, including text, audio, embeddings, social search, video, music, upscaling, or general AI editing. While over-declaration alone is not always problematic, here the declared primary purpose ('complete Venice AI platform') is materially broader than the actual behavior of this specific code chunk, so this is a mismatch.
The description presents the skill as an all-in-one Venice AI platform spanning many modalities and services. However, the actual code only implements music generation against Venice AI audio endpoints, plus related support actions like quoting, polling, downloading, metadata saving, model listing, and cleanup. There is no evidence in this chunk of the other declared capabilities. This is a material description-to-behavior mismatch because the declared primary purpose is much broader than what the code actually does.
This code chunk's primary purpose is much narrower than the declared description. The description claims a full Venice AI platform with numerous modalities and services, while the actual code only handles one feature: image upscaling. That is a material description-to-behavior mismatch because the supplied code does not substantiate the broad declared capability set. The URL download behavior is supportive of the upscaling feature rather than a separate major capability, but it does show external resource access limited to fetching an input image and calling the Venice API. No evidence is present here for text generation, search, speech, video, music, editing, or other listed functions.
The description advertises a broad, all-in-one Venice AI platform with numerous multimodal and search capabilities. The supplied code chunk is narrowly focused on Venice video operations only. It interacts exclusively with video-related API endpoints (/video/quote, /video/queue, /video/retrieve, /video/complete), handles local/remote media inputs, and saves generated MP4 output. There is no evidence in this chunk of text, search, embedding, audio transcription/synthesis, image generation/editing, background removal, upscaling, or music-generation functionality. While video creation is one capability mentioned in the description, the declared purpose materially overstates what this code chunk actually does.
The description substantially overstates the implemented functionality. The code does support several declared capabilities: text/chat generation, image analysis, embeddings, TTS, speech-to-text, model browsing, and it exposes flags for web search and X/Twitter search within chat requests. However, there is no code for image generation, background removal, video creation, music generation, upscaling, or AI editing. The primary purpose is a Venice AI CLI for a subset of platform APIs, not the full platform described. No concerning undeclared capabilities are present beyond normal auth/config reading and HTTP access needed to call the API.
Referenced artifact was not completely inspected
| `venice-video.py` | Video generation (Sora, WAN, Runway) |
Referenced artifact was not completely inspected
| `venice-video.py` | Video generation (Sora, WAN, Runway) |
Documenting a --no-validate option can allow requests to bypass model or parameter validation, which weakens safety checks and may enable unexpected downstream behavior or accidental routing to unsupported endpoints. In a skill that already has broad networked capabilities, encouraging validation bypass increases the chance of misuse and makes auditing harder.
|---------|----------|
| `VENICE_API_KEY not set` | Set env var or configure in `~/.clawdbot/clawdbot.json` |
| `Invalid API key` | Verify at [venice.ai/settings/api](https://venice.ai/settings/api) |
| `Model not found` | Run `--list-models` to see available; use `--no-validate` for new models |
| Rate limited | Check `--show-usage` output |
| Video stuck | Videos can take 1-5 min; use `--timeout 600` for long ones |
| Vision not working | Ensure you're using a vision-capable model (e.g., `qwen3-vl-235b-a22b`) |
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
ap.add_argument("--resolution", help="Resolution preset (1K, 2K, 4K)")
ap.add_argument("--aspect-ratio", help="Aspect ratio (1:1, 16:9, etc.)")
ap.add_argument("--safe-mode", action="store_true", default=False, help="Blur adult content (default: false)")
ap.add_argument("--no-safe-mode", action="store_false", dest="safe_mode", help="Disable safe mode")
ap.add_argument("--hide-watermark", action="store_true", help="Remove Venice watermark")
ap.add_argument("--embed-exif", action="store_true", help="Embed prompt info in image EXIF metadata")
ap.add_argument("--lora-strength", type=int, help="LoRA strength 0-100 for applicable models")
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
ap.add_argument("--complete", metavar="QUEUE_ID", help="Clean up a previously downloaded video (use with --model)")
ap.add_argument("--list-models", action="store_true", help="List available video models and exit")
ap.add_argument("--quote", action="store_true", help="Show price estimate and exit (no generation)")
ap.add_argument("--no-validate", action="store_true", help="Skip model validation")
args = ap.parse_args()
api_key = require_api_key()
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
ap.add_argument("--complete", metavar="QUEUE_ID", help="Clean up a previously downloaded video (use with --model)")
ap.add_argument("--list-models", action="store_true", help="List available video models and exit")
ap.add_argument("--quote", action="store_true", help="Show price estimate and exit (no generation)")
ap.add_argument("--no-validate", action="store_true", help="Skip model validation")
args = ap.parse_args()
api_key = require_api_key()
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
def get_api_key() -> str | None:
"""
Get API key from multiple sources in order:
1. VENICE_API_KEY environment variable
2. ~/.clawdbot/clawdbot.json at skills.entries.venice-ai.env.VENICE_API_KEY
(also checks venice-ai-media for backward compatibility)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
def get_api_key() -> str | None:
"""
Get API key from multiple sources in order:
1. VENICE_API_KEY environment variable
2. ~/.clawdbot/clawdbot.json at skills.entries.venice-ai.env.VENICE_API_KEY
(also checks venice-ai-media for backward compatibility)
The skill advertises and documents capabilities that require environment access, file I/O, and network access, but it does not declare an explicit tool scope such as permissions or allowed-tools. This creates an over-broad execution surface where an agent may invoke the skill without clear boundaries, increasing the chance of unintended data access or exfiltration through third-party API calls.
The metadata and framing present the skill as a general-purpose solution for nearly any AI task, without narrow activation boundaries or exclusions. In agent environments, vague scope encourages over-invocation and may cause sensitive prompts, files, or URLs to be sent to this external service when a more limited local tool would be safer.
The README repeatedly markets the skill as a complete platform for many unrelated tasks, but does not specify concrete triggers, guardrails, or conditions for safe use. That makes accidental misuse more likely, especially in autonomous agents that select skills based on broad descriptions.
The documentation emphasizes privacy but does not clearly and consistently warn that prompts, uploaded files, fetched URLs, web searches, and X/Twitter searches may transit third-party infrastructure depending on the selected feature or model. This can mislead users into sending sensitive material under a false assumption of universal privacy, especially where Grok/X search or remote scraping are involved.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
### Get Your API Key
1. Create account at [venice.ai](https://venice.ai)
2. Go to [venice.ai/settings/api](https://venice.ai/settings/api)
3. Click "Create API Key" → copy the key (starts with `vn_...`)
The documentation explicitly describes an option to scrape URLs found in user messages, which can cause user-provided content or referenced resources to be fetched and transmitted to an external service without a clear privacy warning or consent flow. In an agent skill context, this increases the risk of unintended data disclosure, SSRF-like behavior against internal URLs provided by users, or fetching sensitive intranet resources if downstream safeguards are weak.
The top-level docstring says "Generate images via Venice AI Image API," and the main argument parser description repeats that framing, yet the code includes a --background-remove mode that edits an existing image instead of generating one. This is an active documentation-to-code contradiction about the script's actual function.
The module docstring and CLI description present this script as a tool to generate images via the Venice AI Image API, but it also exposes a separate background-removal workflow. Background removal is a different image-editing capability, so the documented purpose of this file does not fully match the behavior implemented in code.
This endpoint can receive either remote URLs or uploaded local image content for background removal, creating a real data-transfer risk if users assume processing is local. In a skill ecosystem, tools may be invoked on user files automatically, so undisclosed outbound transmission of image contents can expose sensitive personal or internal data.
Accepts local file path, HTTP URL, or data URL.
Returns PNG bytes with transparent background.
"""
url = "https://api.venice.ai/api/v1/image/background-remove"
if image_src.startswith(("http://", "https://")):
# JSON payload with URL
When given a local file, the script reads the image bytes and uploads them to a remote Venice API endpoint, but the user-facing interface does not clearly warn that local content will leave the machine. In an agent-skill context, this can cause unintended exfiltration of sensitive images if the tool is invoked on private files under the assumption it works locally.
The script transparently converts local image, video, or audio files into data URLs and later submits them to the remote Venice API, but it does not provide an explicit warning or consent checkpoint before transmitting local content off-host. In a CLI handling potentially sensitive media, this creates a real privacy and data-exfiltration risk, especially because users may not realize that supplying a local path results in full file upload to a third-party service.
No suspicious patterns detected.