T09 · Insecure Skill Coding Practices
- Location
upload-mix.py:14- Finding
Hard-Coded Application Signing Credential Enables Request Forgery
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill does what it says, but it uploads local files using a local bearer token and a hard-coded signing key without strong scoping or consent controls.
Review before installing. Use this only for files you intend to send to AutoGLM, avoid sensitive documents unless you trust the service and storage behavior, and do not pass returned file URLs to other tools unless you are comfortable with the uploaded content being accessible through that workflow. The publisher should add explicit consent checks, tighter file/path scoping, and remove or rotate the embedded signing key.
upload-mix.py:14Hard-Coded Application Signing Credential Enables Request Forgery
Referenced artifact was not completely inspected
"filename": "SKILL.md",
The skill performs network operations, including token retrieval from a local HTTP service and file upload to an external API, but does not declare any tool scope or permission boundary. This increases the risk that an agent or user invokes network-capable behavior without clear review of what data leaves the host.
The skill description says it uploads local files but does not prominently warn that local file contents are transmitted to an external service. Users may provide sensitive documents or images without understanding that the full contents will leave the local environment and be stored remotely.
The documentation frames the upload result as a reusable file URL/resource for downstream APIs, which can expose the contents of local files through a remotely hosted link. If the URL is accessible beyond the original session or shared with other tools, sensitive local data may be disclosed more broadly than intended.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
## Token Retrieval
When the script starts, it automatically sends an HTTP GET request to the local service to retrieve a token:
| Item | Value |
|------|------|
The output instructions explicitly tell the agent to extract the uploaded file URL and pass it to downstream APIs, encouraging onward disclosure of uploaded local content. This creates a straightforward path for sensitive file contents to propagate across services with limited visibility or control.
The script silently retrieves a bearer token from a local HTTP service and uses it for outbound authentication without informing the user or verifying the trust boundary of that local service. In a local agent environment, this can enable unintended use of sensitive credentials and makes abuse easier if the skill is triggered without the operator understanding that local auth material will be consumed.
The script automatically uploads an arbitrary local file to a remote third-party endpoint and includes an authorization token, but provides no user-facing notice, confirmation, or preview of what data is being transmitted. In an agent-skill context, this increases the risk of silent exfiltration of sensitive local files and associated credentials or session tokens when invoked by another tool or workflow.
No suspicious patterns detected.