T05 · Unauthorized Access and Privilege Escalation
- Location
upload-mix.py:33- Finding
Unrestricted Local File Upload to Third-Party Storage
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill does what it says, but it uploads local files to a public third-party URL and uses local authentication without enough safeguards or scoping.
Review carefully before installing. Use this only for non-sensitive images you are comfortable sending to AutoGLM and potentially exposing through a public URL. Do not point the upload script at documents, credentials, private screenshots, regulated data, or arbitrary local files; the skill should add confirmation, image validation, size limits, private URLs, and secret handling before broad use.
upload-mix.py:33Unrestricted Local File Upload to Third-Party Storage
image-recognition.py:11Hard-Coded Shared Application Signing Key
The skill is presented primarily as image recognition, but its workflow also instructs uploading arbitrary local files to an external service and relying on a local token service. That behavioral gap is security-relevant because users or agent operators may not realize the skill exfiltrates local content before analysis.
The skill explicitly requires uploading a local image to a remote service that returns a public URL, which is a direct data exfiltration path for user-provided local files. Because the URL is publicly accessible, the exposure is broader than normal third-party processing and can enable unauthorized access if the link leaks or is guessable.
The documented end-to-end workflow operationalizes exfiltration by directing the agent to take a local image, upload it externally, and then process the returned public link. In context, this makes the risk more dangerous because the unsafe transfer is not incidental; it is the prescribed default path for local files.
The skill performs network-relevant operations but does not declare any tool scope or allowed-tools boundary. In an agent setting, missing explicit permission boundaries increases the chance that the skill can invoke network actions without transparent review or policy enforcement.
The instructions tell the agent to upload local images to obtain a publicly accessible URL, but they do not warn that this may expose private or sensitive image contents to third parties. This creates a meaningful privacy and consent risk, especially for personal photos, documents, screenshots, or regulated data.
The script silently retrieves an authorization token from a local service and then uses it to authenticate to an external API, without informing the user that local credentials are being accessed. This can violate user expectations and weakens transparency around credential use; if a malicious or compromised skill is executed in this environment, automatic token pickup could enable unauthorized use of local secrets.
The script transmits user-provided image URLs and prompts to a third-party AutoGLM API, but it does not clearly disclose that user content is leaving the local environment. This creates a privacy and data-handling risk, especially because image URLs and prompts may contain sensitive internal resources, personal data, or confidential business information.
The script hardcodes APP_ID and APP_KEY even though the skill is described as token-based, creating embedded long-lived credentials in distributable code. If these credentials are valid, anyone with access to the skill can reuse them against the remote API, enabling unauthorized use, abuse attribution to the owner, or credential harvesting; the mismatch between the manifest and implementation increases suspicion.
The script sends the selected local file to an external API without any user-facing confirmation, preview, or warning about off-device transmission. Because this skill is meant to operate on user-supplied local images and may also be used on documents containing OCR-readable sensitive data, silent upload can lead to inadvertent disclosure of private or regulated information.
The skill is presented as image recognition, but the helper script uploads arbitrary local files to a remote service before analysis, which materially changes the trust boundary and data exposure risk. In this skill context, users may provide sensitive local images or documents expecting analysis, not realizing the content is transmitted externally, so the mismatch makes the behavior more dangerous than a purely local preprocessing step.
No suspicious patterns detected.