T09 · Insecure Skill Coding Practices
- Location
football_prediction.py:165- Finding
DeepSeek API Credential Disclosure Through an Unrestricted Base URL
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly matches its football-prediction purpose, but it sends user data and a DeepSeek API credential over an unvalidated configurable API endpoint.
Review before installing. Use this only if you are comfortable sending match feature text to DeepSeek or a configured compatible endpoint, avoid proprietary betting/account data in inputs, and do not set DEEPSEEK_BASE_URL unless it is a trusted HTTPS endpoint meant to receive that credential. Treat predictions as advisory, not as validated financial advice.
football_prediction.py:165DeepSeek API Credential Disclosure Through an Unrestricted Base URL
football_prediction.py:228Prompt Injection Through Untrusted Match-Data Files and Insufficient Response Validation
The skill advertises executable capabilities involving environment access, file I/O, and network use, but does not declare any explicit tool scope or permissions boundary. This creates an authorization ambiguity where the agent may invoke broader capabilities than users expect, increasing the risk of unintended data access, local file handling, and exfiltration to the external DeepSeek API.
The automatic trigger phrases are broad enough to match normal sports-analysis requests, which can cause the skill to run unexpectedly without clear user intent to invoke this specific workflow. Because the skill performs model/network operations and may process user-provided match data externally, overbroad triggering increases the chance of unintended data handling and opaque agent behavior.
The skill documentation states that it sends data to the DeepSeek API, but it does not clearly warn users that match features and possibly derived user-supplied content will be transmitted to a third-party external service. This undermines informed consent and can lead to privacy or compliance issues, especially if inputs contain proprietary betting data, account-linked information, or other sensitive context.
The module docstring, CLI description, help text, logs, and prompt instructions are all written exclusively in Chinese, which imposes a specific language on users. There is no indication that the skill is region-specific or that users may opt into another language, so this is a natural-language locale policy concern.
All user-facing documentation and examples in the file are presented in Chinese, and the skill does not mention that it is Chinese-only or provide any user language choice. This can constitute a language-policy issue because the skill effectively forces a specific language without explicit opt-in or justification.
The dependency is specified as requests>=2.28.0, which allows installation of any future version and does not ensure a reproducible or reviewed package set. This increases supply-chain risk and makes it impossible to guarantee that a known-safe version is used across environments.
requests>=2.28.0
Because requests is not pinned, the manifest does not show whether deployment will use a version affected by known security advisories. This creates uncertainty around exposure to published requests vulnerabilities and weakens the ability to audit or reliably secure the skill's runtime dependencies.
No suspicious patterns detected.