T09 · Insecure Skill Coding Practices
- Location
scripts/generate_image.py:21- Finding
Access Key and User Prompts Transmitted over Plaintext HTTP
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This image-generation skill is mostly coherent, but it sends user access keys and prompts to a hard-coded server over unencrypted HTTP and handles the key in exposed command-line arguments.
Install only if you trust the operator of the hard-coded image service and are comfortable sending your access key and prompts over unencrypted HTTP. Treat the key as exposed after use, avoid sensitive prompts, and expect generated files to be written to a predictable temporary path unless changed.
scripts/generate_image.py:21Access Key and User Prompts Transmitted over Plaintext HTTP
SKILL.md:13Access Key Exposed through Command-Line Arguments
scripts/generate_image.py:23Predictable Shared Temporary Output Path Permits Symlink and Overwrite Attacks
The script sends the access key in an HTTP header to a server over plain HTTP, which allows network attackers to intercept the key and associated prompts via sniffing or man-in-the-middle attacks. Because the key appears to control paid quota and account access, compromise could lead to unauthorized usage, data exposure, and account abuse.
The skill instructs the agent to invoke a Python script that performs network-backed key validation and image generation, but the manifest declares no explicit tool scope or allowed-tools restrictions. This creates a capability mismatch: an installer or runtime may treat the skill as lower risk than it really is, while the skill can still cause external requests and handle secrets, increasing the chance of unsafe execution or policy bypass.
The description advertises broad triggers such as '生成图片、画图、AI绘图、文生图、生成一张图', which can cause the skill to activate for loosely related user requests without strong intent confirmation. In practice this can lead to unintended execution, unnecessary secret prompting, or invocation in contexts where the user did not actually want this skill to run.
The runtime instruction to execute on 'any image description' is overly ambiguous and can treat ordinary conversational text as a command to call the generation script. Because the skill stores and reuses the user's access key across the session, accidental triggering could consume quota, transmit sensitive prompts externally, or perform unintended billable actions.
The skill's docstring, CLI description, help text, and runtime messages are written only in Chinese, which imposes a specific language on users without any opt-in or language-selection mechanism. The file does not document a region-specific requirement that would justify this locale restriction.
The script transmits user prompts and an access key to an external hard-coded server, which is security-relevant because sensitive user input and credentials leave the local environment. In this skill context, external transmission is expected for an image-generation API, but it becomes dangerous because the destination is a fixed third-party host and, more importantly, uses insecure transport.
payload = {"prompt": prompt, "size": "1024x1024", "quality": quality, "n": n}
try:
r = requests.post(f"{SERVER}/generate", headers=headers, json=payload, timeout=200)
except Exception as e:
print(f"[ERROR] 连接服务器失败: {e}", file=sys.stderr)
sys.exit(1)
The manifest describes a text-to-image generation skill for creating images from prompts, but this script also exposes a separate /quota capability to inspect remaining quota and usage state. Querying account quota is adjacent to the service, but it is still a distinct behavior not reflected in the stated skill description.
No suspicious patterns detected.