T09 · Insecure Skill Coding Practices
- Location
scripts/generate_image.py:584- Finding
Unrestricted Webhook Can Exfiltrate User Prompts and Generated-Media URLs
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly matches its AI image/video generation purpose, but optional notification and download paths can expose prompts or fetch arbitrary URLs without enough safeguards.
Review this before installing if prompts, reference media, or generated-media URLs may be sensitive. Only set FEISHU_WEBHOOK_URL to a trusted HTTPS Feishu endpoint you control, avoid inherited webhook values, be cautious with --download in shared or sensitive network environments, and prefer pinned dependencies when setting up the Python environment.
scripts/generate_image.py:584Unrestricted Webhook Can Exfiltrate User Prompts and Generated-Media URLs
scripts/generate_image.py:539Unvalidated Result URL Enables SSRF-Style Requests and Unbounded Downloads
scripts/generate_image.py:33Predictable Shared Temporary Cache Permits Local Cache Poisoning and Symlink Attacks
SKILL.md:47Documentation Recommends Installation of an Unpinned Third-Party Dependency
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
with open(file_path, 'rb') as f:
files = {'file': (os.path.basename(file_path), f)}
headers = {'X-Api-Key': API_KEY}
response = requests.post(FILE_UPLOAD_URL, headers=headers, files=files, timeout=120)
response.raise_for_status()
result = response.json()
The script will exfiltrate user prompts, result URLs, and error details to an arbitrary webhook endpoint taken directly from the FEISHU_WEBHOOK_URL environment variable. Because this outbound notification is optional, third-party, and not tightly validated or consent-gated, it creates a real data-leak/SSRF-style risk if the environment variable is misconfigured or attacker-controlled.
}
}
response = requests.post(
FEISHU_WEBHOOK_URL,
json=content,
headers={"Content-Type": "application/json"},
Referenced artifact was not completely inspected
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。
Referenced artifact was not completely inspected
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。
Referenced artifact was not completely inspected
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。
Referenced artifact was not completely inspected
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。
Referenced artifact was not completely inspected
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。
Referenced artifact was not completely inspected
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。
Referenced artifact was not completely inspected
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。
Referenced artifact was not completely inspected
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。
Referenced artifact was not completely inspected
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。
Referenced artifact was not completely inspected
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。
Referenced artifact was not completely inspected
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。
Referenced artifact was not completely inspected
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。
Referenced artifact was not completely inspected
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。
Referenced artifact was not completely inspected
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。
Referenced artifact was not completely inspected
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。
Referenced artifact was not completely inspected
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。
Referenced artifact was not completely inspected
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。
Referenced artifact was not completely inspected
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。
Referenced artifact was not completely inspected
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。
Referenced artifact was not completely inspected
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。
Referenced artifact was not completely inspected
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。
Referenced artifact was not completely inspected
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。
Referenced artifact was not completely inspected
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。
Detected: suspicious.dynamic_code_execution