T09 · Insecure Skill Coding Practices
- Location
scripts/cos_client.py:151- Finding
Uploaded images use non-expiring COS object URLs and are not deleted
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This vision skill mostly does what it says, but it has real review-worthy privacy and local-file safety issues around cloud image retention and task file access.
Install only if you are comfortable sending selected local images, prompts, and results to Tencent COS and Doubao/Volcengine. Use a private COS bucket with lifecycle deletion, avoid sensitive documents unless retention is acceptable, run it in a restricted environment, and do not expose the status command to untrusted input until task IDs are validated.
scripts/cos_client.py:151Uploaded images use non-expiring COS object URLs and are not deleted
scripts/task_utils.py:103Unvalidated task IDs allow path traversal and arbitrary JSON file disclosure
scripts/task_utils.py:129Sensitive task parameters and model results are stored with implicit filesystem permissions
requirements.txt:1Third-party dependencies are installed without version or integrity constraints
scripts/vision_cli.py:173Generated-image downloader accepts untrusted URLs without network or resource limits
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
复制配置文件并填入密钥:
cp .env.example .env
在 .env 中填入你的腾讯云和豆包 API 密钥:
This code chunk’s actual purpose is cloud object storage interaction: uploading files to Tencent COS, constructing public URLs, and checking whether objects exist. While COS storage is mentioned in the description, the core declared functionality centers on computer vision and image generation tasks, which are entirely absent here. There is also no asynchronous workflow management or any usage of Doubao AI models. Therefore, the supplied code materially under-implements and does not accurately represent the declared skill purpose.
The code broadly matches part of the description: it does perform visual recognition-style requests and image generation via Doubao models, including text-to-image and image-to-image style inputs. However, important declared elements are not implemented in this chunk. There is no Tencent COS storage support, no asynchronous task execution/orchestration, and no concrete OCR or object detection logic beyond sending a generic multimodal prompt to a vision model. Because the description specifically claims async execution with Tencent COS storage and enumerates OCR/object detection capabilities, the supplied code only partially fulfills the declared purpose and materially overstates implemented functionality.
Using shell=True for process management unnecessarily exposes shell execution semantics in a tool that already handles user-driven tasks and external resources. In this skill context, which orchestrates background jobs and remote downloads, reducing command-execution surface is important because future code changes or hostile runtime environments could turn this into a command-execution vector.
# grep -v grep 排除自身,wc -l 统计行数
# 注意:这只是一个简易的软限制,不够精确但能防止瞬间炸机
cmd = "ps -ef | grep worker.py | grep -v grep | wc -l"
result = subprocess.check_output(cmd, shell=True)
count = int(result.strip())
MAX_CONCURRENT_WORKERS = 5
Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.
except:
pass
env = os.environ.copy()
env['PYTHONPATH'] = SCRIPT_DIR + os.pathsep + env.get('PYTHONPATH', '')
subprocess.Popen(
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
for image_path in args.image_path:
if not os.path.exists(image_path) and not image_path.startswith(('http://', 'https://')):
print(json.dumps({"error": f"图片文件不存在或无效URL: {image_path}"}))
return
prompt = args.prompt
if args.format and args.format in FORMAT_PRESETS:
The README explicitly advertises automatic upload of local images to Tencent COS, but the introduction and usage guidance do not provide a prominent, upfront warning that user-provided files will be transmitted to third-party cloud services. In a vision skill, inputs commonly contain sensitive documents, screenshots, or personal data, so this omission increases the risk of unintended data disclosure and privacy/compliance violations.
The skill advertises operations that inherently require sensitive capabilities—environment access for secrets, local file reads/writes, network egress, and shell execution via the CLI—but it does not declare any tool scope or permission boundaries. In an agent setting, this weakens least-privilege controls and makes it easier for the skill to access or exfiltrate local images, prompts, credentials, or generated outputs beyond what a user may expect.
The skill states that local images are uploaded to Tencent COS and prompts/images are sent to external AI services, but it does not present a prominent user warning about this data transfer. In this context, users may supply screenshots, invoices, contracts, or other sensitive documents, so undisclosed cloud upload creates privacy, compliance, and data exfiltration risk.
The code uploads arbitrary local files to Tencent COS using configured cloud credentials and returns a directly accessible URL, but it provides no consent boundary, allowlist, or privacy warning. In an agent skill context, this creates a real data exfiltration risk if untrusted workflow inputs can influence which local file is uploaded.
This is the concrete sink where a local file is transmitted to remote cloud storage. Because the function accepts a caller-supplied local path and constructs a retrievable URL, it can be abused by surrounding agent logic to exfiltrate sensitive local files, especially in a vision skill that may process user-provided paths or intermediate files.
upload_params['ContentType'] = content_type
# 使用高级上传接口
response = self.client.upload_file(**upload_params)
# 构造访问URL
url = self._build_url(remote_key)
Data is uploaded to cloud storage (S3 / GCS / Azure Blob). This may be a legitimate backup or exfiltration to an external bucket. Manual review is recommended.
if len(sys.argv) > 1:
test_file = sys.argv[1]
cos_client = COSClient()
result = cos_client.upload_file(test_file)
print(result)
else:
print("Usage: python3 cos_client.py <file_path>")
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
try:
self.logger.info(f"开始视觉识别: {image_url}")
response = requests.post(url, headers=headers, json=payload, timeout=60)
response.raise_for_status()
return response.json()
except Exception as e:
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
try:
self.logger.info(f"开始视觉识别: {image_url}")
response = requests.post(url, headers=headers, json=payload, timeout=60)
response.raise_for_status()
return response.json()
except Exception as e:
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
try:
self.logger.info(f"开始视觉识别: {image_url}")
response = requests.post(url, headers=headers, json=payload, timeout=60)
response.raise_for_status()
return response.json()
except Exception as e:
This code posts user-supplied image URLs and text prompts to an external service using requests.post. While there is logging for operation start/failure, the code does not include any disclosure that user content will be transmitted off-system, and that behavior is not otherwise explained in a user-facing warning within this file.
The generate_image method sends prompts and possibly reference image URLs to a third-party endpoint for image generation. Although the action is logged, there is no user disclosure in comments/docstrings or prompts warning that potentially sensitive content will leave the local environment.
This code performs file deletions in clean_old_tasks and file writes in save_task, but there is no confirmation prompt or user-facing logging when these safety-relevant filesystem operations occur. The Chinese docstrings/comments describe behavior for developers, but they do not clearly disclose to end users that task data may be automatically persisted and later deleted.
This file embeds natural-language descriptions and prompt presets in Chinese, including user-visible defaults for recognition behavior. Because the skill does not offer language selection or clearly justify a Chinese-only locale requirement, it creates a language policy concern for users who did not opt into that locale.
The code invokes subprocess.check_output with shell=True, which is inherently riskier because it executes through a shell and can be influenced by shell semantics or environment manipulation. Although the command string is currently static, this pattern expands attack surface and can become exploitable if any part of the command later becomes user-controlled or if PATH/shell environment is compromised.
# grep -v grep 排除自身,wc -l 统计行数
# 注意:这只是一个简易的软限制,不够精确但能防止瞬间炸机
cmd = "ps -ef | grep worker.py | grep -v grep | wc -l"
result = subprocess.check_output(cmd, shell=True)
count = int(result.strip())
MAX_CONCURRENT_WORKERS = 5
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
env = os.environ.copy()
env['PYTHONPATH'] = SCRIPT_DIR + os.pathsep + env.get('PYTHONPATH', '')
subprocess.Popen(
[sys.executable, WORKER_SCRIPT, task_id],
env=env,
stdout=subprocess.DEVNULL,
The skill writes recognition output directly to the user-specified output path, which affects local filesystem state and may overwrite existing files. The code announces success after writing, but does not provide advance disclosure, confirmation, or overwrite protection for this safety-relevant operation.
This code saves downloaded content directly to the path supplied by the user, which modifies local files and can overwrite existing data. Although there is a post-action print confirming where the file was saved, there is no pre-action warning, confirmation, or descriptive disclosure near the write operation about the file-write side effect.
The file's docstring and multiple user-facing prompt strings are written to require Chinese output/instructions, such as quality suffixes and default prompts. This appears to impose a specific language/locale without any opt-in or documented justification, which violates the language-choice policy.
This code uploads local image paths to COS and later passes the resulting URLs to vision/generation APIs, which transmits user-provided data off the local system. Although there is internal logging, there is no confirmation prompt or clear user-facing disclosure in the file warning that local images will be uploaded to remote services.
No suspicious patterns detected.