T09 · Insecure Skill Coding Practices
- Location
scripts/common.py:677- Finding
Unvalidated Remote Result URL Enables Server-Side Request Forgery
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This appears to be a real Baidu Cloud video translation skill, but it needs Review because it uploads user media to cloud services and uses cloud/netdisk authority with weak disclosure and URL scoping.
Review before installing. Use this only for media you are comfortable sending to Baidu Cloud VOD and, if enabled, Baidu Netdisk. Use least-privileged Baidu credentials, do not paste AK/SK values into chat or files, watch for paid processing charges, and be careful with delete-project or update-task operations.
scripts/common.py:677Unvalidated Remote Result URL Enables Server-Side Request Forgery
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
headers = {"Content-Type": "video/mp4"}
with open(video_path, 'rb') as f:
response = requests.put(upload_url, data=f, headers=headers, timeout=600)
if response.status_code in [200, 100]:
if debug:
The skill description emphasizes translation features but does not clearly warn users that video, audio, subtitle, and possibly biometric voice content will be uploaded to and processed by a third-party cloud service. Because this skill handles potentially sensitive media, lack of explicit disclosure undermines informed consent and can lead to unintentional exposure of private or regulated data.
Referenced artifact was not completely inspected
python3 scripts/translate.py <视频> --source zh --target en
Referenced artifact was not completely inspected
python3 scripts/translate.py <视频> --source zh --target en
Referenced artifact was not completely inspected
python3 scripts/translate.py <视频> --source zh --target en
Referenced artifact was not completely inspected
python3 scripts/translate.py <视频> --source zh --target en
Referenced artifact was not completely inspected
python3 scripts/translate.py <视频> --source zh --target en
Referenced artifact was not completely inspected
python3 scripts/translate.py <视频> --source zh --target en
Referenced artifact was not completely inspected
python3 scripts/translate.py <视频> --source zh --target en
This skill performs multiple outbound network operations to Baidu VOD and downloads arbitrary result URLs, yet the declared permissions apparently do not include network access. Undeclared network capability is a real security concern because it enables data exfiltration, remote task creation, and cloud-side actions without transparent user consent.
This skill performs multiple outbound network operations to Baidu VOD and downloads arbitrary result URLs, yet the declared permissions apparently do not include network access. Undeclared network capability is a real security concern because it enables data exfiltration, remote task creation, and cloud-side actions without transparent user consent.
The trigger rules include broad phrases such as requests to 'translate video', 'video dubbing', and especially 'query or manage translation projects/tasks', without strong scoping to explicit user intent or this specific cloud provider workflow. Overbroad triggering can cause the skill to activate in unrelated contexts and prompt for local file paths or begin cloud-processing workflows the user did not intend, increasing privacy and consent risks.
The skill instructs users to export BAIDU_VOD_AK and BAIDU_VOD_SK credentials and shows concrete secret-handling patterns, but it does not warn against exposing those values in chat, logs, shell history, or generated command output. This creates a realistic risk of credential leakage, especially in agent-mediated environments where commands and transcripts may be retained.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
if method == "GET":
response = requests.get(url, headers=headers, params=params, timeout=30)
elif method == "POST":
response = requests.post(url, headers=headers, json=json_data, timeout=30)
elif method == "PUT":
response = requests.put(url, headers=headers, json=json_data, timeout=30)
else:
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
elif method == "POST":
response = requests.post(url, headers=headers, json=json_data, timeout=30)
elif method == "PUT":
response = requests.put(url, headers=headers, json=json_data, timeout=30)
else:
raise ValueError(f"不支持的 HTTP 方法: {method}")
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
def check_bdpan_installed():
"""检查 bdpan 是否安装"""
try:
result = subprocess.run(
["bdpan", "version"],
capture_output=True,
text=True,
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
def check_bdpan_logged_in():
"""检查 bdpan 是否已登录"""
try:
result = subprocess.run(
["bdpan", "whoami"],
capture_output=True,
text=True,
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
if debug:
print(f"执行: {' '.join(cmd)}")
result = subprocess.run(cmd, capture_output=True, text=True, timeout=600)
if result.returncode == 0:
if debug:
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
if debug:
print(f"执行: {' '.join(cmd)}")
result = subprocess.run(cmd, capture_output=True, text=True, timeout=600)
if result.returncode == 0:
if debug:
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
def list_netdisk_files(path="", debug=False):
"""列出网盘文件"""
cmd = ["bdpan", "ls", path, "--json"]
result = subprocess.run(cmd, capture_output=True, text=True, timeout=30)
if result.returncode == 0:
try:
The module docstring, usage instructions, and all descriptive text are presented only in Chinese. This creates a locale/language policy issue because users are not offered a language choice or an alternative locale, and the file does not document a justified region-specific constraint.
No suspicious patterns detected.