T08 · Insecure Dependencies
- Location
references/requirements.txt:6- Finding
Unpinned third-party dependencies create mutable supply-chain exposure
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a straightforward Tencent Cloud chat API helper, but users should treat anything they send through it as leaving their local environment.
Install only if you intend to use Tencent Cloud LKE. Do not send secrets, regulated personal data, internal document URLs, or confidential prompts unless your organization permits Tencent Cloud processing; pin dependency versions before production use and avoid passing sensitive values through fields that may be printed to logs.
references/requirements.txt:6Unpinned third-party dependencies create mutable supply-chain exposure
scripts/sse_chat.py:126Sensitive workflow values may be exposed through console logging
The skill clearly instructs users to call a remote Tencent Cloud endpoint, but the manifest does not declare any tool scope or allowed network capability. This creates a transparency and governance gap: an agent may exfiltrate prompts, identifiers, or file metadata over the network without an explicit permission boundary for users or platform policy to enforce.
The skill describes sending session identifiers, visitor identifiers, message content, and optional file URLs to a third-party cloud service, but provides no privacy notice, consent guidance, or data-handling warning. In an agent setting, this can cause inadvertent disclosure of personal, confidential, or regulated data to an external processor without the operator realizing what leaves the environment.
The example explicitly performs external transmission of conversation data to a remote SSE endpoint. While this is core to the skill's purpose, it is still security-relevant because prompts, identifiers, and optional document references may be sent off-platform and streamed back, increasing exposure if users assume the interaction is local or trusted by default.
curl --location 'https://wss.lke.cloud.tencent.com/v1/qbot/chat/sse' \
--header 'Content-Type: application/json' \
--data '{
"session_id": "a29bae68-cb1c-489d-8097-6be78f136acf",
This markdown file documents required request fields including a visitor identifier and free-form message content sent to a remote HTTPS endpoint, but it does not include any warning about privacy, data handling, or sensitivity of transmitted user data. Under the markdown-specific SQP-2 criteria, user-facing documentation should warn when skill behavior may affect user data or privacy.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
| 460037 | 搜索资源已用尽 |
| 460038 | 该AppID请求存在异常行为 |
## cURL 完整示例
### 基础对话
The workflow example shows sending custom variables such as a user ID and order type to the service, which can affect privacy and user data exposure. The documentation presents this as a normal usage pattern without any caution about minimizing, redacting, or protecting sensitive identifiers.
The file’s natural-language interface, usage text, help strings, and runtime messages are entirely in Chinese, which imposes a specific language/locale on users. There is no indication that the tool is region-specific or that users can opt into another language.
The script sends user-supplied message content plus optional metadata such as custom variables, visitor labels, and file information to Tencent Cloud, but it does not provide an explicit warning, consent prompt, or data-minimization guidance before transmission. In a reusable skill context, this can lead operators to unintentionally forward sensitive data to a third-party service, creating privacy and compliance risk rather than a code-execution flaw.
This code performs an outbound HTTPS POST to a third-party Tencent endpoint containing conversation content, identifiers, and optional metadata. External transmission is expected for this skill's purpose, but it still represents a real security/privacy boundary because sensitive prompts or attached metadata may be exfiltrated outside the local trust domain if users are not adequately informed or if untrusted inputs are passed through blindly.
print("-" * 50)
try:
response = requests.post(
url,
headers=headers,
json=payload,
This plain-text requirements file uses Chinese headings and instructions throughout, but does not indicate that the skill is region-specific or provide any user opt-in for language/locale. Under the policy rule, forcing a specific language without documented justification can be a natural-language policy violation.
No suspicious patterns detected.