Back to skill

Security audit

Translate TXT

Security checks for vulnerabilities and agentic risk

Overview

This translation skill is coherent, but needs review because it uploads documents and credentials to configurable external API endpoints and stores the API key in a local .env file without strong safeguards.

Install only if you are comfortable sending the source text and derived context to the selected translation provider. Use a trusted HTTPS endpoint, avoid confidential or regulated files unless the provider is approved, prefer secure environment-based secret injection over command-line keys, and protect or rotate the API key stored in .env.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/translate.py:59
Finding

API Credentials and Document Contents Can Be Sent to Unrestricted or Unencrypted Endpoints

Content
View full analysis
str: """Call OpenAI-compatible chat completion API with retry on timeout.""" url = f"{base_url.rstrip('/')}/chat/completions" payload_dict = { "model": model, "messages": messages, "temperature": float(os.environ.get("TRANSLATE_TEMPERATURE", "1")), "max_tokens": int(os.environ.get("TRANSLATE_MAX_TOKENS", "4096")), } thinking_mode = os.environ.get("TRANSLATE_THINKING", "auto") if thinking_mode in ("disabled", "auto"): payload_dict["enable_thinking"] = False payload = json.dumps(payload_dict).encode("utf-8") req = urllib.request.Request( url, data=payload, headers={ "Content-Type": "application/json", "Authorization": f"Bearer {api_key}", }, method="POST", ) ``` The destination is read directly from configuration without validation: ```python api_key = os.environ.get("TRANSLATE_API_KEY", "") base_url = os.environ.get("TRANSLATE_BASE_URL", "https://api.siliconflow.cn/v1") model = os.environ.get("TRANSLATE_MODEL", "Qwen/Qwen2.5-7B-Instruct") ``` The setup script accepts an arbitrary endpoint: ```bash --base-url) BASE_URL="$2"; shift 2 ;; ``` The documentation explicitly instructs users or agents to configure custom endpoints: ```bash # Custom endpoint bash ~/.comate/skills/translate-txt/setup.sh --api-key sk-xxx --base-url https://my-api.example.com/v1 --model my-model ``` ### Technical Analysis Sending document text to a remote API is necessary for the declared cloud translation functionality. However, the implementation accepts ...[truncated 2213 chars]
Remediation
View remediation
str: parsed = urlsplit(base_url) if parsed.scheme != "https": raise ValueError("TRANSLATE_BASE_URL must use HTTPS") if not parsed.hostname or parsed.username or parsed.password or parsed.fragment: raise ValueError("Invalid translation API URL") return base_url.rstrip("/") ``` ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
setup.sh:16
Finding

API Key Is Exposed Through Command-Line Arguments and Insecure Plaintext File Permissions

Content
View full analysis
/dev/null; then local tmp=$(mktemp) sed "s|^${key}=.*|${key}=${value}|" "$ENV_FILE" > "$tmp" && mv "$tmp" "$ENV_FILE" else echo "${key}=${value}" >> "$ENV_FILE" fi } ``` The API key is accepted as a command-line argument: ```bash --api-key) API_KEY="$2"; shift 2 ;; ``` The configuration file is created using the caller’s current umask, and the key is then stored in plaintext: ```bash if [ ! -f "$ENV_FILE" ]; then touch "$ENV_FILE" fi # --- Non-interactive mode (CLI args provided) --- if [ -n "$API_KEY" ]; then # Resolve provider -> base_url + model if [ -n "$PROVIDER" ]; then RESOLVED_URL=$(get_provider_url "$PROVIDER") RESOLVED_MODEL=$(get_provider_model "$PROVIDER") BASE_URL="${BASE_URL:-$RESOLVED_URL}" MODEL="${MODEL:-$RESOLVED_MODEL}" fi update_env "TRANSLATE_API_KEY" "$API_KEY" ``` The documented setup procedure encourages this usage: ```bash bash ~/.comate/skills/translate-txt/setup.sh --api-key --provider ``` ### Technical Analysis Command-line arguments are not a secure secret-input channel. Depending on the host environment, the API key may be exposed through: - Shell history. - Process listings while the command is running. - Agent tool-call transcripts. - Terminal or orchestration logs. - Audit and job execution records. The `.env` file is created with `touch` without first setting `umask 077` or applying `chmod 600`. Its permissions therefore depend on the caller’s environment. Wit ...[truncated 1558 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (31)

Tainted flow: 'req' from os.environ.get (line 74, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/translate.py (reported line 87)May include surrounding context.

python
timeout = int(os.environ.get("TRANSLATE_TIMEOUT", "300"))
    for attempt in range(1, max_retries + 1):
        try:
            with urllib.request.urlopen(req, timeout=timeout) as resp:
                body = json.loads(resp.read().decode("utf-8"))
                return body["choices"][0]["message"]["content"]
        except (TimeoutError, urllib.error.URLError) as e:

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

Storing an API key in a plain .env file creates credential exposure risk through accidental inclusion in source control, overbroad filesystem access, backups, or logs. Because the skill also performs network operations, compromise of that key could enable unauthorized API usage, cost abuse, and data access through the configured provider account.

Content

Scanner excerpt · SKILL.md (reported line 40)May include surrounding context.

text
translate-txt/
├── SKILL.md              # Skill definition
├── .env                  # User configuration (created by setup)
├── setup.sh              # Setup script (interactive & non-interactive)
└── scripts/
    └── translate.py      # Translation script

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/translate.py (reported line 36)May include surrounding context.

python
def load_dotenv():
    """Load .env file from the skill's root directory (parent of scripts/)."""
    skill_root = Path(__file__).resolve().parent.parent
    env_path = skill_root / ".env"
    if not env_path.is_file():

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/translate.py (reported line 38)May include surrounding context.

python
def load_dotenv():
    """Load .env file from the skill's root directory (parent of scripts/)."""
    skill_root = Path(__file__).resolve().parent.parent
    env_path = skill_root / ".env"
    if not env_path.is_file():
        return
    with open(env_path, "r", encoding="utf-8") as f:

Credential Access

High
Category
Privilege Escalation
Confidence
91% confidence
Finding

The script deliberately uses a local .env file to store API credentials, creating a persistent secret on disk in the skill directory. If that directory is readable by other users, synced, backed up, or committed to source control, the credential can be exposed and abused for unauthorized API access and billing fraud.

Content

Scanner excerpt · setup.sh (reported line 13)May include surrounding context.

sh
#     bash setup.sh --api-key sk-xxx --provider openai

SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)"
ENV_FILE="$SCRIPT_DIR/.env"

# --- Helper functions ---

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Creating the .env file without immediately applying restrictive permissions can leave a window where secrets are later written to a file with default umask-derived access. In shared or automated environments, this can expose the API key to unintended readers.

Content

Scanner excerpt · setup.sh (reported line 87)May include surrounding context.

sh
esac
done

# --- Create .env if needed ---

if [ ! -f "$ENV_FILE" ]; then
    touch "$ENV_FILE"

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · test.txt (reported line 121)May include surrounding context.

text
"Offend Dobby!" choked the elf. "Dobby has never been asked to sit down by a wizard - like an equal-"
  Harry, trying to say "Shh!" and look comforting at the same time, ushered Dobby back onto the bed where he sat hiccoughing, looking like a large and very ugly doll. At last he managed to control himself, and sat with his great eyes fixed on Harry in an expression of watery adoration.
  "You can't have met many decent wizards," said Harry, trying to cheer him up.
  Dobby shook his head. Then, without warning, he leapt up and started banging his head furiously on the window, shouting, "Bad Dobby! Bad Dobby!"
  "Don't - what are you doing?" Harry hissed, springing up and pulling Dobby back onto the bed - Hedwig had woken up with a particularly loud screech and was beating her wings wildly against the bars of her cage.
  "Dobby had to punish himself, sir," said the elf, who had gone slightly cross-eyed. "Dobby almost spoke ill of his family, sir . . . ."
  "Your family?"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill clearly performs file reads/writes, uses environment secrets, and makes outbound network requests, but it declares no explicit tool scope or allowed-tools. This increases the blast radius if the agent runtime grants broader-than-necessary capabilities and prevents users from understanding what the skill is allowed to access.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The configured default base URL indicates external transmission of user file contents and possibly metadata to a remote service. In a translation skill this behavior is expected, but it is still security-relevant because it exposes potentially sensitive document contents outside the local trust boundary.

Content

Scanner excerpt · SKILL.md (reported line 15)May include surrounding context.

md
required: true
        - key: TRANSLATE_BASE_URL
          description: Base URL for OpenAI-compatible API
          default: https://api.siliconflow.cn/v1
        - key: TRANSLATE_MODEL
          description: Model name to use
          default: Qwen/Qwen2.5-7B-Instruct

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill is designed to send file contents to an external OpenAI-compatible API, but the description does not clearly warn users that their text will leave the local environment and be processed by a third party. This can cause accidental disclosure of confidential, regulated, or proprietary data because users may assume translation happens locally.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Defaulting output to Chinese without explicit user opt-in can produce unexpected transformations and policy or workflow errors, especially in multilingual, compliance, or accessibility-sensitive contexts. While not a classic exploit primitive, it creates a real safety and integrity risk because the skill may act contrary to user expectations.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The configuration table reiterates use of a remote API endpoint, confirming that text will be transmitted externally for processing. This is contextually expected for a cloud translation skill, but it remains dangerous when users are not explicitly warned about data egress and provider handling of content.

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

md
| Variable | Default | Description |
|---|---|---|
| `TRANSLATE_API_KEY` | (none, required) | API key for the translation service |
| `TRANSLATE_BASE_URL` | `https://api.siliconflow.cn/v1` | Base URL for OpenAI-compatible API |
| `TRANSLATE_MODEL` | `Qwen/Qwen2.5-7B-Instruct` | Model name to use |
| `TRANSLATE_THINKING` | `auto` | Thinking mode: `auto`/`disabled` (recommended) or `enabled` |
| `TRANSLATE_MAX_TOKENS` | `4096` | Max output tokens per chunk |

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The usage text states a default target language of Chinese, and the argument parser also defaults --target-lang to Chinese. This imposes a specific language choice unless the user overrides it, which is a natural-language locale policy concern when no explicit opt-in is obtained.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The implementation sends user content not just once for translation, but also in additional passes for keyword extraction and background inference. That expands the data exposure surface and increases the amount of sensitive text disclosed to the external provider, which matters if users process confidential documents.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The CLI argument definition sets --target-lang to Chinese by default, causing translations to default to a specific language even when the user has not chosen one. This is a language/locale policy issue because the script does not offer explicit opt-in before applying that locale preference.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The script allows outbound transmission of full document contents to a configurable external endpoint via TRANSLATE_BASE_URL. This is expected functionality for the skill, but it becomes risky because the endpoint is fully configurable and there is no validation or user-facing warning, so sensitive text could be sent to an untrusted service.

Content

Scanner excerpt · scripts/translate.py (reported line 365)May include surrounding context.

python
# Resolve API config from environment
    api_key = os.environ.get("TRANSLATE_API_KEY", "")
    base_url = os.environ.get("TRANSLATE_BASE_URL", "https://api.siliconflow.cn/v1")
    model = os.environ.get("TRANSLATE_MODEL", "Qwen/Qwen2.5-7B-Instruct")

    if not api_key:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script transmits user file contents to a third-party LLM service for processing, but it does not present an explicit privacy warning or confirmation at the point of use. In a translation skill, this is contextually expected, but users may still unknowingly send sensitive data such as proprietary documents, credentials, or personal information off-host.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/translate.py (reported line 10)May include surrounding context.

python
# Usage:
#   Interactive:  bash setup.sh
#   Non-interactive (for AI agent):
#     bash setup.sh --api-key sk-xxx --base-url https://api.siliconflow.cn/v1 --model Qwen/Qwen2.5-7B-Instruct
#     bash setup.sh --api-key sk-xxx --provider siliconflow
#     bash setup.sh --api-key sk-xxx --provider deepseek
#     bash setup.sh --api-key sk-xxx --provider openai

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · setup.sh (reported line 7)May include surrounding context.

sh
# Usage:
#   Interactive:  bash setup.sh
#   Non-interactive (for AI agent):
#     bash setup.sh --api-key sk-xxx --base-url https://api.siliconflow.cn/v1 --model Qwen/Qwen2.5-7B-Instruct
#     bash setup.sh --api-key sk-xxx --provider siliconflow
#     bash setup.sh --api-key sk-xxx --provider deepseek
#     bash setup.sh --api-key sk-xxx --provider openai

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · setup.sh (reported line 36)May include surrounding context.

sh
# Usage:
#   Interactive:  bash setup.sh
#   Non-interactive (for AI agent):
#     bash setup.sh --api-key sk-xxx --base-url https://api.siliconflow.cn/v1 --model Qwen/Qwen2.5-7B-Instruct
#     bash setup.sh --api-key sk-xxx --provider siliconflow
#     bash setup.sh --api-key sk-xxx --provider deepseek
#     bash setup.sh --api-key sk-xxx --provider openai

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · setup.sh (reported line 137)May include surrounding context.

sh
# Usage:
#   Interactive:  bash setup.sh
#   Non-interactive (for AI agent):
#     bash setup.sh --api-key sk-xxx --base-url https://api.siliconflow.cn/v1 --model Qwen/Qwen2.5-7B-Instruct
#     bash setup.sh --api-key sk-xxx --provider siliconflow
#     bash setup.sh --api-key sk-xxx --provider deepseek
#     bash setup.sh --api-key sk-xxx --provider openai

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · setup.sh (reported line 140)May include surrounding context.

sh
# Usage:
#   Interactive:  bash setup.sh
#   Non-interactive (for AI agent):
#     bash setup.sh --api-key sk-xxx --base-url https://api.siliconflow.cn/v1 --model Qwen/Qwen2.5-7B-Instruct
#     bash setup.sh --api-key sk-xxx --provider siliconflow
#     bash setup.sh --api-key sk-xxx --provider deepseek
#     bash setup.sh --api-key sk-xxx --provider openai

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · setup.sh (reported line 147)May include surrounding context.

sh
# Usage:
#   Interactive:  bash setup.sh
#   Non-interactive (for AI agent):
#     bash setup.sh --api-key sk-xxx --base-url https://api.siliconflow.cn/v1 --model Qwen/Qwen2.5-7B-Instruct
#     bash setup.sh --api-key sk-xxx --provider siliconflow
#     bash setup.sh --api-key sk-xxx --provider deepseek
#     bash setup.sh --api-key sk-xxx --provider openai

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · setup.sh (reported line 36)May include surrounding context.

sh
echo "${val:-$default}"
}

PROVIDER_URLS="siliconflow:https://api.siliconflow.cn/v1 deepseek:https://api.deepseek.com/v1 openai:https://api.openai.com/v1"
PROVIDER_MODELS="siliconflow:Qwen/Qwen2.5-7B-Instruct deepseek:deepseek-chat openai:gpt-4o-mini"

get_provider_url() {

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · setup.sh (reported line 141)May include surrounding context.

sh
echo "${val:-$default}"
}

PROVIDER_URLS="siliconflow:https://api.siliconflow.cn/v1 deepseek:https://api.deepseek.com/v1 openai:https://api.openai.com/v1"
PROVIDER_MODELS="siliconflow:Qwen/Qwen2.5-7B-Instruct deepseek:deepseek-chat openai:gpt-4o-mini"

get_provider_url() {

Static analysis

No suspicious patterns detected.