T09 · Insecure Skill Coding Practices
- Location
config.json:4- Finding
API Credentials Stored in Plaintext Configuration
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This audiobook skill does what it claims, but it sends manuscript text to external AI services and asks users to keep API keys in a local config file, so it needs review before use.
Install only if you are comfortable sending chapter text to DeepSeek and MiniMax and storing generated intermediates locally. Use throwaway or restricted API keys, avoid unpublished or confidential manuscripts unless the providers' terms are acceptable, keep config.json out of source control/backups, and manually clean temp_analysis.json, temp_audio, and temp_bgm after use.
config.json:4API Credentials Stored in Plaintext Configuration
scripts/music_generator.py:132Unvalidated Server-Provided URL Download Enables Client-Side SSRF
scripts/audio_assembler.py:17Unpinned Runtime Dependency Installation
This mismatch becomes security-relevant because the skill presents itself as a normal audiobook generator while actually involving undeclared external network transmission of user-provided text to third-party TTS services. Users may consent to local media processing but not realize their manuscript or chapter content is being uploaded externally, creating a privacy and data-handling risk.
This mismatch becomes security-relevant because the skill presents itself as a normal audiobook generator while actually involving undeclared external network transmission of user-provided text to third-party TTS services. Users may consent to local media processing but not realize their manuscript or chapter content is being uploaded externally, creating a privacy and data-handling risk.
This mismatch becomes security-relevant because the skill presents itself as a normal audiobook generator while actually involving undeclared external network transmission of user-provided text to third-party TTS services. Users may consent to local media processing but not realize their manuscript or chapter content is being uploaded externally, creating a privacy and data-handling risk.
The skill instructs sending full chapter text to DeepSeek for analysis, but the documentation does not clearly warn users that their manuscript content will be transmitted to an external API. For a novel-writing context, this is especially sensitive because unpublished creative work may contain private, proprietary, or monetizable content that users would not expect to leave their machine.
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
# 尝试精确匹配和部分匹配
for key, prompt in MOOD_PROMPT_MAP.items():
if key in mood:
return prompt
return DEFAULT_PROMPT
The skill declares capabilities to read user files, write output files, and send chapter content to external services, but it does not declare any tool scope or permission boundaries. This weakens user consent and platform control, making it easier for the skill to access files or exfiltrate chapter text without an explicit, reviewable capability declaration.
The trigger phrases include broad everyday expressions such as '做成音频' or '语音版', which can cause accidental invocation in contexts where the user did not intend this skill. Because this skill reads files, writes outputs, and sends content to external APIs, accidental triggering can lead to unintended data disclosure or file operations.
The skill writes final outputs to the filesystem and retains intermediate JSON and audio artifacts, but this persistence is only mentioned later as a note and not surfaced as an operational warning. Temporary files can expose sensitive manuscript text, character metadata, or generated audio to other local users, backups, or unintended later reuse.
This code file contains natural-language documentation and CLI descriptions entirely in Chinese, including the module docstring and usage text. Under the policy, forcing a specific language without user choice is a locale/language policy concern, and there is no indication that the skill is region-specific or that users can select another language.
The script sends full chapter text to DeepSeek's external API for processing, but there is no explicit user-facing notice or consent step before transmitting potentially sensitive or copyrighted content off-device. In a skill that processes user-supplied manuscripts or unpublished novels, this creates privacy, confidentiality, and data-governance risk even though the transmission is part of intended functionality.
This code performs external network transmission to api.deepseek.com, sending prompts that include the user's chapter text. External transmission is expected for an LLM-backed analyzer, but it is still security-relevant because it exposes user content to a third party and may violate privacy or confidentiality expectations if not tightly controlled.
def call_deepseek(system_prompt, user_prompt, api_key, model="deepseek-chat"):
"""调用 DeepSeek API 分析文本"""
url = "https://api.deepseek.com/v1/chat/completions"
headers = {
"Authorization": f"Bearer {api_key}",
"Content-Type": "application/json",
The file's natural-language interface is entirely in Chinese, including the top-level description, usage examples, and argument help context, with no indication that this skill is China-specific or that another language is available. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
SKILL_DIR = SCRIPT_DIR.parent
CONFIG_PATH = SKILL_DIR / "config.json"
MUSIC_URL = "https://api.minimaxi.com/v1/music_generation"
# 情绪 → 音乐 Prompt 映射
MOOD_PROMPT_MAP = {
The module docstring, CLI descriptions, and embedded user-facing output are all written in Chinese, and the voice-selection logic is based on Chinese-character heuristics for role names. This enforces a specific language/locale experience without any opt-in or documented justification, which matches the language/locale policy violation criteria.
The script sends chapter text and an API key to a third-party TTS service, which is a genuine external data transmission. In the context of a novel-to-audiobook skill this is expected behavior, but it still creates privacy and data-handling risk because potentially sensitive or copyrighted chapter content is exported off-platform to an external provider.
CONFIG_PATH = SKILL_DIR / "config.json"
# MiniMax TTS API
TTS_URL = "https://api.minimaxi.com/v1/t2a_v2"
def load_config():
All natural-language user-facing descriptions, prompts, and CLI help text in this file are fixed to Chinese, with no indication that the user can choose another language. This can violate language/locale policy when a skill imposes a specific language without user opt-in or documented regional scope.
No suspicious patterns detected.