T09 · Insecure Skill Coding Practices
- Location
scripts/generate_image.py:202- Finding
TLS Certificate Verification Can Be Disabled for Sensitive API Traffic
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a real Qwen image tool, but it should be reviewed because it can upload prompts and local images to Alibaba Cloud and includes an option that can disable TLS protection.
Install only if you are comfortable sending prompts and any selected local images to Alibaba Cloud/DashScope. Avoid using --no-verify-ssl, prefer DASHSCOPE_API_KEY over command-line keys, and do not submit private or regulated images unless the service terms and retention rules fit your needs.
scripts/generate_image.py:202TLS Certificate Verification Can Be Disabled for Sensitive API Traffic
scripts/generate_image.py:230API Response URLs Are Downloaded Without Destination or Content Validation
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
def get_api_key(provided_key: str | None) -> str | None:
"""Get API key from argument first, then environment."""
return provided_key or os.getenv("DASHSCOPE_API_KEY")
The skill invokes a script that uses environment-sourced API credentials and communicates with a remote cloud service, but the manifest does not declare any tool scope or permission boundary. This increases the chance of the skill being activated with broader-than-expected access and makes security review, least-privilege enforcement, and user understanding of data flow more difficult.
The trigger phrases are very broad and match common requests like 'generate image', 'edit photo', or 'add text', which can cause the skill to activate in many ordinary conversations without clear user intent to use this specific remote service. In this skill's context, that matters because activation can lead to sending prompts and possibly user-supplied images to Alibaba Cloud, creating privacy and consent risks.
The repeated trigger description remains ambiguous and reinforces activation on generic image-related language rather than clearly scoped intents. Repetition of broad triggers can make accidental routing more likely, especially for a skill that may process local files and send them to a third-party API.
The usage and workflow explain how to pass local images or image URLs to the script, but they do not clearly warn users that local images will be transmitted to a remote Alibaba Cloud API for processing. Because this skill supports editing personal or proprietary images, omission of this disclosure can lead to unintentional exfiltration of sensitive visual data and compliance/privacy issues.
The --no-verify-ssl option disables TLS certificate verification for both API calls and image downloads, allowing man-in-the-middle interception or tampering with prompts, API credentials, and returned image URLs/content. Because this tool sends bearer tokens and potentially sensitive user images to a remote service, turning off certificate validation materially increases exposure.
In edit mode, local images are base64-encoded and included in the outbound API request payload, which sends user-provided image data and prompts to a third-party service. Although the script logs that it is generating/editing an image, it does not clearly disclose that local files and text prompts are uploaded externally.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
try:
# Make API request
response = requests.post(
api_url,
headers={
"Content-Type": "application/json",
The manifest describes an image creation/editing assistant, but does not mention credential discovery from the runtime environment. While using an API key is an implementation detail for a cloud image service, reading environment variables introduces a broader capability beyond the user-facing image manipulation scope.
The default value for --negative-prompt is hard-coded in Chinese, imposing a specific language choice on all users unless they override it manually. This is a natural-language locale preference that is not presented as an opt-in or user-selectable default.
No suspicious patterns detected.