T09 · Insecure Skill Coding Practices
- Location
config.json:3- Finding
Hardcoded Printer Credentials Expose Administrative File Operations
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This printer-control skill is not clearly malicious, but it packages a real printer credential and uses insecure FTPS for upload, download, and deletion.
Do not install this published version as-is. Rotate the exposed printer access code, remove credentials from the skill and script fallbacks, load secrets from a private local source, enable certificate validation or certificate pinning for FTPS, and add clear confirmation for delete operations before using it on a real printer.
config.json:3Hardcoded Printer Credentials Expose Administrative File Operations
scripts/ftp.sh:40FTPS Server Authentication Is Disabled for All File Operations
The documented behavior does not accurately bound what the skill can do: it includes remote deletion, arbitrary upload/download, and incomplete implementation of stated status/timelapse features. This mismatch is dangerous because users or orchestration agents may grant trust based on a narrower description while the actual capability enables broader file manipulation on the printer.
The skill embeds a live printer IP, serial number, and access code directly in documentation, exposing credentials for a network-reachable device. Anyone with access to the skill can potentially connect to the printer over FTPS/MQTT, access files, or interfere with its operation, making this a clear secret disclosure issue.
Using curl --insecure disables TLS certificate validation for the FTPS connection, allowing a man-in-the-middle attacker on the network to impersonate the printer endpoint. Because the command also sends credentials, an attacker could intercept authentication data and tamper with file listings or other responses.
list|ls)
path="${1:-/}"
[[ "$path" != /* ]] && path="/$path"
exec $CURL -s --insecure --connect-timeout 10 -u "$AUTH" "${BASE_URL}${path}" 2>&1
;;
upload|put)
Uploading with curl --insecure permits TLS interception and endpoint spoofing during file transfer. An attacker could capture printer credentials, alter uploaded print files in transit, or redirect uploads to a malicious service, which is especially risky in a 3D-printer control context where modified models/G-code can affect device behavior.
fi
filename=$(basename "$local_file")
echo "⬆️ 上传 $filename 到 ${remote_dir}..."
exec $CURL -T "$local_file" --insecure --connect-timeout 10 -u "$AUTH" "${BASE_URL}${remote_dir}${filename}" 2>&1
;;
download|get)
Downloading with curl --insecure disables server authentication, so a network attacker can spoof the FTPS server and supply malicious or falsified files. This can expose credentials and result in untrusted files being written locally, increasing risk if those files are later opened or used in downstream workflows.
local_path="$local_path/$filename"
fi
echo "⬇️ 下载 $remote_path 到 $local_path..."
exec $CURL -s --insecure --connect-timeout 10 -u "$AUTH" -o "$local_path" "${BASE_URL}${remote_path}" 2>&1
echo "✅ 下载完成: $local_path"
;;
Issuing delete commands over an FTPS session with --insecure allows a man-in-the-middle attacker to impersonate the printer and influence or observe destructive operations while harvesting credentials. In this skill context, the command is destructive, so spoofed or intercepted sessions can lead to unauthorized file deletion or misdirected operator actions.
remote_path="${1:?需要指定远程文件路径}"
[[ "$remote_path" != /* ]] && remote_path="/$remote_path"
echo "🗑️ 删除 $remote_path"
exec $CURL -s --insecure --connect-timeout 10 -u "$AUTH" -Q "DELE $remote_path" "${BASE_URL}/" 2>&1
;;
size|info)
Even for size/info operations, curl --insecure enables server spoofing and credential interception because the client no longer authenticates the FTPS endpoint. An attacker can falsify inventory information, mislead operators about printer contents, and obtain access credentials for later abuse.
size|info)
path="${1:-/}"
[[ "$path" != /* ]] && path="/$path"
$CURL -s --insecure --connect-timeout 10 -u "$AUTH" "${BASE_URL}${path}" 2>&1 | \
awk '/^-/{total += $5; count++} END {printf "文件数: %d, 总大小: %.1f MB\n", count, total/1024/1024}'
;;
The skill documents direct shell-based execution (bash, perl, curl) but does not declare any tool scope or allowed-tools restrictions. That creates an unnecessary trust gap: an agent may invoke broad shell access to operate on files and network resources without an explicit permission boundary, increasing the chance of misuse or unintended command execution.
The natural-language content of the skill is entirely in Chinese, with no indication that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific context. Per SQP-3, forcing a specific language without user opt-in is a policy concern.
The markdown describes a delete operation against remote printer files, but it provides no warning that the action can remove files from the device and may be irreversible. Under SQP-2 for markdown files, behaviors affecting user data or system integrity should be accompanied by explicit warnings.
The manifest describes a printer-control skill focused on Bambu P1S file management, connection status, and timelapse access. Line L22 states that operations are performed through generic system tools such as curl, perl, and ruby, which introduces broader execution-capable dependencies not justified by the stated purpose in this file's documented intent.
The file embeds user-facing descriptions and operational messages in Chinese, starting with the header comments and continuing through help output. Because the skill does not provide an opt-in language choice or indicate that it is intentionally limited to Chinese users, this is a natural-language locale policy issue.
Manifest 说明提到“文件管理(FTPS)”、文件列表、上传下载 gcode/3mf 文件和查看延时摄影,但未提及删除远程文件。此脚本额外提供 delete/rm/del 并执行 FTPS DELE 操作,属于比描述更具破坏性的能力扩展。
The help text shown to users is exclusively in Chinese, which forces a specific language for interaction. Under the policy, language restrictions should either be optional for the user or clearly justified as a region-specific constraint.
The natural-language note is written only in Chinese, which imposes a specific language on users without offering any language choice or documenting a justified locale restriction. This matches the policy category for language or locale violations in natural-language content.
No suspicious patterns detected.