T09 · Insecure Skill Coding Practices
- Location
scripts/mmsearch.py:8- Finding
Hard-Coded MiniMax API Credential in Search Script
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill appears to provide the advertised MiniMax search and image-analysis features, but it bundles an API key and runs unpinned external code with broad environment access, so it needs Review before installation.
Install only after the publisher removes and rotates the bundled MiniMax API key, pins or vendors the MCP dependency, passes a minimal environment to subprocesses, and clearly discloses that search terms, prompts, image paths, image URLs, and possibly image content are processed by an external service.
scripts/mmsearch.py:8Hard-Coded MiniMax API Credential in Search Script
scripts/mmvision.py:8Hard-Coded MiniMax API Credential in Vision Script
scripts/mmsearch.py:16Unpinned Runtime Package Execution in Search Script
scripts/mmvision.py:16Unpinned Runtime Package Execution in Vision Script
If the skill claims search capability but actually only performs image understanding, or vice versa, the mismatch can cause the agent to invoke the wrong workflow and send unintended user data to an external API. The finding is more serious because it also indicates undisclosed API credential use, which is a sensitive behavior outside the stated purpose.
If the skill claims search capability but actually only performs image understanding, or vice versa, the mismatch can cause the agent to invoke the wrong workflow and send unintended user data to an external API. The finding is more serious because it also indicates undisclosed API credential use, which is a sensitive behavior outside the stated purpose.
The script hard-codes a live MiniMax API key directly into source and exports it into the runtime environment. Anyone with file access can recover and abuse the credential, leading to unauthorized API usage, billing abuse, and possible access to associated account resources.
A hard-coded API credential is not only present but also propagated into a subprocess environment with no disclosure to the user. This increases exposure because child processes and related diagnostics may access the secret, broadening the blast radius of the credential leak.
Using os.environ.copy() forwards the entire parent environment to the subprocess, which can expose unrelated secrets, tokens, and internal configuration to external tooling. In this skill context, that is more dangerous because the skill already injects an API key and then launches a third-party MCP process, unnecessarily expanding access to sensitive data.
stdin=subprocess.PIPE,
stdout=subprocess.PIPE,
stderr=subprocess.PIPE,
env=os.environ.copy(),
text=True,
bufsize=1
)
A live MiniMax API key is hardcoded directly in the script and exported into the process environment. Anyone with access to the code can reuse the credential, and any downstream process or logs that expose environment variables may leak it further, enabling unauthorized API use and billing abuse.
The script silently injects a hardcoded API key into the environment without disclosure to the user. This hides credential use, makes secret exposure easier during debugging or child-process inspection, and normalizes unsafe secret handling in a tool whose stated purpose does not require bundled credentials.
Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.
stdin=subprocess.PIPE,
stdout=subprocess.PIPE,
stderr=subprocess.PIPE,
env=os.environ.copy(),
text=True,
bufsize=1
)
The skill advertises executable shell commands and use of environment-backed secrets but does not declare any explicit tool scope such as allowed-tools or permissions. That makes the runtime authority ambiguous and increases the risk of over-broad execution, especially for a skill that can invoke scripts and contact external services.
Broad triggers like common words for search or image analysis can cause unintended invocation during normal conversation, leading to unexpected shell/script execution or external API calls. In this skill's context, accidental activation is more dangerous because user queries or image references may be transmitted to a third-party service.
The skill documentation does not warn users that search terms, image URLs, or image content may be sent to an external API for processing. This lack of transparency can expose sensitive user data or internal URLs without informed consent, particularly when the skill processes arbitrary image paths or remote image links.
The script launches an external MCP server via subprocess, which is a safety-relevant operation under this rule set. Although there is an internal comment, there is no confirmation prompt, visible print/log message, or broader user disclosure explaining that an external command will be executed.
The manifest says the skill should support both searching and image analysis depending on user intent, including an understand_image function. In this file, the CLI always invokes only the web_search tool and accepts only a text query, so the implemented behavior is narrower than the declared skill description.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
"""Call MCP tool via stdio"""
# Start MCP server
proc = subprocess.Popen(
["uvx", "minimax-coding-plan-mcp", "-y"],
stdin=subprocess.PIPE,
stdout=subprocess.PIPE,
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
"""Call MCP tool via stdio"""
# Start MCP server
proc = subprocess.Popen(
["uvx", "minimax-coding-plan-mcp", "-y"],
stdin=subprocess.PIPE,
stdout=subprocess.PIPE,
The tool sends the user-provided image source and prompt to an external MiniMax MCP service, but there is no user-facing notice or consent flow indicating that image data may leave the local system. In an image-understanding skill, this is especially relevant because images may contain sensitive personal, business, or location information.
The skill's natural-language description, trigger phrases, headings, and examples are primarily presented in Chinese, while also including some English trigger terms. This may implicitly constrain usage to a specific language/locale without documenting that choice or offering an explicit language option.
Mentioning an API key dependency without warning that the skill uses a credentialed external service hides an important trust boundary from users and reviewers. While weaker than direct secret exposure, it still creates a transparency and governance issue around third-party processing and billing-backed access.
The only user-facing examples are Chinese prompt strings, which implicitly steer usage toward a specific language. There is no accompanying note that other languages are supported or that the language requirement is intentional and justified.
No suspicious patterns detected.