Back to skill

Security audit

SiliconFlow API

Security checks for vulnerabilities and agentic risk

Overview

This is a real SiliconFlow media-generation wrapper, but it needs review because it sends user content to a third-party API and has unsafe scripting that can execute injected Python from crafted prompts.

Review before installing. Use only with non-sensitive prompts, images, and text; do not pass untrusted prompt content to i2i or i2v until the Python construction is fixed; store the API key with restrictive permissions; and expect SiliconFlow billing and third-party processing for generated media.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/sf_api.sh:103
Finding

User-Controlled Prompt Injected into Executable Python Source

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/sf_api.sh:98
Finding

Predictable Shared Temporary Files Permit Symlink Attacks and Data Exposure

Content
View full analysis
/tmp/sf_b64.txt b64=$(cat /tmp/sf_b64.txt) # 生成请求 JSON python3 -c " import json b64 = open('/tmp/sf_b64.txt').read().strip() payload = { 'model': 'Kwai-Kolors/Kolors', 'prompt': '$prompt', 'n': 1, 'size': '1024x1024', 'image': 'data:image/png;base64,' + b64 } open('/tmp/sf_req.json', 'w').write(json.dumps(payload)) " resp=$(curl -s -X POST "$BASE_URL/images/generations" \ -H "Authorization: Bearer $API_KEY" \ -H "Content-Type: application/json" \ -d @/tmp/sf_req.json) ``` Image-to-video processing: ```bash # 写 base64 到临时文件 base64 -w0 "$image_path" > /tmp/sf_b64.txt # 生成请求 JSON python3 -c " import json b64 = open('/tmp/sf_b64.txt').read().strip() payload = { 'model': 'Wan-AI/Wan2.2-I2V-A14B', 'prompt': '$prompt', 'duration': $duration, 'image': 'data:image/png;base64,' + b64 } open('/tmp/sf_req.json', 'w').write(json.dumps(payload)) " resp=$(curl -s -X POST "$BASE_URL/video/submit" \ -H "Authorization: Bearer $API_KEY" \ -H "Content-Type: application/json" \ -d @/tmp/sf_req.json) ``` ### Technical Analysis The script repeatedly uses the globally predictable paths `/tmp/sf_b64.txt` and `/tmp/sf_req.json`. It does not create these files atomically, verify their ownership or type, set restrictive permissions, or delete them after processing. On a multi-user system, another local process can create either path in advance as a symbolic link. Shell redirection and Python's ordinary file opening will then follow that link. A concurrent process can also read or replace the files between creation and use. The files contain sensitive user-provided image content, prompts, and complete API request bodies. Reusing the s ...[truncated 1335 chars]
Remediation
View remediation
"$b64_file" curl --fail --silent --show-error \ -X POST "$BASE_URL/video/submit" \ -H "Authorization: Bearer $API_KEY" \ -H "Content-Type: application/json" \ --data-binary "@$request_file" ``` 4. Avoid intermediate files where practical by streaming data or having a fixed Python helper read the original image and construct the request. 5. Remove the unused `b64=$(cat /tmp/sf_b64.txt)` assignment. 6. Ensure separate invocations never share temporary paths. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/sf_api.sh:20
Finding

API Credential Is Collected Visibly and Stored Without Enforced Access Controls

Content
View full analysis
"$CONFIG_FILE" <<< "{\"api_key\": \"$key\"}" echo "✅ API Key 已保存到 $CONFIG_FILE" ``` ### Technical Analysis The API key is entered with ordinary `read`, so terminal echo remains enabled and the secret is visible while typed. The configuration file is created using shell redirection without setting a restrictive umask or explicitly applying mode `0600`. Its final permissions therefore depend on the caller's environment and may allow unintended local users to read it. The key is also inserted directly into JSON text rather than serialized with a JSON-aware API. Unusual characters such as quotes or backslashes can produce malformed configuration data. This is primarily an integrity and reliability problem, but it reinforces that the credential is not handled as structured secret data. The API credential is legitimately required for the declared functionality, but visible input and potentially permissive storage exceed the exposure necessary to provide that functionality. ### Attack Path 1. A user invokes `bash scripts/sf_api.sh setup`. 2. The API key is displayed as it is typed, allowing observation or terminal capture. 3. The script creates `.sf-config.json` using the caller's existing umask. 4. If that umask permits group or other access, another local account or process can read the key. 5. The attacker uses the recovered credential to authenticate to SiliconFlow and consume the victim's account resources. ### Impact Assessment Credential compromise may permit: - Unauthorized SiliconFlow API requests under the victim's account. - Consumption of paid account balance or quotas. - Access t ...[truncated 333 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (26)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/sf_api.sh (reported line 32)May include surrounding context.

sh
# 测试连通性
    echo "测试 API 连通性..."
    resp=$(curl -s https://api.siliconflow.cn/v1/models \
        -H "Authorization: Bearer $key")
    if echo "$resp" | python3 -c "import json,sys; d=json.load(sys.stdin); print(len(d.get('data',[])))" 2>/dev/null; then
        echo "✅ API 连接成功"

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/sf_api.sh (reported line 54)May include surrounding context.

sh
echo "  提示词: $prompt"
    echo "  尺寸: $size"
    
    resp=$(curl -s -X POST "$BASE_URL/images/generations" \
        -H "Authorization: Bearer $API_KEY" \
        -H "Content-Type: application/json" \
        -d "{

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Although this is not external script fetching, it is still dangerous because the script downloads a remote URL supplied by the API directly to disk without validation. That can be abused to fetch arbitrary attacker-controlled content or probe internal network resources if the upstream response is tampered with.

Content

Scanner excerpt · scripts/sf_api.sh (reported line 78)May include surrounding context.

sh
return 1
    fi
    
    curl -s "$url" -o "$output"
    echo "✅ 图片已保存: $output"
}

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

This is another misclassified 'script fetching' case that nevertheless exposes a real unsafe-download pattern: the code trusts and downloads a remote URL from API output without any checks. A compromised response could direct the client to retrieve malicious or internal-only resources and save them locally.

Content

Scanner excerpt · scripts/sf_api.sh (reported line 135)May include surrounding context.

sh
return 1
    fi
    
    curl -s "$url" -o "$output"
    echo "✅ 编辑完成: $output"
}

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/sf_api.sh (reported line 174)May include surrounding context.

sh
# 轮询等待
    for i in $(seq 1 60); do
        sleep 10
        status_resp=$(curl -s -X POST "$BASE_URL/video/status" \
            -H "Authorization: Bearer $API_KEY" \
            -H "Content-Type: application/json" \
            -d "{\"requestId\": \"$req_id\"}")

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

The code downloads a video from a URL extracted from API status data and writes it to a file without validating the URL origin or content. If an attacker can influence the API response or if the service is compromised, this can trigger arbitrary outbound requests and local storage of untrusted content.

Content

Scanner excerpt · scripts/sf_api.sh (reported line 194)May include surrounding context.

sh
" 2>/dev/null)
            
            if [ -n "$video_url" ] && [ "$video_url" != "None" ]; then
                curl -s "$video_url" -o "$output"
                echo "✅ 视频已生成: $output"
            else
                echo "✅ 视频已生成"

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/sf_api.sh (reported line 248)May include surrounding context.

sh
open('/tmp/sf_req.json', 'w').write(json.dumps(payload))
"
    
    resp=$(curl -s -X POST "$BASE_URL/video/submit" \
        -H "Authorization: Bearer $API_KEY" \
        -H "Content-Type: application/json" \
        -d @/tmp/sf_req.json)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/sf_api.sh (reported line 272)May include surrounding context.

sh
echo "📊 查询视频状态..."
    
    resp=$(curl -s -X POST "$BASE_URL/video/status" \
        -H "Authorization: Bearer $API_KEY" \
        -H "Content-Type: application/json" \
        -d "{\"requestId\": \"$req_id\"}")

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

This path downloads a remotely provided video URL directly to a local file with no host, scheme, redirect, content-type, or size validation. In practice, that creates a client-side arbitrary fetch primitive that could be abused via compromised API responses or malicious intermediaries.

Content

Scanner excerpt · scripts/sf_api.sh (reported line 293)May include surrounding context.

sh
" 2>/dev/null)
        
        if [ -n "$video_url" ] && [ "$video_url" != "None" ]; then
            curl -s "$video_url" -o "$output"
            echo "✅ 视频已下载: $output"
        else
            echo "$resp" | python3 -m json.tool 2>/dev/null

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/sf_api.sh (reported line 321)May include surrounding context.

sh
echo "  文本: $text"
    echo "  音色: $voice"
    
    curl -s -X POST "$BASE_URL/audio/speech" \
        -H "Authorization: Bearer $API_KEY" \
        -H "Content-Type: application/json" \
        -d "{

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises shell-driven setup and execution but does not declare any explicit tool scope such as shell or file-write permissions. This creates a mismatch between what the skill can do and what a user or platform policy reviewer can assess, increasing the chance of unintended command execution or local file modification without clear consent boundaries.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says to use this skill whenever a user needs to generate images, video, or audio, which is very broad and can cause the agent to invoke it in many contexts without sufficient user awareness. Because the skill performs shell actions, stores an API key locally, and sends content to a third-party service, overbroad triggering raises the risk of unnecessary external transmission and unintended cost-incurring actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill describes generation features and local key storage, but it does not clearly warn that user prompts, uploaded images, and text content are transmitted to SiliconFlow's external API for processing. In this context, the omission is significant because the skill is explicitly designed to handle potentially sensitive media and text, and users may not realize their data leaves the local environment.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/sf_api.sh (reported line 8)May include surrounding context.

sh
set -e

CONFIG_FILE="$(dirname "$0")/../.sf-config.json"
BASE_URL="https://api.siliconflow.cn/v1"

# 读取配置
load_config() {

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/sf_api.sh (reported line 32)May include surrounding context.

sh
set -e

CONFIG_FILE="$(dirname "$0")/../.sf-config.json"
BASE_URL="https://api.siliconflow.cn/v1"

# 读取配置
load_config() {

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/sf_api.sh (reported line 54)May include surrounding context.

sh
echo "  提示词: $prompt"
    echo "  尺寸: $size"
    
    resp=$(curl -s -X POST "$BASE_URL/images/generations" \
        -H "Authorization: Bearer $API_KEY" \
        -H "Content-Type: application/json" \
        -d "{

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The script downloads content from a URL returned by the remote API and writes it directly to a local file without validating the scheme, host, content type, or size. If the API response is compromised or malicious, this enables SSRF-like access from the local machine to arbitrary URLs and can also write unexpected content to disk.

Content

Scanner excerpt · scripts/sf_api.sh (reported line 78)May include surrounding context.

sh
return 1
    fi
    
    curl -s "$url" -o "$output"
    echo "✅ 图片已保存: $output"
}

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This shell script base64-encodes a local image and includes it in a POST request to the SiliconFlow API, which transmits user file contents off the local system. While the command prints progress information, it does not explicitly disclose that the source image will be uploaded to a remote service, and there is no confirmation prompt or warning comment near the operation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

This code trusts a remotely supplied URL and fetches it directly to a local file without any origin or content validation. A compromised upstream service or manipulated response could cause downloads from attacker-chosen locations, exposing internal network resources or storing malicious/unexpected payloads locally.

Content

Scanner excerpt · scripts/sf_api.sh (reported line 135)May include surrounding context.

sh
return 1
    fi
    
    curl -s "$url" -o "$output"
    echo "✅ 编辑完成: $output"
}

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/sf_api.sh (reported line 174)May include surrounding context.

sh
# 轮询等待
    for i in $(seq 1 60); do
        sleep 10
        status_resp=$(curl -s -X POST "$BASE_URL/video/status" \
            -H "Authorization: Bearer $API_KEY" \
            -H "Content-Type: application/json" \
            -d "{\"requestId\": \"$req_id\"}")

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/sf_api.sh (reported line 272)May include surrounding context.

sh
# 轮询等待
    for i in $(seq 1 60); do
        sleep 10
        status_resp=$(curl -s -X POST "$BASE_URL/video/status" \
            -H "Authorization: Bearer $API_KEY" \
            -H "Content-Type: application/json" \
            -d "{\"requestId\": \"$req_id\"}")

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This function reads a local image, base64-encodes it, and submits it to the remote video generation API. Although status messages are printed, they do not explicitly warn the user that the local file content is being uploaded to an external service, which is the key safety-relevant behavior.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/sf_api.sh (reported line 248)May include surrounding context.

sh
open('/tmp/sf_req.json', 'w').write(json.dumps(payload))
"
    
    resp=$(curl -s -X POST "$BASE_URL/video/submit" \
        -H "Authorization: Bearer $API_KEY" \
        -H "Content-Type: application/json" \
        -d @/tmp/sf_req.json)

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/sf_api.sh (reported line 321)May include surrounding context.

sh
echo "  文本: $text"
    echo "  音色: $voice"
    
    curl -s -X POST "$BASE_URL/audio/speech" \
        -H "Authorization: Bearer $API_KEY" \
        -H "Content-Type: application/json" \
        -d "{

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

All user-facing prompts, help text, and defaults are presented only in Chinese, including the default TTS voice of '中文男声'. Under the stated policy, forcing a specific language or locale without user opt-in is a natural-language policy violation unless clearly justified or optional.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.potential_exfiltration

Shell script base64-encodes a local file and sends it over the network.

Critical
Code
suspicious.potential_exfiltration
Location
scripts/sf_api.sh:99