T09 · Insecure Skill Coding Practices
- Location
scripts/sf_api.sh:103- Finding
User-Controlled Prompt Injected into Executable Python Source
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a real SiliconFlow media-generation wrapper, but it needs review because it sends user content to a third-party API and has unsafe scripting that can execute injected Python from crafted prompts.
Review before installing. Use only with non-sensitive prompts, images, and text; do not pass untrusted prompt content to i2i or i2v until the Python construction is fixed; store the API key with restrictive permissions; and expect SiliconFlow billing and third-party processing for generated media.
scripts/sf_api.sh:103User-Controlled Prompt Injected into Executable Python Source
scripts/sf_api.sh:98Predictable Shared Temporary Files Permit Symlink Attacks and Data Exposure
scripts/sf_api.sh:20API Credential Is Collected Visibly and Stored Without Enforced Access Controls
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
# 测试连通性
echo "测试 API 连通性..."
resp=$(curl -s https://api.siliconflow.cn/v1/models \
-H "Authorization: Bearer $key")
if echo "$resp" | python3 -c "import json,sys; d=json.load(sys.stdin); print(len(d.get('data',[])))" 2>/dev/null; then
echo "✅ API 连接成功"
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
echo " 提示词: $prompt"
echo " 尺寸: $size"
resp=$(curl -s -X POST "$BASE_URL/images/generations" \
-H "Authorization: Bearer $API_KEY" \
-H "Content-Type: application/json" \
-d "{
Although this is not external script fetching, it is still dangerous because the script downloads a remote URL supplied by the API directly to disk without validation. That can be abused to fetch arbitrary attacker-controlled content or probe internal network resources if the upstream response is tampered with.
return 1
fi
curl -s "$url" -o "$output"
echo "✅ 图片已保存: $output"
}
This is another misclassified 'script fetching' case that nevertheless exposes a real unsafe-download pattern: the code trusts and downloads a remote URL from API output without any checks. A compromised response could direct the client to retrieve malicious or internal-only resources and save them locally.
return 1
fi
curl -s "$url" -o "$output"
echo "✅ 编辑完成: $output"
}
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
# 轮询等待
for i in $(seq 1 60); do
sleep 10
status_resp=$(curl -s -X POST "$BASE_URL/video/status" \
-H "Authorization: Bearer $API_KEY" \
-H "Content-Type: application/json" \
-d "{\"requestId\": \"$req_id\"}")
The code downloads a video from a URL extracted from API status data and writes it to a file without validating the URL origin or content. If an attacker can influence the API response or if the service is compromised, this can trigger arbitrary outbound requests and local storage of untrusted content.
" 2>/dev/null)
if [ -n "$video_url" ] && [ "$video_url" != "None" ]; then
curl -s "$video_url" -o "$output"
echo "✅ 视频已生成: $output"
else
echo "✅ 视频已生成"
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
open('/tmp/sf_req.json', 'w').write(json.dumps(payload))
"
resp=$(curl -s -X POST "$BASE_URL/video/submit" \
-H "Authorization: Bearer $API_KEY" \
-H "Content-Type: application/json" \
-d @/tmp/sf_req.json)
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
echo "📊 查询视频状态..."
resp=$(curl -s -X POST "$BASE_URL/video/status" \
-H "Authorization: Bearer $API_KEY" \
-H "Content-Type: application/json" \
-d "{\"requestId\": \"$req_id\"}")
This path downloads a remotely provided video URL directly to a local file with no host, scheme, redirect, content-type, or size validation. In practice, that creates a client-side arbitrary fetch primitive that could be abused via compromised API responses or malicious intermediaries.
" 2>/dev/null)
if [ -n "$video_url" ] && [ "$video_url" != "None" ]; then
curl -s "$video_url" -o "$output"
echo "✅ 视频已下载: $output"
else
echo "$resp" | python3 -m json.tool 2>/dev/null
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
echo " 文本: $text"
echo " 音色: $voice"
curl -s -X POST "$BASE_URL/audio/speech" \
-H "Authorization: Bearer $API_KEY" \
-H "Content-Type: application/json" \
-d "{
The skill advertises shell-driven setup and execution but does not declare any explicit tool scope such as shell or file-write permissions. This creates a mismatch between what the skill can do and what a user or platform policy reviewer can assess, increasing the chance of unintended command execution or local file modification without clear consent boundaries.
The description says to use this skill whenever a user needs to generate images, video, or audio, which is very broad and can cause the agent to invoke it in many contexts without sufficient user awareness. Because the skill performs shell actions, stores an API key locally, and sends content to a third-party service, overbroad triggering raises the risk of unnecessary external transmission and unintended cost-incurring actions.
The skill describes generation features and local key storage, but it does not clearly warn that user prompts, uploaded images, and text content are transmitted to SiliconFlow's external API for processing. In this context, the omission is significant because the skill is explicitly designed to handle potentially sensitive media and text, and users may not realize their data leaves the local environment.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
set -e
CONFIG_FILE="$(dirname "$0")/../.sf-config.json"
BASE_URL="https://api.siliconflow.cn/v1"
# 读取配置
load_config() {
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
set -e
CONFIG_FILE="$(dirname "$0")/../.sf-config.json"
BASE_URL="https://api.siliconflow.cn/v1"
# 读取配置
load_config() {
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
echo " 提示词: $prompt"
echo " 尺寸: $size"
resp=$(curl -s -X POST "$BASE_URL/images/generations" \
-H "Authorization: Bearer $API_KEY" \
-H "Content-Type: application/json" \
-d "{
The script downloads content from a URL returned by the remote API and writes it directly to a local file without validating the scheme, host, content type, or size. If the API response is compromised or malicious, this enables SSRF-like access from the local machine to arbitrary URLs and can also write unexpected content to disk.
return 1
fi
curl -s "$url" -o "$output"
echo "✅ 图片已保存: $output"
}
This shell script base64-encodes a local image and includes it in a POST request to the SiliconFlow API, which transmits user file contents off the local system. While the command prints progress information, it does not explicitly disclose that the source image will be uploaded to a remote service, and there is no confirmation prompt or warning comment near the operation.
This code trusts a remotely supplied URL and fetches it directly to a local file without any origin or content validation. A compromised upstream service or manipulated response could cause downloads from attacker-chosen locations, exposing internal network resources or storing malicious/unexpected payloads locally.
return 1
fi
curl -s "$url" -o "$output"
echo "✅ 编辑完成: $output"
}
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# 轮询等待
for i in $(seq 1 60); do
sleep 10
status_resp=$(curl -s -X POST "$BASE_URL/video/status" \
-H "Authorization: Bearer $API_KEY" \
-H "Content-Type: application/json" \
-d "{\"requestId\": \"$req_id\"}")
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# 轮询等待
for i in $(seq 1 60); do
sleep 10
status_resp=$(curl -s -X POST "$BASE_URL/video/status" \
-H "Authorization: Bearer $API_KEY" \
-H "Content-Type: application/json" \
-d "{\"requestId\": \"$req_id\"}")
This function reads a local image, base64-encodes it, and submits it to the remote video generation API. Although status messages are printed, they do not explicitly warn the user that the local file content is being uploaded to an external service, which is the key safety-relevant behavior.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
open('/tmp/sf_req.json', 'w').write(json.dumps(payload))
"
resp=$(curl -s -X POST "$BASE_URL/video/submit" \
-H "Authorization: Bearer $API_KEY" \
-H "Content-Type: application/json" \
-d @/tmp/sf_req.json)
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
echo " 文本: $text"
echo " 音色: $voice"
curl -s -X POST "$BASE_URL/audio/speech" \
-H "Authorization: Bearer $API_KEY" \
-H "Content-Type: application/json" \
-d "{
All user-facing prompts, help text, and defaults are presented only in Chinese, including the default TTS voice of '中文男声'. Under the stated policy, forcing a specific language or locale without user opt-in is a natural-language policy violation unless clearly justified or optional.
Detected: suspicious.potential_exfiltration