T09 · Insecure Skill Coding Practices
- Location
scripts/provider_manager.py:143- Finding
Unrestricted Configurable Endpoint Requests Enable SSRF and Local-Network Probing
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a real multi-provider model-routing skill, but it needs Review because its local discovery and credential workflows are broader and less controlled than the docs make clear.
Install only if you are comfortable with the skill probing configured local model endpoints and writing local config/cache files. Before use, restrict discovery endpoints to trusted localhost addresses, avoid running provider_manager.py on configs from others, use environment variables instead of inline api_key values, add runtime config and cache files to your own .gitignore, and rotate any key ever committed or shared.
scripts/provider_manager.py:143Unrestricted Configurable Endpoint Requests Enable SSRF and Local-Network Probing
examples/add_openai.yaml:4Plaintext API-Key Workflow Can Expose Provider Credentials
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
api_key_env: BAILIAN_API_KEY
BAILIAN_API_KEY=sk-sp-xxx
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
api_key_env: BAILIAN_API_KEY
BAILIAN_API_KEY=sk-sp-xxx
The documented purpose is model assignment/routing, but the described behavior also includes local endpoint scanning, provider management, and file/cache manipulation. This mismatch is dangerous because users may invoke the skill expecting passive routing logic while it performs broader discovery and system-affecting actions, undermining informed consent and increasing the attack surface.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
local_first: false
# 环境变量设置说明
# 在 .env.local 文件中设置(不要提交到 Git):
# OPENAI_API_KEY=sk-proj-xxxxxxxxxxxxxxxxxxxxxxxx
This markdown file is written almost entirely in Chinese and labels some content as bilingual elsewhere, but this file itself does not offer a language choice or explain that it is intentionally region-specific. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.
The skill advertises and documents capabilities that imply network access, filesystem read/write, and possible environment use, but it does not declare any tool scope or permissions boundaries. In an agent ecosystem, missing explicit permissions increases the chance that a user or host system grants broader access than expected, making unintended local inspection or modification easier.
The skill explicitly promotes automatic scanning of local model services but does not warn that it will inspect the local environment and contact localhost endpoints. Even if limited to local services, this can reveal installed tooling, enumerate internal services, and trigger unintended requests against sensitive local interfaces.
The quick-start and management commands include a scan action without explaining that it will automatically discover and contact local model services. Users may run the command as a harmless inventory step, but it can perform active probing of local endpoints and create network or audit side effects on the host.
The file is entirely written in Chinese, including headings and status text, with no indication that language selection is optional or that the file is intentionally region-specific. Per the policy criteria, forcing a specific language without user opt-in can constitute a natural-language policy violation.
This manifest contains user-facing natural-language instructions such as setup guidance and warnings entirely in Chinese. Under the language/locale policy, forcing a single language without user opt-in or justification is a policy concern because non-Chinese-speaking users may be unable to safely configure the skill.
The README instructs users to configure API keys for third-party providers without clearly warning that prompts, metadata, and possibly sensitive agent data may be transmitted to external cloud services. In a multi-provider routing skill, this omission is more significant because the system can route tasks across several vendors, increasing the chance of unintentional data exposure.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
type: openai-compatible
enabled: true
priority: 2
base_url: https://api.openai.com/v1
api_key_env: OPENAI_API_KEY # ✅ 推荐使用环境变量
# api_key: sk-proj-XXXXXXXXXXXXXXXXXXXXXXXX # ⚠️ 或临时测试用(不要提交)
timeout: 30
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
type: openai-compatible
enabled: true
priority: 2
base_url: https://api.openai.com/v1
api_key_env: OPENAI_API_KEY # ✅ 推荐使用环境变量
# api_key: sk-proj-XXXXXXXXXXXXXXXXXXXXXXXX # ⚠️ 或临时测试用(不要提交)
timeout: 30
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
type: openai-compatible
enabled: true
priority: 2
base_url: https://api.openai.com/v1
api_key_env: OPENAI_API_KEY # ✅ 推荐使用环境变量
# api_key: sk-proj-XXXXXXXXXXXXXXXXXXXXXXXX # ⚠️ 或临时测试用(不要提交)
timeout: 30
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
type: openai-compatible
enabled: true
priority: 2
base_url: https://api.openai.com/v1
api_key_env: OPENAI_API_KEY # ✅ 推荐使用环境变量
# api_key: sk-proj-XXXXXXXXXXXXXXXXXXXXXXXX # ⚠️ 或临时测试用(不要提交)
timeout: 30
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
type: openai-compatible
enabled: true
priority: 2
base_url: https://api.openai.com/v1
api_key_env: OPENAI_API_KEY # ✅ 推荐使用环境变量
# api_key: sk-proj-XXXXXXXXXXXXXXXXXXXXXXXX # ⚠️ 或临时测试用(不要提交)
timeout: 30
SQP-3 applies to all file types and covers language or locale policy violations. The module docstring presents the skill only in Chinese, with no indication that users may choose another language or that the skill is intentionally region-specific.
This code file contains natural-language descriptions, docstrings, and console output in Chinese, but does not indicate that the language is optional or limited to a Chinese-speaking audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.
This markdown file advertises 'Automatically scan and discover local model services' as a feature, but it does not warn users that invoking scanning will send requests to local endpoints and probe running services. For a markdown skill description, this is a user-visible behavior that can affect system/privacy awareness and should be disclosed more explicitly.
The README instructs users to run the scan command directly, but provides no warning that this operation performs network requests to local services such as Ollama or LM Studio. Because this markdown serves as user guidance, omitting that disclosure can leave users unaware of the operation's effect on their local system.
The documentation promotes automatic scanning of local model services but does not clearly warn that this feature will actively send requests to localhost endpoints and may enumerate locally exposed services. In this skill context, that behavior is expected functionality, but the missing disclosure can still surprise users and reduce informed consent around local network probing.
This manifest contains user-facing comments and instructions primarily in Chinese, with some English, but does not state that the file is intended only for Chinese-speaking users or offer a language/locale alternative. Under the natural-language policy rule, forcing a specific language without opt-in can be a policy concern even in configuration comments.
This YAML file contains user-facing natural language comments entirely in Chinese, such as setup warnings and configuration guidance. Under the policy for natural-language violations, forcing a specific language without opt-in can be a locale policy issue when no alternative language or justification is provided.
No suspicious patterns detected.