T09 · Insecure Skill Coding Practices
- Location
scripts/main.py:91- Finding
Unrestricted Local File Reading and Transmission Through Image Arguments
- Content
View full analysis
100 and "/" not in value and "\\" not in value: return {"Base64": value} ``` The data is placed into the API request at `scripts/submit_job.py:145-165`: ```python for i, (tpl_input, face_input) in enumerate(zip(template_images, face_images)): f ...[truncated 3151 chars]- Remediation
View remediation
MAX_IMAGE_SIZE: raise ValueError("Image exceeds the 10 MB limit") ``` 4. Validate content using JPEG and PNG magic bytes and a maintained image parser. Verify the decoded format and dimensions rather than trusting the extension. 5. Read with a strict size bound instead of unconditionally calling `f.read()`. 6. Require explicit approval before uploading a local file, particularly when its path originated from untrusted conversational content. 7. Clearly disclose that local image contents are transmitted to Tencent Cloud for processing. 8. Prefer presigned, user-controlled URLs where appropriate, while applying URL validation and access controls. ]]>
