T09 · Insecure Skill Coding Practices
- Location
scripts/download_album.py:34- Finding
Path Traversal Through Server-Controlled Album and Asset Names
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill matches its Immich photo-management purpose, but unsafe file-download and credential-handling patterns make it something users should review before installing.
Install only after reviewing the helper scripts. Use a narrowly scoped Immich API key, prefer environment variables or an interactive secret prompt over --api-key, require HTTPS except for explicitly trusted local testing, and avoid the download helper until album and filename path handling is sanitized and contained to the chosen output directory.
scripts/download_album.py:34Path Traversal Through Server-Controlled Album and Asset Names
scripts/upload_photos.py:12API Credentials and Private Media Can Be Transmitted Over Cleartext HTTP
scripts/upload_photos.py:69Immich API Key Exposed Through Command-Line Arguments
The skill documents and encourages network-capable actions against an external Immich instance but does not declare an explicit tool scope such as allowed-tools or permissions. That creates a governance gap: the agent could be invoked for network operations without clear least-privilege boundaries or user-visible constraints, increasing the chance of unintended outbound requests to sensitive self-hosted services.
The trigger conditions are very broad, ending with 'Any Immich-related photo tasks,' which can cause the skill to activate for loosely related requests. In a skill that can access photo libraries, users, albums, and jobs on a self-hosted server, over-broad invocation increases the risk of unintended sensitive operations or data access.
The documentation shows passing the API key directly on the command line via --api-key, which commonly exposes secrets through shell history, process listings, telemetry, and logs. Because the API key grants access to photo assets and account-related endpoints, accidental disclosure could lead to unauthorized data access or service manipulation.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Test connection
curl -H "x-api-key: $IMMICH_API_KEY" "$IMMICH_URL/api/server-info/ping"
The script uses album/API-controlled filenames directly when constructing local output paths, so a malicious or compromised Immich server could supply names containing path separators or traversal sequences and cause writes outside the intended album directory. In a download utility, this expands the tool's filesystem write scope beyond downloading media into a chosen folder and could overwrite user files or place attacker-controlled content in sensitive locations writable by the process.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
album = next((a for a in albums if a.get("albumName") == album_name), None)
if not album:
resp = requests.post(f"{base_url}/api/albums",
headers=headers,
json={"albumName": album_name})
album = resp.json()
No suspicious patterns detected.