External Transmission
- Category
- Data Exfiltration
- Confidence
- 91% confidence
- Finding
The README instructs use of a remote API endpoint with bearer-token authentication, meaning prompts and possibly sensitive user-provided content are sent to an external service. In a content-generation skill this external transmission is expected, but it remains security-relevant because users are not warned about data egress, third-party processing, retention, or billing implications.
- Content
bash # 生成视频 curl -X POST "https://ark.cn-beijing.volces.com/api/v3/contents/generations/tasks" \ -H "Content-Type: application/json" \ -H "Authorization: Bearer ${API_KEY}" \ -d '{
