T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/gateway.py:50- Finding
Unauthenticated Public Gateway Permits Unauthorized Use of Provider Accounts
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a disclosed AI API gateway guide, but its included gateway code can expose users' provider accounts through an unauthenticated public-facing service.
Review this before installing or running it. The guide can be useful for comparing China-based AI APIs, but do not expose the included gateway on a network without adding authentication, local-only binding, rate limits, request size limits, and quota controls. Store provider keys in environment variables or a secret manager, avoid committing real keys to YAML, and assume any prompt or code sent through the examples may be transmitted to third-party AI providers.
scripts/gateway.py:50Unauthenticated Public Gateway Permits Unauthorized Use of Provider Accounts
scripts/config.yaml:1Provider Credentials Are Designed to Be Stored in Plaintext Configuration
The skill documents code and configuration that read environment variables and make outbound network requests, but it declares no corresponding tool scope or permissions. This creates a capability/visibility mismatch: an orchestrator or reviewer may not realize the skill can access secrets and transmit data to external providers.
The trigger keywords include broad everyday phrases such as switching models or API usage that may match benign conversations outside the intended context. Overbroad activation can cause unintended invocation of a skill that recommends third-party services and external API usage, increasing the chance of surprise data disclosure or irrelevant actions.
The activation matrix uses ambiguous examples like 'OpenAI compatible' or 'API gateway' without requiring intent qualifiers such as domestic-provider aggregation or provider switching. This can cause the skill to trigger on general developer questions and steer users toward external services unexpectedly.
The skill provides setup and call examples that send prompts and credentials to third-party APIs, but it does not clearly warn users that their inputs will leave the local environment. In a gateway context, this is more sensitive because the skill encourages multi-provider routing and fallback, which can multiply external disclosures across vendors.
This example performs an outbound API request containing user prompts and a bearer credential. The behavior is expected for an API-gateway skill, but it is still security-relevant because users may copy it without understanding that sensitive data will be transmitted to an external provider.
# 小米MiMo
curl https://api.xiaomimimo.com/v1/chat/completions \
-H "Content-Type: application/json" \
-H "Authorization: Bearer $MIMO_API_KEY" \
-d '{
This example performs an outbound API request containing user prompts and a bearer credential. The behavior is expected for an API-gateway skill, but it is still security-relevant because users may copy it without understanding that sensitive data will be transmitted to an external provider.
# 小米MiMo
curl https://api.xiaomimimo.com/v1/chat/completions \
-H "Content-Type: application/json" \
-H "Authorization: Bearer $MIMO_API_KEY" \
-d '{
This curl example sends prompts and an authorization token to DeepSeek over the network. In context, the risk is not malicious code execution but unannounced third-party data exposure and possible credential mishandling by users who paste real secrets into examples.
}'
# DeepSeek
curl https://api.deepseek.com/v1/chat/completions \
-H "Content-Type: application/json" \
-H "Authorization: Bearer $DEEPSEEK_API_KEY" \
-d '{
The Python SDK example configures an external base URL and API key for remote inference. This is normal functionality, but in a skill document it should be treated as a disclosure point because copied code may send arbitrary prompt contents outside the user's trust boundary.
# 小米MiMo
client = OpenAI(
base_url="https://api.xiaomimimo.com/v1",
api_key="sk-xxxxx"
)
This example directs traffic and credentials to an external DeepSeek endpoint. The skill context makes it more sensitive because it is framed as a drop-in replacement gateway, which can encourage broad reuse without careful review of data-handling implications.
# DeepSeek
client = OpenAI(
base_url="https://api.deepseek.com/v1",
api_key="sk-xxxxx"
)
The streaming example still transmits prompt content and credentials to a third party; streaming changes response handling but not the core disclosure risk. Users may incorrectly assume streaming is local or safer when it still crosses the network boundary.
from openai import OpenAI
client = OpenAI(
base_url="https://api.xiaomimimo.com/v1",
api_key="sk-xxxxx"
)
The gateway configuration example stores provider endpoints and references API keys for multiple third-party services. In a routing/fallback design, a single prompt may be sent to alternate providers, increasing the blast radius of accidental disclosure compared with a single-provider example.
# gateway.yaml
providers:
- name: mimo
base_url: https://api.xiaomimimo.com/v1
api_key: ${MIMO_API_KEY}
models: [mimo-v2.5]
priority: 1
This second provider entry is part of a multi-provider gateway that can forward requests externally to DeepSeek. The security concern is cumulative: additional providers increase the number of external trust boundaries and potential retention/exposure surfaces.
priority: 1
- name: deepseek
base_url: https://api.deepseek.com/v1
api_key: ${DEEPSEEK_API_KEY}
models: [deepseek-chat]
priority: 2
The sample gateway code reads API keys from the environment and uses them to send messages to external providers. That is standard practice, but without explicit warnings it normalizes forwarding arbitrary user input and can mislead users about where their data goes.
PROVIDERS = {
"mimo": {
"base_url": "https://api.xiaomimimo.com/v1",
"api_key": os.getenv("MIMO_API_KEY"),
"models": ["mimo-v2.5"]
},
This provider configuration extends the same gateway forwarding logic to another remote endpoint. In context, the danger is higher than a simple one-off example because retry/fallback logic may cause repeated submissions of the same sensitive input to multiple vendors.
"models": ["mimo-v2.5"]
},
"deepseek": {
"base_url": "https://api.deepseek.com/v1",
"api_key": os.getenv("DEEPSEEK_API_KEY"),
"models": ["deepseek-chat"]
}
The unsupported-scope section states that private deployment is not supported, but a later example recommends and demonstrates self-hosted gateway deployment. Inconsistent scope boundaries increase the chance that users follow risky infrastructure steps without the safety checks that would normally accompany supported deployment guidance.
This section recommends a concrete external API endpoint to users seeking a free AI service. The risk is lower than executable code, but it still encourages direct transmission of user data to a third-party provider without adjacent privacy caveats.
【推荐方案】
🥇 小米MiMo(首选)
• API:https://api.xiaomimimo.com/v1/chat/completions
• 模型:mimo-v2.5
• 额度:当前免费无限
• 中文:⭐⭐⭐⭐⭐
This recommendation names an external DeepSeek endpoint in a way that may prompt immediate use. While informational, it contributes to third-party data-sharing risk if readers are not warned that their prompts will leave their environment.
• 适合:高频调用、中文对话
🥈 DeepSeek(备选)
• API:https://api.deepseek.com/v1/chat/completions
• 模型:deepseek-chat
• 额度:注册送500万tokens
• 推理:⭐⭐⭐⭐⭐
This recommendation promotes DeepSeek-Coder via a remote API endpoint. In a code-generation context, users may paste proprietary code or secrets, making external transmission particularly sensitive even though the example itself is informational.
【推荐方案】
🥇 DeepSeek-Coder(代码最强)
• API:https://api.deepseek.com/v1/chat/completions
• 模型:deepseek-coder
• 额度:500万tokens免费
• 代码:⭐⭐⭐⭐⭐
The code example configures an external DeepSeek client with an API key and is likely to be copied verbatim. For code-assistant use cases, the surrounding context increases risk because users may send proprietary code, secrets, or internal architecture details to a third party unintentionally.
from openai import OpenAI
client = OpenAI(
base_url="https://api.deepseek.com/v1",
api_key="sk-xxxxx"
)
The skill says private/self-hosted deployment consulting is out of scope, yet later provides self-hosted gateway deployment instructions. This contradiction can bypass user expectations and reviewer assumptions, causing the skill to facilitate operational actions it claims not to support.
The deployment example uses a container image reference without a pinned tag or digest, so users may pull an unexpected or later-mutated image. That weakens supply-chain integrity and can expose users to malicious or compromised upstream images without any change to the documentation.
This markdown file appears to force a single language/locale for all users through its title, parameter descriptions, examples, and guidance. The policy allows locale constraints only when users are given a choice or when the restriction is explicitly documented and justified, neither of which is present here.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# 基础对话(curl)
curl http://localhost:18080/v1/chat/completions \
-H "Content-Type: application/json" \
-d '{
"model": "auto",
The example code sends user content directly to external model APIs but does not warn that prompts, attachments, and metadata may be transmitted to third-party providers and subject to their retention policies. In a gateway/integration skill, this omission can mislead users into sending sensitive business or personal data without informed consent or sanitization.
This code example configures a client to send user messages to an external provider, but without any explicit warning about third-party data transmission, retention, or sensitivity handling. In context, the skill encourages easy drop-in replacement, which makes accidental disclosure of confidential prompts more likely.
from openai import OpenAI
client = OpenAI(
base_url="https://api.xiaomimimo.com/v1",
api_key="sk-xxxxx" # 你的API Key
)
No suspicious patterns detected.