T09 · Insecure Skill Coding Practices
- Location
scripts/gen_image.py:27- Finding
Hardcoded ThinkZone API Credentials Committed to Source and Documentation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent image-generation tool, but it exposes real-looking API credentials and allows sensitive prompts/images to be sent through loosely scoped API configuration.
Review before installing. Use only your own rotated ThinkZone key, remove all bundled plaintext keys, avoid machine-wide or hardcoded secrets, and do not send sensitive prompts or private reference images unless you intend them to be uploaded to the configured external API endpoint.
scripts/gen_image.py:27Hardcoded ThinkZone API Credentials Committed to Source and Documentation
scripts/gen_image.py:409Caller-Controlled API Destination Can Receive Bearer Credentials and Private Reference Images
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
)
try:
with urllib.request.urlopen(req, timeout=120) as response:
result = json.loads(response.read().decode("utf-8"))
except urllib.error.HTTPError as e:
error_body = e.read().decode("utf-8")
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
)
try:
with urllib.request.urlopen(req, timeout=120) as response:
result = json.loads(response.read().decode("utf-8"))
except urllib.error.HTTPError as e:
error_body = e.read().decode("utf-8")
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
)
try:
with urllib.request.urlopen(req, timeout=120) as response:
result = json.loads(response.read().decode("utf-8"))
except urllib.error.HTTPError as e:
error_body = e.read().decode("utf-8")
The file contains what appears to be a live ThinkZone API key directly in documentation and instructs users to persist it in their environment. Hardcoding and publishing secrets in a skill repository enables anyone with access to the file to reuse the credential, leading to unauthorized API usage, quota exhaustion, billing abuse, and possible access to associated account resources.
The test command embeds the real API key in an example shell command, which increases exposure through shell history, terminal logs, screenshots, copy/paste sharing, and CI transcripts. In the context of an image-generation skill that calls a paid external API, this directly facilitates credential theft and downstream billing or service abuse.
The document contains a live-looking API key in plaintext and instructs users to copy it directly into an environment variable. This is a real secret exposure issue because anyone with access to the repository or documentation can reuse the credential for unauthorized API calls, billing abuse, or pivoting into connected services; in a distributable agent skill, that context makes the leak more dangerous rather than less.
The document contains what appears to be a live API key in plaintext, which is a direct secret exposure. Anyone with access to this file can reuse the credential to call the external image-generation service, incur charges, access account-linked resources, or pivot into broader compromise depending on the provider's permissions.
The skill is configured to auto-trigger for any agent on very common phrases like '生成图片' or '做一张图', creating a broad activation surface and increasing the chance of unintended execution. In a multi-agent environment, this can cause accidental external API calls, unexpected spending, and transmission of user content without deliberate consent or contextual validation.
The document explicitly includes a live API key and recommends hardcoding it into source code or setting it broadly at the system level. This creates a direct secret exposure risk: anyone with access to the repository, docs, logs, screenshots, or host environment can reuse the credential to make unauthorized API calls, incur cost, and potentially access account-scoped resources.
The file discloses an actual API key and instructs users to set it at machine scope without any warning about secret hygiene, access control, rotation, or auditability. For an image-generation skill, this is unjustified and broadens exposure across all processes on the host, making theft or misuse more likely through local compromise, debugging tools, accidental disclosure, or shared administration.
The declared purpose focuses on image generation, but the documented behavior also implies reading local reference images, writing generated files to disk, and using external network access with sensitive credentials. That mismatch is dangerous because users may provide prompts or local files without realizing data leaves the machine and artifacts are persisted locally, creating confidentiality and consent risks.
The declared purpose focuses on image generation, but the documented behavior also implies reading local reference images, writing generated files to disk, and using external network access with sensitive credentials. That mismatch is dangerous because users may provide prompts or local files without realizing data leaves the machine and artifacts are persisted locally, creating confidentiality and consent risks.
The document plainly discloses what appears to be a live ThinkZone API key in a markdown file. Exposed API credentials can be copied by anyone with repository or artifact access and then abused to generate images, incur charges, exhaust quotas, or access related account resources; the surrounding 'test success' context makes it look like a real working secret rather than a placeholder.
The test instructions tell users to export the same real API key into environment variables, further propagating credential exposure and encouraging unsafe handling of secrets. This increases the chance the key will be copied into shell history, screenshots, logs, support messages, or reused by others who read the file.
The code silently falls back to a hardcoded API key when THINKZONE_API_KEY is unset, which embeds a live credential in the skill and causes undisclosed use of that credential. In a distributed skill, anyone with code access can extract and abuse the key, leading to unauthorized API consumption, billing exposure, and possible account compromise or service suspension.
A hardcoded fallback API key is a credential exposure issue and also hides from users/operators that the script may authenticate with an embedded secret. This enables unauthorized reuse by anyone who can read the repository or packaged skill, potentially causing financial loss and abuse of the linked ThinkZone account.
A sensitive API credential is embedded and used without any disclosure, consent flow, or operational safeguards. Beyond secrecy loss, this means anyone running the script may unknowingly consume external paid resources and send requests under the owner’s account.
The file is entirely written in Chinese and even the example prompt content is fixed to Chinese, with no indication that language choice is optional. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly justified.
The documentation describes automatic image generation through an external API but does not clearly disclose that prompts and possibly reference images will be sent to a third-party service. This creates a privacy and compliance risk because users or downstream agents may unknowingly transmit sensitive data outside the local environment.
Presenting credential embedding as a normal configuration fallback normalizes insecure secret handling and increases the chance that developers will copy the pattern into production code. Even if framed as a backup option, it undermines environment-based secret management and can lead to long-lived credentials being committed to source control or distributed to multiple agents and hosts.
The manifest describes an image-generation skill supporting exactly three model families: Gemini, MiniMax, and Seedream. The README instead presents the skill as a BytePlus Seedream-only tool with five supported models, which materially changes the claimed capabilities and scope exposed to users.
The README documents an image parameter that accepts URL or Base64 reference images, but it does not warn users that those images may be transmitted to an external third-party service for processing. This creates a privacy and data-handling risk because users may unknowingly upload sensitive, personal, or proprietary images outside their environment.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
--model seedream-5-0-260128
### 示例 5:cURL 调用
```bash
curl -X POST "https://open.thinkzoneai.com/v3/images/generations" \
The skill advertises executable behavior involving environment variables, shell execution, network access, and file writes, but it does not declare any explicit tool scope such as permissions or allowed-tools. This weakens reviewability and containment because a host may grant broader capabilities than users or operators expect, especially for a skill that can transmit prompts and local image paths to an external service and save outputs locally.
The trigger phrases are broad everyday terms like '画图', '生成图片', and '做一张图', which can cause the skill to activate in situations where the user did not intend external API usage or file handling. In context, unintended activation matters because the skill can send prompts and possibly reference images to a third-party service and write outputs locally.
Detected: suspicious.exposed_secret_literal