T09 · Insecure Skill Coding Practices
- Location
scripts/search_faces.py:33- Finding
Biometric Images Are Retained Remotely by Default
- Content
View full analysis
dict: api_key = get_api_key() with open(image_path, "rb") as f: files = {"user_image": (os.path.basename(image_path), f, "image/jpeg")} data = {} if rotate: data["rotate_image"] = "true" if vendor_data: data["vendor_data"] = vendor_data r = requests.post(ENDPOINT, headers={"x-api-key": api_key}, files=files, data=data, timeout=60) ``` The API documentation states: ```markdown | `user_image` | file | **Yes** | — | Face image to search (JPEG/PNG/WebP/TIFF, max 5MB) | | `rotate_image` | boolean | No | `false` | Try 0/90/180/270 rotations for non-upright faces | | `save_api_request` | boolean | No | `true` | Save in Business Console | | `vendor_data` | string | No | — | Your identifier for session tracking | ``` ### Technical Analysis Uploading a face image and the `DIDIT_API_KEY` to the documented Didit HTTPS endpoint is disclosed and required for the Skill's remote face-search functionality. The destination is hardcoded as `https://verification.didit.me/v3/face-search/`, and no covert secondary recipient was identified. However, the API defaults `save_api_request` to `true`, while the script does not override that behavior. Consequently, every submitted biometric image may be retained in the Didit Business Console even when the operator only needs an immediate search result. Remote retention is not necessary for the core one-time comparison operation and therefore exceeds minimum data handling requirements. Face images are sensitive biometric data. Unlike ordinary credentials, biometric traits cannot readily be changed after compromi ...[truncated 1326 chars]- Remediation
View remediation
