T09 · Insecure Skill Coding Practices
- Location
scripts/main.py:84- Finding
Configurable API endpoint can redirect sensitive invoice data and credentials
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears to be a legitimate cloud OCR tool, but it uploads sensitive vehicle invoice files and its bearer token to a configurable network endpoint without tight destination controls or strong privacy disclosure.
Install only if you are comfortable sending complete vehicle sales invoices to Sugon-Scnet or another configured OCR endpoint. Keep `SCNET_API_BASE` at the documented HTTPS Scnet host unless you have explicitly approved another endpoint, protect the `.env` file, and consider whether invoices contain data that requires consent, redaction, or vendor review before upload.
scripts/main.py:84Configurable API endpoint can redirect sensitive invoice data and credentials
skill.yaml:21Third-party dependency is not version-pinned or integrity-verified
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 获取技能根目录(脚本所在目录的上一级)
SKILL_ROOT = Path(__file__).parent.parent.absolute()
ENV_FILE = SKILL_ROOT / "config" / ".env"
# --- 新增:重试配置 ---
MAX_RETRIES = 3 # 最大重试次数
RETRY_BACKOFF_FACTOR = 2 # 退避因子,每次重试等待时间翻倍
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
INITIAL_RETRY_DELAY = 1 # 初始等待时间(秒)
# --------------------
def load_config():
"""从 .env 文件加载配置,若文件不存在则抛出友好错误"""
if not ENV_FILE.exists():
error_msg = (
"\n===============================================\n"
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
INITIAL_RETRY_DELAY = 1 # 初始等待时间(秒)
# --------------------
def load_config():
"""从 .env 文件加载配置,若文件不存在则抛出友好错误"""
if not ENV_FILE.exists():
error_msg = (
"\n===============================================\n"
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
INITIAL_RETRY_DELAY = 1 # 初始等待时间(秒)
# --------------------
def load_config():
"""从 .env 文件加载配置,若文件不存在则抛出友好错误"""
if not ENV_FILE.exists():
error_msg = (
"\n===============================================\n"
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
* [Get started with GitLab CI/CD](https://docs.gitlab.com/ee/ci/quick_start/)
* [Analyze your code for known vulnerabilities with Static Application Security Testing (SAST)](https://docs.gitlab.com/ee/user/application_security/sast/)
* [Deploy to Kubernetes, Amazon EC2, or Amazon ECS using Auto Deploy](https://docs.gitlab.com/ee/topics/autodevops/requirements.html)
* [Use pull-based deployments for improved Kubernetes management](https://docs.gitlab.com/ee/user/clusters/agent/)
* [Set up protected environments](https://docs.gitlab.com/ee/ci/environments/protected_environments.html)
The skill documentation indicates capabilities to read local files, invoke Python from the shell, and send data over the network, but it does not declare any explicit tool scope such as permissions or allowed-tools. That creates a least-privilege gap: an agent may execute the skill with broader access than necessary, increasing the chance that sensitive local files or OCR inputs are transmitted externally without clear operator constraints.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
SCNET_API_KEY=your_scnet_api_key_here
SCNET_API_BASE=https://api.scnet.cn/api/llm/v1
2. 添加:`SCNET_API_KEY=你的密钥`
3. 设置文件权限为 600(仅所有者可读写)
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
SCNET_API_KEY=your_scnet_api_key_here
SCNET_API_BASE=https://api.scnet.cn/api/llm/v1
2. 添加:`SCNET_API_KEY=你的密钥`
3. 设置文件权限为 600(仅所有者可读写)
The file explicitly defines an external OCR API endpoint, meaning uploaded invoice files and their extracted contents are transmitted to a remote service outside the local skill boundary. External transmission is not inherently malicious, but in this case it is security-relevant because the data includes sensitive vehicle, identity, and tax information, and the documentation does not describe trust boundaries, encryption expectations beyond HTTPS, or provider data governance.
# Sugon-Scnet OCR API 文档摘要
## 接口地址
`POST https://api.scnet.cn/api/llm/v1/ocr/recognize`
## 请求头
- `Content-Type: multipart/form-data`
The documentation describes uploading vehicle sales invoices to a third-party OCR endpoint and shows extraction of highly sensitive personal, financial, and vehicle-identifying data such as buyer identity, VIN, engine number, tax IDs, and payment amounts, but it provides no warning about remote data transmission, retention, or privacy implications. In this skill context, the omission is more dangerous because the processed documents are explicitly rich in regulated or sensitive information, so users may unknowingly transmit PII and financial records off-platform.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
" b) 配置文件:\n"
f" mkdir -p {SKILL_ROOT}/config\n"
f" echo 'SCNET_API_KEY=你的密钥' > {ENV_FILE}\n"
f" chmod 600 {ENV_FILE}\n"
"\n配置完成后重新运行。"
)
sys.exit(error_msg)
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
" b) 配置文件:\n"
f" mkdir -p {SKILL_ROOT}/config\n"
f" echo 'SCNET_API_KEY=你的密钥' > {ENV_FILE}\n"
f" chmod 600 {ENV_FILE}\n"
"\n配置完成后重新运行。"
)
sys.exit(error_msg)
The skill transmits vehicle sales invoice images and extracted personal/vehicle data to an external third-party API endpoint. Because the documents contain sensitive identifiers such as VIN, engine number, buyer information, tax amounts, and certificate numbers, this creates a real data exfiltration/privacy risk if users are unaware, if the service is untrusted, or if regulatory controls require local processing.
)
sys.exit(error_msg)
config.setdefault('SCNET_API_BASE', 'https://api.scnet.cn/api/llm/v1')
return config
def recognize_with_retry(ocr_type, file_path, config, retry_count=0):
The file presents user-facing natural language almost entirely in Chinese, starting with the title and release notes, without indicating that this locale is optional or region-specific. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation.
No suspicious patterns detected.