T09 · Insecure Skill Coding Practices
- Location
scripts/main.py:78- Finding
Unrestricted API Endpoint Override Can Disclose Credentials and Uploaded Documents
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This OCR skill does what it claims, but it can upload sensitive license documents and the API token to a configurable remote endpoint without enforcing the documented provider.
Install only if you are comfortable sending health-license images or PDFs and the Scnet API token to an external OCR service. Before use, keep config/.env private, do not paste the token into chat, verify SCNET_API_BASE is exactly the intended Scnet HTTPS endpoint, and avoid uploading documents without authorization or privacy review.
scripts/main.py:78Unrestricted API Endpoint Override Can Disclose Credentials and Uploaded Documents
SKILL.md:64Unpinned Third-Party Dependency Installation
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 获取技能根目录(脚本所在目录的上一级)
SKILL_ROOT = Path(__file__).parent.parent.absolute()
ENV_FILE = SKILL_ROOT / "config" / ".env"
# --- 新增:重试配置 ---
MAX_RETRIES = 3 # 最大重试次数
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# --------------------
def load_config():
"""从 .env 文件加载配置,若文件不存在则抛出友好错误"""
if not ENV_FILE.exists():
error_msg = (
"\n===============================================\n"
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# --------------------
def load_config():
"""从 .env 文件加载配置,若文件不存在则抛出友好错误"""
if not ENV_FILE.exists():
error_msg = (
"\n===============================================\n"
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# --------------------
def load_config():
"""从 .env 文件加载配置,若文件不存在则抛出友好错误"""
if not ENV_FILE.exists():
error_msg = (
"\n===============================================\n"
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
* [Get started with GitLab CI/CD](https://docs.gitlab.com/ee/ci/quick_start/)
* [Analyze your code for known vulnerabilities with Static Application Security Testing (SAST)](https://docs.gitlab.com/ee/user/application_security/sast/)
* [Deploy to Kubernetes, Amazon EC2, or Amazon ECS using Auto Deploy](https://docs.gitlab.com/ee/topics/autodevops/requirements.html)
* [Use pull-based deployments for improved Kubernetes management](https://docs.gitlab.com/ee/user/clusters/agent/)
* [Set up protected environments](https://docs.gitlab.com/ee/ci/environments/protected_environments.html)
The skill documents capabilities that imply local file access, network access, and shell execution, but it does not declare any explicit tool scope such as permissions or allowed-tools. That creates an authorization gap where an agent may invoke broader capabilities than users or platform policy expect, increasing the chance of unintended file access or outbound requests.
The skill is explicitly designed to transmit user-provided document images to an external API endpoint for OCR processing. Because the content is a卫生许可证 and may contain regulated or sensitive business data, sending local files off-host creates a real data exposure risk if users are not clearly informed and if endpoint restrictions are not enforced.
SCNET_API_KEY=your_scnet_api_key_here
SCNET_API_BASE=https://api.scnet.cn/api/llm/v1
2. 添加:`SCNET_API_KEY=你的密钥`
3. 设置文件权限为 600(仅所有者可读写)
The activation guidance says the AI may auto-trigger the skill based on broad descriptive keywords, without clear constraints on when it should or should not run. In a skill that reads local file paths and sends document contents to an external OCR API, ambiguous triggering raises the risk of unintended invocation and accidental exfiltration of sensitive documents.
This configuration section confirms use of a third-party API base for processing OCR requests, meaning local document data will leave the environment. In the context of identity or license OCR, the external transmission is security-relevant because accidental uploads could expose sensitive content or violate data-handling expectations.
| 变量名 | 默认值 | 说明 |
|--------|--------|------|
| SCNET_API_KEY | 必需 | Scnet API 密钥 |
| SCNET_API_BASE | https://api.scnet.cn/api/llm/v1 | API 基础地址(一般无需修改) |
### 输出
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Sugon-Scnet OCR API 文档摘要
## 接口地址
`POST https://api.scnet.cn/api/llm/v1/ocr/recognize`
## 请求头
- `Content-Type: multipart/form-data`
The documentation instructs users to upload potentially sensitive license images and PDFs to a third-party OCR API but provides no privacy, retention, consent, or data-handling warning. Because health/sanitation license documents may contain business and personal information, this omission increases the risk of unauthorized disclosure, compliance violations, and unsafe use in privacy-sensitive environments.
The module docstring and all user-facing messages are written only in Chinese, and the script specifies output behavior without indicating any language choice or opt-in. Under the policy, forcing a specific language is a natural-language locale violation unless the constraint is explicitly justified as region-specific or optional.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
" b) 配置文件:\n"
f" mkdir -p {SKILL_ROOT}/config\n"
f" echo 'SCNET_API_KEY=你的密钥' > {ENV_FILE}\n"
f" chmod 600 {ENV_FILE}\n"
"\n配置完成后重新运行。"
)
sys.exit(error_msg)
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
" b) 配置文件:\n"
f" mkdir -p {SKILL_ROOT}/config\n"
f" echo 'SCNET_API_KEY=你的密钥' > {ENV_FILE}\n"
f" chmod 600 {ENV_FILE}\n"
"\n配置完成后重新运行。"
)
sys.exit(error_msg)
This skill uploads the user-supplied file to an external third-party OCR API at api.scnet.cn. Because the input is a health license document, it may contain sensitive business or personal information, so external transmission creates privacy, compliance, and data-handling risk if users are not explicitly informed or if endpoint configuration is altered.
)
sys.exit(error_msg)
config.setdefault('SCNET_API_BASE', 'https://api.scnet.cn/api/llm/v1')
return config
def recognize_with_retry(ocr_type, file_path, config, retry_count=0):
The manifest description is written only in Chinese ('支持卫生许可证的票据识别。') and provides no indication that users may choose another language or that the skill is intentionally limited to a Chinese-language or region-specific audience. Under the policy, forcing a specific language or locale without opt-in is a natural-language policy concern.
This markdown file uses Chinese for the title and entry text, which may impose a specific language without any stated opt-in or justification. Under the natural-language policy rule, forcing a language can be a policy concern when no locale scope or user choice is documented.
The manifest description is presented entirely in Chinese, and the file does not indicate that this language restriction is optional, user-selectable, or justified as a region-specific skill constraint. This can violate language/locale policy expectations when a skill implicitly forces a specific language without opt-in.
L130 states that the skill '会自动等待并重试(最多 3 次)', which is a concrete behavioral claim about automatic retry logic. In the provided skill file, there is no corresponding implementation detail or referenced retry mechanism; for a single-file audit, this is an intent/documentation claim that is unsupported by the actual artifact shown.
This markdown file presents all operational instructions and API details only in Chinese. That can constitute a language/locale policy issue when users are not given an explicit choice or justification for the language restriction.
No suspicious patterns detected.