T09 · Insecure Skill Coding Practices
- Location
scripts/main.py:50- Finding
Arbitrary API Base Allows Sensitive Document and Credential Redirection
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a disclosed SCNET OCR uploader, but it can be configured to send sensitive documents and the bearer token to an arbitrary API base while warning users only about the default SCNET destination.
Review this skill before installing. Use it only when you are comfortable uploading the selected document to SCNET, avoid sensitive documents unless you have authority and consent, and check that `SCNET_API_BASE` is unset or exactly the intended HTTPS SCNET endpoint before running because a changed value could redirect both the file and API key.
scripts/main.py:50Arbitrary API Base Allows Sensitive Document and Credential Redirection
SKILL.md:78Unpinned Third-Party Dependency Installation
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 获取技能根目录(脚本所在目录的上一级)
SKILL_ROOT = Path(__file__).parent.parent.absolute()
ENV_FILE = SKILL_ROOT / "config" / ".env"
# --- 新增:重试配置 ---
MAX_RETRIES = 3 # 最大重试次数
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# --------------------
def load_config():
"""从环境变量或 .env 文件加载配置,环境变量优先"""
config = {}
# 1. 如果 config/.env 存在,先加载其中的变量
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# --------------------
def load_config():
"""从环境变量或 .env 文件加载配置,环境变量优先"""
config = {}
# 1. 如果 config/.env 存在,先加载其中的变量
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# --------------------
def load_config():
"""从环境变量或 .env 文件加载配置,环境变量优先"""
config = {}
# 1. 如果 config/.env 存在,先加载其中的变量
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# --------------------
def load_config():
"""从环境变量或 .env 文件加载配置,环境变量优先"""
config = {}
# 1. 如果 config/.env 存在,先加载其中的变量
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# --------------------
def load_config():
"""从环境变量或 .env 文件加载配置,环境变量优先"""
config = {}
# 1. 如果 config/.env 存在,先加载其中的变量
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
* [Get started with GitLab CI/CD](https://docs.gitlab.com/ee/ci/quick_start/)
* [Analyze your code for known vulnerabilities with Static Application Security Testing (SAST)](https://docs.gitlab.com/ee/user/application_security/sast/)
* [Deploy to Kubernetes, Amazon EC2, or Amazon ECS using Auto Deploy](https://docs.gitlab.com/ee/topics/autodevops/requirements.html)
* [Use pull-based deployments for improved Kubernetes management](https://docs.gitlab.com/ee/user/clusters/agent/)
* [Set up protected environments](https://docs.gitlab.com/ee/ci/environments/protected_environments.html)
The skill explicitly requires environment variables, local file access, network access, and shell execution, but it does not declare any tool scope or permission boundaries. That creates an authorization gap where the host agent may invoke broad capabilities without clear least-privilege constraints or user-visible consent boundaries.
The skill sends user-supplied images and PDFs to an external OCR service, and the documented file types include highly sensitive documents such as IDs, bank cards, passports, and medical records. Even though the skill warns about privacy, external transmission of such data is inherently risky because it exposes sensitive content to a third party and depends on that provider's data handling practices.
SCNET_API_KEY=your_scnet_api_key_here
SCNET_API_BASE=https://api.scnet.cn/api/llm/v1
2. 添加:`SCNET_API_KEY=你的密钥`
3. 设置文件权限为 600(仅所有者可读写)
This configuration section again confirms outbound transmission to the SCNET API and normalizes a default external endpoint for processing user documents. In context, the skill is specifically designed to handle regulated and sensitive records, so the external transfer risk is amplified despite the presence of disclosure text.
| 变量名 | 默认值 | 说明 |
|--------|--------|------|
| SCNET_API_KEY | 必需 | Scnet API 密钥 |
| SCNET_API_BASE | https://api.scnet.cn/api/llm/v1 | API 基础地址(一般无需修改) |
### 数据使用与保留
This template documents OCR extraction of extensive highly sensitive personal and financial data, including ID numbers, passports, bank cards, medical records, payment instruments, and customs/financial documents, but provides no privacy, consent, retention, masking, or access-control guidance. In the context of an OCR skill intended to process exactly these document types, that omission can normalize unsafe handling of regulated data and increase the risk of over-collection, exposure, downstream misuse, or noncompliant integrations.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
> 接口返回的识别结果可能包含 PII,请妥善保管,避免泄露或持久化到不安全位置。
## 接口地址
`POST https://api.scnet.cn/api/llm/v1/ocr/recognize`
## 请求头
- `Content-Type: multipart/form-data`
The script uploads user-supplied files to a third-party OCR endpoint by default, which is a real data exfiltration/privacy risk because the supported document types include highly sensitive IDs, bank cards, medical and financial records. Although the code prints a warning, it still transmits the full document off-host and does not enforce consent, destination allowlisting beyond configurability, or data minimization.
config['SCNET_API_BASE'] = env_api_base
# 3. 设置默认值
config.setdefault('SCNET_API_BASE', 'https://api.scnet.cn/api/llm/v1')
# 4. 检查必要配置
api_key = config.get('SCNET_API_KEY', '')
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
"2. 配置文件:\n"
f" mkdir -p {SKILL_ROOT}/config\n"
f" echo 'SCNET_API_KEY=你的真实密钥' > {ENV_FILE}\n"
f" chmod 600 {ENV_FILE}\n"
)
sys.exit(error_msg)
The file is entirely written in Chinese, including headings and operational notes, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific audience. Under the policy rule for language/locale, this can be a natural-language policy concern when no opt-in or justification is provided.
The manifest description is entirely in Chinese and frames the skill's use conditions only in Chinese, which can amount to a language/locale constraint in the skill's natural-language interface. The file does not explicitly state that other languages are accepted or offer a language choice/opt-in.
The file presents all user-facing documentation in Chinese only, with no indication that users can choose another language or that the language restriction is intentional and justified. This can violate the language/locale policy when a skill forces a specific language without user opt-in.
No suspicious patterns detected.