T09 · Insecure Skill Coding Practices
- Location
scripts/kiri-engine.ps1:182- Finding
Incomplete image-path validation can upload unintended files
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill appears purpose-built for KIRI Engine 3D scanning, but its image upload path can unintentionally send non-image local files to the external service if a wildcard or file path is used incorrectly.
Install only if you are comfortable sending the selected media to KIRI Engine. Use dedicated folders or explicit image-only wildcards, avoid broad wildcards, do not point the image option at mixed project folders, and treat the stored API key file as a secret. Review downloaded ZIP contents before using extracted files in another workflow.
scripts/kiri-engine.ps1:182Incomplete image-path validation can upload unintended files
scripts/kiri-engine.ps1:43API credential is stored in an unencrypted profile file without enforced restrictive permissions
The README advertises automatic download and extraction of ZIP assets to a user-specified directory but does not warn about local file creation, overwrite behavior, or archive extraction risks. In a skill that retrieves remote content from an external service, silent extraction can lead to unexpected filesystem changes and, depending on implementation, could expose users to overwrite or path traversal issues.
The documented workflow instructs users to upload local videos and image sets to a remote API, but the README does not clearly and prominently warn that potentially sensitive local media will leave the device and be processed by a third party. This can cause unintentional disclosure of private or regulated content, especially because the skill is centered around local media processing.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
## API 文档
- Base URL: `https://api.kiriengine.app/api/`
- 官方文档: https://gentlebandit.feishu.cn/wiki/PsHawWV0gi2jePkmRoycwMwXnIc
## License
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
## API 文档
- Base URL: `https://api.kiriengine.app/api/`
- 官方文档: https://gentlebandit.feishu.cn/wiki/PsHawWV0gi2jePkmRoycwMwXnIc
## License
This script is designed to transmit local videos, image sets, API credentials, and task identifiers to an external third-party service at api.kiriengine.app. In the context of an agent skill, that is a real data exfiltration surface because local user files are uploaded off-host and later a remote archive is downloaded and extracted, so compromise, misuse, or unexpected content from the service could affect confidentiality and downstream safety.
)
$ConfigPath = Join-Path $env:USERPROFILE '.kiri-engine-config.json'
$BaseUrl = 'https://api.kiriengine.app/api/v1/open'
# ── 读取 API Key ──────────────────────────────────────────
function Get-ApiKey {
The download workflow does more than fetch a model: it automatically extracts the downloaded ZIP into a directory and then deletes the original archive. While the code prints progress messages during execution, the top-level synopsis/description does not warn users that running the download action will write files, unpack content, and remove the ZIP, which is a material filesystem side effect.
The natural-language instructions and operational guidance are presented exclusively in Chinese. Under the language/locale policy, forcing a single language without opt-in or justification can be a policy issue because users are not offered a language choice.
The user-facing synopsis, description, and parameter help are entirely in Chinese, which effectively forces a specific language for interaction and documentation. There is no opt-in, alternate locale, or documented justification that this skill is intended only for a Chinese-language audience.
No suspicious patterns detected.