T09 · Insecure Skill Coding Practices
- Location
generate.py:429- Finding
API Credentials and User Data Can Be Sent to Arbitrary or Plaintext Endpoints
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent image-generation tool, but it needs Review because it can send API keys and user images to arbitrary or unencrypted endpoints.
Install only if you trust usa0.top and the publisher. Use a dedicated, revocable, quota-limited API key, avoid --base-url unless you fully trust the destination, do not use HTTP endpoints, and do not provide sensitive local files or private-network image URLs. Windows users should know the key is saved persistently as their user USA_API_KEY environment variable.
generate.py:429API Credentials and User Data Can Be Sent to Arbitrary or Plaintext Endpoints
generate.py:480Unrestricted Image URL Fetching Enables Server-Side Request Forgery
generate.py:3Automatically Installed Dependencies Are Not Reproducibly Pinned
The skill instructs the agent to access environment variables, read and write files, install or repair tooling, invoke local scripts, and make network requests, but it does not declare any explicit tool scope or permissions. This creates a capability/consent mismatch: a host may expose broader powers than users realize, and the skill’s behavior includes sensitive actions such as handling API-key setup and sending prompts/images to a third-party service.
This code file contains natural-language strings in Chinese for errors, help text, prompts, and status output, and does not provide any user opt-in or alternative locale. Under the policy rule, forcing a specific language without choice is a natural-language policy violation.
The script sends prompts, optional input images, and the Authorization bearer token to a remote service, and it also permits overriding --base-url to any HTTP/HTTPS endpoint. In the skill context, this is dangerous because users may be prompted to enter and persist a third-party API key and then unknowingly transmit that credential and their image data to an arbitrary server if the base URL is changed or the provider is untrusted/compromised.
response = requests.post(url, data=form_fields, files=files, headers=headers, timeout=(30, 300))
else:
url = f"{args.base_url}/v1/images/generations"
response = requests.post(url, json=common_fields, headers=headers, timeout=(30, 300))
response.raise_for_status()
except ImageGenerationError:
raise
Detected: suspicious.exposed_secret_literal