T09 · Insecure Skill Coding Practices
- Location
scripts/enhance_prompt.sh:57- Finding
Arbitrary Python Code Execution Through Unquoted Heredoc Input Interpolation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill's video-generation purpose is coherent, but it ships unsafe credential handling and a shell helper vulnerability that can expose secrets or execute injected code.
Review this carefully before installing. Use your own Kameo key, treat the documented kam_ value as exposed, avoid the registration helper as written, and do not pass real passwords on the command line. Do not run the enhanced prompt helper on untrusted filenames or dialogue until the heredoc interpolation is fixed. Only upload portraits when you have consent and are comfortable sending the image and prompt to Kameo and, for enhanced prompts, Google Gemini.
scripts/enhance_prompt.sh:57Arbitrary Python Code Execution Through Unquoted Heredoc Input Interpolation
SKILL.md:27API Credential-Like Secret Embedded Repeatedly in Documentation
scripts/register.sh:7Account Password Accepted as a Command-Line Argument
The documentation goes beyond content generation into registration, login, API-key creation, and local credential storage. Those account lifecycle operations are materially different from the declared purpose and increase the chance of collecting secrets or performing sensitive actions users did not intend.
The documentation goes beyond content generation into registration, login, API-key creation, and local credential storage. Those account lifecycle operations are materially different from the declared purpose and increase the chance of collecting secrets or performing sensitive actions users did not intend.
The documentation goes beyond content generation into registration, login, API-key creation, and local credential storage. Those account lifecycle operations are materially different from the declared purpose and increase the chance of collecting secrets or performing sensitive actions users did not intend.
The documentation contains what appears to be a live Kameo API key in plaintext and instructs users to store it in a local credentials file. Exposed API keys can be abused by anyone who sees the repository or logs, leading to unauthorized account use, credit consumption, and possible access to associated service data.
export KAMEO_API_KEY="kam_I3rdx43IymFNbfBw1c0ZbSc7o3aUfQgz8cljZA6T7fs"
Or store in `~/.config/kameo/credentials.json`:
```json
{
"api_key": "kam_I3rdx43IymFNbfBw1c0ZbSc7o3aUfQgz8cljZA6T7fs"
The usage guide embeds what appears to be a real API key and instructs users to export or store it in plaintext without any warning about secret handling. Exposed credentials can be reused by anyone with access to the repository or logs, enabling unauthorized API usage, billing abuse, and possible account compromise.
The documentation instructs users to place an API key in a plaintext credentials file under the home directory. Plaintext long-lived secrets are easily exposed through backups, local compromise, shell history, support bundles, or accidental repository inclusion.
# 或保存到配置文件
mkdir -p ~/.config/kameo
cat > ~/.config/kameo/credentials.json << EOF
{
"api_key": "kam_I3rdx43IymFNbfBw1c0ZbSc7o3aUfQgz8cljZA6T7fs"
}
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Check Kameo credit balance
API_KEY="${KAMEO_API_KEY:-}"
if [ -z "$API_KEY" ] && [ -f ~/.config/kameo/credentials.json ]; then
API_KEY=$(jq -r '.api_key' ~/.config/kameo/credentials.json)
fi
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Check Kameo credit balance
API_KEY="${KAMEO_API_KEY:-}"
if [ -z "$API_KEY" ] && [ -f ~/.config/kameo/credentials.json ]; then
API_KEY=$(jq -r '.api_key' ~/.config/kameo/credentials.json)
fi
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Check Kameo credit balance
API_KEY="${KAMEO_API_KEY:-}"
if [ -z "$API_KEY" ] && [ -f ~/.config/kameo/credentials.json ]; then
API_KEY=$(jq -r '.api_key' ~/.config/kameo/credentials.json)
fi
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Check Kameo credit balance
API_KEY="${KAMEO_API_KEY:-}"
if [ -z "$API_KEY" ] && [ -f ~/.config/kameo/credentials.json ]; then
API_KEY=$(jq -r '.api_key' ~/.config/kameo/credentials.json)
fi
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Check Kameo credit balance
API_KEY="${KAMEO_API_KEY:-}"
if [ -z "$API_KEY" ] && [ -f ~/.config/kameo/credentials.json ]; then
API_KEY=$(jq -r '.api_key' ~/.config/kameo/credentials.json)
fi
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Check Kameo credit balance
API_KEY="${KAMEO_API_KEY:-}"
if [ -z "$API_KEY" ] && [ -f ~/.config/kameo/credentials.json ]; then
API_KEY=$(jq -r '.api_key' ~/.config/kameo/credentials.json)
fi
The script writes a reusable API key in plaintext to a predictable file path under the user's home directory. Even with mode 600, plaintext credential storage can be harvested by malware running as the user, exposed through insecure backups, or inadvertently disclosed during support/debugging.
# Save to config
mkdir -p ~/.config/kameo
cat > ~/.config/kameo/credentials.json << EOF
{
"api_key": "$KAMEO_KEY",
"email": "$EMAIL"
The credentials file is explicitly persisted and retained for later use, creating an ongoing target for local compromise. The file path is disclosed to the user, which is transparent, but the underlying risk remains because a long-lived API secret is stored on disk.
"email": "$EMAIL"
}
EOF
chmod 600 ~/.config/kameo/credentials.json
echo "✅ Saved to ~/.config/kameo/credentials.json"
echo ""
The script instructs the user to export the API key into the current shell session, which can increase exposure through shell history, environment inspection by same-user processes, or accidental leakage into child processes. While common in CLI tooling, it still handles a live credential in a comparatively weak way.
EOF
chmod 600 ~/.config/kameo/credentials.json
echo "✅ Saved to ~/.config/kameo/credentials.json"
echo ""
echo "Export for current session:"
echo " export KAMEO_API_KEY='$KAMEO_KEY'"
The skill documentation describes capabilities that require shell, network, and environment-variable access, but it does not declare an explicit tool/permission scope. That omission weakens reviewability and can cause the skill to be executed with broader access than users expect, especially since it also references local credential files and outbound API calls.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
---
name: kameo
description: Generate expressive talking-head videos from static images using Kameo AI. Converts static avatars/portraits into dynamic 5-second videos with realistic facial expressions, lip-sync, and motion. Use when you need to bring static images to life, create AI character videos, demonstrate visual communication, or generate talking avatars from photos.
---
# Kameo AI - Talking Head Video Generation
The documentation explains how to upload images and prompts to Kameo but does not clearly warn users that their media and text are transmitted to an external API and resulting videos are hosted on a CDN. Users may unknowingly send sensitive faces, prompts, or personal content to third-party infrastructure.
Including a registration helper in a generation skill expands the operational scope into account creation and key provisioning. That can normalize handling user credentials and sensitive setup steps in a context where users expect only media generation.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl -X POST https://api.kameo.chat/api/public/generate \
-H "X-API-Key: kam_I3rdx43IymFNbfBw1c0ZbSc7o3aUfQgz8cljZA6T7fs" \
-H "Content-Type: application/json" \
-d '{
The skill encourages persistent storage of an API key in ~/.config/kameo/credentials.json, increasing the lifetime and exposure window of the secret beyond a single session. Persistent secrets raise the risk of unauthorized reuse after host compromise, backup leakage, or accidental disclosure.
export KAMEO_API_KEY="kam_I3rdx43IymFNbfBw1c0ZbSc7o3aUfQgz8cljZA6T7fs"
# 或保存到配置文件
mkdir -p ~/.config/kameo
cat > ~/.config/kameo/credentials.json << EOF
{
"api_key": "kam_I3rdx43IymFNbfBw1c0ZbSc7o3aUfQgz8cljZA6T7fs"
The manifest describes a skill for generating talking-head videos from static images using Kameo AI. The usage documentation also instructs users to register an account and automatically create API keys, which is an account-management/onboarding capability not stated as part of the skill's purpose.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# 配置信息(无需认证)
curl https://api.kameo.chat/api/public/config
# 价格信息(无需认证)
curl https://api.kameo.chat/api/public/pricing
This example includes a concrete API key directly in the authenticated curl command, turning otherwise expected external transmission into credential disclosure. Anyone reading the file can reuse the token to make authenticated API calls, incur charges, or access associated account resources.
curl -H "X-API-Key: kam_..." https://api.kameo.chat/api/public/credits
# 生成视频
curl -X POST https://api.kameo.chat/api/public/generate \
-H "X-API-Key: kam_I3rdx43IymFNbfBw1c0ZbSc7o3aUfQgz8cljZA6T7fs" \
-H "Content-Type: application/json" \
-d @request.json
The package description promotes generating talking-head videos from static images but provides no warning about consent, impersonation, or privacy risks. In a skill that operates on user-provided portraits and can create realistic facial motion and lip-sync, omission of these safeguards can enable deceptive or non-consensual use and mislead downstream users or agents about the sensitivity of the capability.
Detected: suspicious.exposed_secret_literal, suspicious.potential_exfiltration