T09 · Insecure Skill Coding Practices
- Location
SKILL.md:33- Finding
Mandatory Authentication Check Exposes Cloud Credentials
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This image-beauty skill performs plausible remote image processing, but its credential handling and input processing are risky enough to require careful review before installation.
Install only if you are comfortable sending images to the remote Volcengine/Kickart service and can provide tightly scoped, disposable credentials through a safe secret mechanism. Do not paste long-lived AK/SK secrets into chat, do not run the credential-echo preflight as written, and avoid untrusted image URLs or archives until URL allowlisting, size limits, log redaction, and safe archive extraction are added.
SKILL.md:33Mandatory Authentication Check Exposes Cloud Credentials
scripts/core/api/iccp/client.py:105HTTP Request Logging Records Authorization Credentials
scripts/beauty.py:454Arbitrary Image URL Fetching Enables SSRF and Resource Exhaustion
scripts/beauty.py:395TAR Link Entries Can Cause Unauthorized External File Upload
The skill advertises beauty-enhancement triggers, but the observed behavior includes combo/package registration and query operations unrelated to photo processing. Bundling account/subscription workflows into a beautification skill can trick users into authorizing non-obvious service interactions and data sharing.
The skill advertises beauty-enhancement triggers, but the observed behavior includes combo/package registration and query operations unrelated to photo processing. Bundling account/subscription workflows into a beautification skill can trick users into authorizing non-obvious service interactions and data sharing.
The skill advertises beauty-enhancement triggers, but the observed behavior includes combo/package registration and query operations unrelated to photo processing. Bundling account/subscription workflows into a beautification skill can trick users into authorizing non-obvious service interactions and data sharing.
The skill advertises beauty-enhancement triggers, but the observed behavior includes combo/package registration and query operations unrelated to photo processing. Bundling account/subscription workflows into a beautification skill can trick users into authorizing non-obvious service interactions and data sharing.
The skill advertises beauty-enhancement triggers, but the observed behavior includes combo/package registration and query operations unrelated to photo processing. Bundling account/subscription workflows into a beautification skill can trick users into authorizing non-obvious service interactions and data sharing.
The skill advertises beauty-enhancement triggers, but the observed behavior includes combo/package registration and query operations unrelated to photo processing. Bundling account/subscription workflows into a beautification skill can trick users into authorizing non-obvious service interactions and data sharing.
The skill advertises beauty-enhancement triggers, but the observed behavior includes combo/package registration and query operations unrelated to photo processing. Bundling account/subscription workflows into a beautification skill can trick users into authorizing non-obvious service interactions and data sharing.
The skill advertises beauty-enhancement triggers, but the observed behavior includes combo/package registration and query operations unrelated to photo processing. Bundling account/subscription workflows into a beautification skill can trick users into authorizing non-obvious service interactions and data sharing.
The skill advertises beauty-enhancement triggers, but the observed behavior includes combo/package registration and query operations unrelated to photo processing. Bundling account/subscription workflows into a beautification skill can trick users into authorizing non-obvious service interactions and data sharing.
The skill advertises beauty-enhancement triggers, but the observed behavior includes combo/package registration and query operations unrelated to photo processing. Bundling account/subscription workflows into a beautification skill can trick users into authorizing non-obvious service interactions and data sharing.
The skill advertises beauty-enhancement triggers, but the observed behavior includes combo/package registration and query operations unrelated to photo processing. Bundling account/subscription workflows into a beautification skill can trick users into authorizing non-obvious service interactions and data sharing.
The skill advertises beauty-enhancement triggers, but the observed behavior includes combo/package registration and query operations unrelated to photo processing. Bundling account/subscription workflows into a beautification skill can trick users into authorizing non-obvious service interactions and data sharing.
The skill explicitly instructs the agent to ask users to paste ACCESS_KEY_ID and SECRET_ACCESS_KEY directly into chat and then export them for later use. Soliciting cloud credentials in chat is a severe secret-handling anti-pattern that can expose long-lived account access, enable account takeover or resource abuse, and bypass safer delegated-auth flows.
The skill directs the agent to have users paste access credentials into chat and reuse them for subsequent commands, creating direct exposure of secrets in conversational logs and downstream tooling. In the context of a consumer-facing image beautification skill, requesting cloud account keys is especially unjustified and highly suspicious, making credential theft or accidental leakage much more severe.
Referenced artifact was not completely inspected
python3.12 -m pip install -r ./scripts/requirements.txt
The V1 client logs the full headers and request body before making the outbound call, which includes the Authorization signature and potentially sensitive image-processing request content. Logs are often widely accessible in operational environments, so this creates a direct credential and data exposure path without needing to compromise the application itself.
The V2 client logs the Bearer token in the Authorization header together with the request body before sending the request. Exposure of a bearer token is especially dangerous because possession alone is sufficient for reuse against the target API until the token expires or is revoked.
The code calls IAM ListUsers and selects an admin user ID, then uses owner identities for media operations. For an image beautification skill, enumerating tenant users and implicitly acting under an admin account is unnecessary privilege expansion and can enable unauthorized access to or association with higher-privileged resources if the API credentials permit it.
The manifest says this skill analyzes user-provided images and performs intelligent beauty enhancement, outputting beautified images. This file instead validates arbitrary media, uploads files to a remote material system, and stores metadata in CSV records; there is no image beautification, portrait enhancement, or transformed-image output logic here.
The code’s actual behavior is unrelated to the declared image beautification skill: it instantiates a service and calls a remote registration endpoint for an 'Ark Claw' package. This mismatch is dangerous because users or downstream systems may invoke the skill expecting local image processing, while it instead performs an undisclosed account/service registration action over the network.
The skill declares executable behaviors that involve environment-variable access, filesystem reads/writes, and network activity, but it does not declare any explicit tool scope or allowed-tools boundary. This weakens sandboxing and review because the agent may exercise broader capabilities than users would reasonably expect from an image beautification skill.
The trigger phrases are broad beauty-related terms likely to appear in ordinary conversation, which raises the likelihood of over-triggering the skill on unintended requests. In context, over-triggering is more dangerous because the skill also invokes networked processing and credential-dependent workflows beyond simple local formatting.
The command set includes a subscription/package query command unrelated to the declared beautification purpose. While not necessarily malicious by itself, it broadens the skill's operational scope into account/service management without clear disclosure, increasing the chance of unintended data access and user confusion.
The skill processes local image paths, URLs, and archives and may transmit them to remote services, but the description does not clearly warn users about external transfer, archive handling, or privacy implications. This undermines informed consent, especially for personal portrait images that may contain sensitive biometric or identifying information.
The file prescribes fixed Chinese response templates and examples for all returned user messages, but does not provide user opt-in for language selection or explain a legitimate region-specific constraint. This can violate language/locale policy when a skill forces one language by default regardless of user preference.
No suspicious patterns detected.