T08 · Insecure Dependencies
- Location
references/install-guide.md:31- Finding
Volcengine CLI Is Downloaded and Installed Without Integrity Verification
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill matches its CDN-management purpose, but it needs review because it can make live cloud CDN changes and has unsafe CLI and credential-handling patterns.
Install only after reviewing the scripts and using least-privilege Volcengine credentials limited to the required CDN actions. Verify the Volcengine CLI source and checksum yourself, avoid putting AK/SK values in shell history or chat, prefer the interactive scripts with confirmation, and carefully review every domain, origin, refresh URL, and preload URL before running commands against production.
references/install-guide.md:31Volcengine CLI Is Downloaded and Installed Without Integrity Verification
references/install-guide.md:66Secret Keys Are Passed Through Command-Line Arguments
scripts/add-cdn-domain.sh:18Project-Local Executable Is Preferred Without Provenance Verification
scripts/submit-preload.sh:24User-Controlled Values Are Concatenated Into JSON Without Escaping
代码的主要行为是新增 CDN 域名,这与声明的一部分一致。但声明还包含两个重要能力:1)支持刷新/预热;2)必要时检查并安装 CLI。该代码片段中只看到对本地 ve 可执行文件存在性的检查,缺失安装逻辑;同时也没有任何刷新或预热相关 API 调用(如 URL/目录刷新或预热)。因此描述覆盖的能力范围明显大于实际代码行为,属于描述与行为不一致。
代码的核心行为是:检查 ve CLI 是否可执行、让用户选择预热或刷新、收集 URL、构造请求体并调用 ve cdn SubmitPreloadTask 或 ve cdn SubmitRefreshTask。这与声明中的“刷新预热”部分一致,但与“管理 CDN 域名、支持新增域名”不符,因为代码没有创建/添加域名相关调用。此外,声明说会在需要时检查并安装 CLI,而代码仅在 CLI 缺失时提示参考安装文档并退出,并不实际安装。因此描述未准确代表代码实际行为,属于明显不匹配。
代码片段只是定义了两个函数:一个输出不同业务类型的推荐 CDN 配置 JSON,另一个输出这些配置的说明文字。它没有调用火山引擎 CLI,也没有执行任何域名管理操作,没有新增域名、缓存刷新、预热、CLI 检查或安装等行为。该代码的实际用途更像是“生成 CDN 推荐配置模板”,与声明的“通过 CLI 管理 CDN 域名并支持刷新预热”存在明显主功能不匹配。
声明描述的是一个较完整的 CDN 域名管理能力集合,包括新增域名、刷新预热,以及必要时检查安装 CLI。实际提供的代码片段只是一个“提交刷新任务”的脚本:它构造 UrlList 和 Type 参数后调用 ve cdn SubmitRefreshTask。代码中没有新增域名相关调用,没有预热任务相关调用,也没有任何检查/安装 CLI 的逻辑,只有本地或系统 ve 可执行文件的选择。因此该代码片段的实际行为明显比声明更窄,且缺少声明中的关键能力,属于描述与行为不一致。
The skill clearly instructs users to run shell commands such as bash scripts/... and ve ..., but the manifest does not declare any tool scope or allowed tools. This creates an execution-scope ambiguity where an agent may invoke shell capabilities without explicit least-privilege boundaries, increasing the risk of unintended command execution or overly broad runtime permissions.
The skill instructs users to perform CDN refresh and preload operations without clearly warning that these actions immediately affect live traffic, cache state, origin load, and user-visible content delivery. In an agent-assisted context, omission of impact warnings can lead to accidental production disruption, excessive cache invalidation, or unintended high-load events against origin infrastructure.
The prerequisites tell users to configure AK/SK credentials but provide no guidance on secure handling, storage, redaction, or least-privilege use. In an agent setting, this omission increases the risk that users paste secrets into chat, store them insecurely in shell history or scripts, or use overprivileged credentials for state-changing CDN operations.
L004 将文档范围描述为“CDN 域名创建”的常见场景,但后续示例不仅创建域名,还包含私有对象存储源站鉴权配置,直接在请求体中设置 AccessKeyId 和 AccessKeySecret。相较于“创建域名”的表述,这属于额外的敏感能力展示,超出了仅创建域名这一自然语义范围。
The example shows AccessKeyId and AccessKeySecret embedded directly in a CLI payload for private object storage origin authentication, without any warning about secret handling. Users may copy this pattern into shell history, repos, logs, tickets, or shared terminals, causing credential leakage and unauthorized access to the backing storage or CDN-integrated resources.
This is a markdown file, so SQP-2 applies to user-facing documentation. The section shows ve cdn DeleteCdnDomain --Domain "www.example.com" as a direct deletion command, but does not warn that it removes an existing CDN domain configuration or advise the user to verify the target before running it.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
unzip -q ve.zip
mkdir -p ~/.local/bin
mv ve ~/.local/bin/
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
unzip -q ve.zip
mkdir -p ~/.local/bin
mv ve ~/.local/bin/
The guide tells users to pass the AccessKey and SecretKey directly as command-line arguments to ve configure set. Secrets supplied on the command line can be exposed via shell history, terminal logging, process listings, or audit tooling, which creates a realistic credential leakage risk for cloud accounts.
这是一个 markdown 文件,适用 SQP-2。L067-L068 明确要求填写 AccessKeyId 和 AccessKeySecret,但文档没有提醒用户这些字段属于敏感凭证、应避免泄露、记录或提交到不安全位置;该行为涉及隐私和系统完整性,应有基本警示。
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
echo ""
echo "3. 解压并安装:"
echo " unzip -q ve.zip"
echo " mkdir -p ~/.local/bin"
echo " mv ve ~/.local/bin/"
echo ""
echo "4. 配置环境变量(如果还没有配置):"
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
echo ""
echo "3. 解压并安装:"
echo " unzip -q ve.zip"
echo " mkdir -p ~/.local/bin"
echo " mv ve ~/.local/bin/"
echo ""
echo "4. 配置环境变量(如果还没有配置):"
The natural-language/config value sets "ServiceRegion": "chinese_mainland" unconditionally. This enforces a specific locale/region behavior with no visible user choice, which matches the policy category for language/locale-style regional constraints lacking opt-in or justification in the file.
The manifest description says the skill supports both adding CDN domains and performing refresh/preload operations. In this script, the only user-selectable actions are '提交预热任务' and '提交刷新任务', which call SubmitPreloadTask and SubmitRefreshTask respectively; there is no code path for creating or adding domains.
The comment and all user-facing usage/help output are written in Chinese, which imposes a specific language on users without any opt-in or explanation. This matches the policy category for language/locale violations because the script does not offer an alternative language or justify that it is intended only for a Chinese-speaking or region-specific audience.
The comments and echoed user-facing strings are entirely in Chinese, including usage guidance and operational warnings. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless the locale restriction is clearly justified, which this script does not do.
L004 明确说文档提供的是“CDN 域名创建”的常见场景,但后续多个场景包含缓存、压缩、页面优化、回源协议、回源 Host、Range、CacheKey、VideoDrag 以及私有桶鉴权等附加配置。这里并非单纯信息不全,而是文档对自身范围的表述与实际示例覆盖内容存在明显偏差。
SQP-3 适用于所有文件类型。该文档全文以中文固定呈现,未说明这是面向特定中文区域用户的受限文档,也未提供语言选择或用户自选机制,可能构成语言/locale 策略上的强制单一语言。
The script's comments and usage/help text are written in Chinese, including the only user-facing guidance shown on incorrect invocation. This imposes a specific language on users without any opt-in or indication that the skill is intentionally limited to a Chinese-speaking or region-specific audience.
No suspicious patterns detected.