T09 · Insecure Skill Coding Practices
- Location
scripts/img2img.py:18- Finding
Generic API Key Fallback May Disclose an Unrelated Credential
- Content
View full analysis
Vulnerability Details
File Location:
scripts/img2img.py, lines 18–21 and 72–76
Vulnerability Type: Improper credential selection and unintended secret disclosure
Risk Level: MediumVulnerable Code
python for name in ('SILICONFLOW_API_KEY', 'API_KEY'): v = os.environ.get(name) if v: return vpython headers = { 'Authorization': f'Bearer {load_key()}', 'Content-Type': 'application/json', } resp = requests.post(API_URL, headers=headers, json=payload, timeout=180)The same credential-selection flaw also appears in
scripts/txt2img.py, lines 17–20 and 55–59.Technical Analysis
The script first looks for the provider-specific
SILICONFLOW_API_KEYenvironment variable, but it then falls back to the genericAPI_KEYvariable. A generic variable does not establish that the credential belongs to SiliconFlow. It may contain a token for an unrelated provider or internal service.When
SILICONFLOW_API_KEYis absent andAPI_KEYis present, the script automatically places that value in an HTTPAuthorizationheader and transmits it to the fixed SiliconFlow endpoint:text https://api.siliconflow.cn/v1/images/generationsThis violates least-privilege and explicit-secret-selection principles. The scripts should only access credentials specifically designated for their declared service. HTTPS protects the credential in transit but does not prevent disclosure to the unintended recipient.
The Base64 handling in
scripts/img2img.pyis not itself a vulnerability. It serializes an explicitly selected reference image into a data URL for the documented image-to-image API request.Attack Path
- An Agent, automation environment, or user session exposes an unrelated credential through the generic
API_KEYenvironment variable. - The provider-specific
SILICONFLOW_API_KEYvariable is not set. - The user or Agent invokes
scripts/img2img.pywith a prompt and reference image. load_key()sel ...[truncated 859 chars]
- An Agent, automation environment, or user session exposes an unrelated credential through the generic
- Remediation
View remediation
Remediation Suggestions
- Remove the generic
API_KEYfallback from both scripts:
python key = os.environ.get('SILICONFLOW_API_KEY') if key: return key-
Accept only credentials explicitly associated with SiliconFlow, such as
SILICONFLOW_API_KEYor a validatedsiliconflow.apiKeyconfiguration entry. -
Fail closed with a clear error when the provider-specific credential is unavailable rather than guessing that another secret is compatible.
-
Avoid sourcing credentials from unrelated configuration sections. In particular, do not reuse a memory-search credential solely because its base URL contains a provider domain; use a dedicated image-generation credential entry.
-
Update both scripts consistently and add tests confirming that:
SILICONFLOW_API_KEYis accepted.- A standalone generic
API_KEYis rejected. - Missing provider-specific credentials terminate execution before any network request.
- Credentials are never printed in normal output or error messages.
- Remove the generic
