T09 · Insecure Skill Coding Practices
- Location
scripts/generate.py:52- Finding
Unrestricted and Unbounded Download from an API-Controlled URL
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears to generate images as advertised, but it needs review because it automatically downloads external content to a hard-coded local path with weak safeguards.
Install only if you are comfortable sending prompts and API-key-authenticated requests to Volcengine. Review or change the script before use so downloads have timeouts, size and content checks, validated image hosts, and a user-chosen output directory instead of the hard-coded C:/Users/zcf path. Do not include secrets, private data, or regulated content in prompts.
scripts/generate.py:52Unrestricted and Unbounded Download from an API-Controlled URL
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
print(f"正在生成: {prompt}")
print(f"模型: {model}, 尺寸: {size}")
response = requests.post(API_BASE_URL, headers=headers, json=payload)
if response.status_code != 200:
print(f"错误: {response.status_code}")
The skill appears to use environment variables and network access, but the manifest does not declare any tool scope such as permissions or allowed-tools. This weakens transparency and policy enforcement, making it easier for a skill to access secrets and exfiltrate user-provided content to an external service without clear user-facing declaration.
The invocation example and description are broad enough that normal conversational text about generating an image could trigger the skill without clear boundaries. Over-broad triggers can cause unintended activation, sending user prompts to a third-party API and producing side effects such as API usage costs and local file creation.
The skill documentation describes image generation but does not clearly warn that prompts are transmitted to an external image-generation API. Users may unknowingly send sensitive or regulated data off-platform, creating privacy, confidentiality, and compliance risk.
This file contains natural-language descriptions, help text, and runtime messages exclusively in Chinese, including the module docstring and CLI-facing strings. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
print(f"正在生成: {prompt}")
print(f"模型: {model}, 尺寸: {size}")
response = requests.post(API_BASE_URL, headers=headers, json=payload)
if response.status_code != 200:
print(f"错误: {response.status_code}")
The skill description says it generates images via an API, but the code also automatically downloads remote content and writes it locally without making that side effect explicit to the user. This expands the trust boundary from API interaction to filesystem modification and remote content retrieval, which can surprise users and create unnecessary local persistence of untrusted data.
Writing files to a hard-coded user-specific path is unsafe because it assumes a particular host layout and silently persists data outside the caller's chosen workspace. In agent or shared environments, this can cause unintended data placement, privacy issues, or overwrite/conflict risks, especially since the downloaded file originates from a remote URL.
Although the output section mentions saving images to downloads/images, the skill description does not prominently warn that generated files are automatically written to local storage. This can surprise users, create data residue on disk, and expose generated content to other local users or processes.
No suspicious patterns detected.