T09 · Insecure Skill Coding Practices
- Location
scripts/imagegen.py:358- Finding
Path Traversal Through Untrusted Task Metadata During Result Download
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a disclosed AI image-generation helper, but its result download code can let remote task metadata write files outside the chosen output folder.
Review this before installing. Use it only with a trusted AI Hive account and authorized reference images, prefer a dedicated output directory, avoid sensitive working directories, and consider fixing filename sanitization before routine use. Store the API key only if you are comfortable with a local config file at `~/.ai-hive/config.json`.
scripts/imagegen.py:358Path Traversal Through Untrusted Task Metadata During Result Download
SKILL.md:70Unpinned Third-Party Dependency Installation
The skill invokes a local Python script that performs network access, file reads/writes, environment usage, and shell execution, but the manifest does not declare any tool scope or permissions boundaries. This weakens least-privilege guarantees and makes it easier for an agent runtime or reviewer to underestimate the skill's capabilities, increasing the chance of unintended file access, outbound requests, or credential handling.
The skill’s natural-language description, headings, instructions, and examples are entirely in Chinese, which effectively imposes a specific language on users. The file does not indicate that Chinese is optional, nor does it offer an alternative locale or language choice.
This markdown file contains user-facing natural-language content only in Chinese, which can constitute a language/locale policy violation if users are not given an opt-in or alternative language. Nothing in the file indicates that the skill is region-specific or that language selection is optional.
The sample API key placeholder uses Chinese text ('请替换为你的APIKey'), which imposes a specific language in user-facing configuration content. The file does not offer a language choice or explain that the skill is intentionally region- or locale-specific.
No suspicious patterns detected.