T09 · Insecure Skill Coding Practices
- Location
promo-video-maker/scripts/hub-api.sh:8- Finding
Bearer Credential Can Be Disclosed to an Untrusted Configurable API Origin
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The hub is mostly coherent, but one routed video skill provisions and stores cloud credentials and can send them to a configurable API origin without enough user-facing scoping or controls.
Review this skill before installing if you plan to use the promo-video workflow. It may create cloud project state, generate workspace links, and store a reusable API key on disk. Only use trusted environment settings for the Maliang/Nano base URL, and avoid running the helper scripts in shells or wrappers that can set untrusted `PROMO_VIDEO_MAKER_BASE_URL` or `MALIANG_HUB_BASE_URL` values.
promo-video-maker/scripts/hub-api.sh:8Bearer Credential Can Be Disclosed to an Untrusted Configurable API Origin
promo-video-maker/scripts/bootstrap.sh:7Automatic Provisioning Discloses the Local Machine Hostname
The declared description says this skill is a general front door/router for multiple public skills. The supplied code does not perform routing, user dispatch, or selection among presentation/social/promotional skills. Instead, it is a concrete bootstrap/provisioning script for one specific skill: promo video maker. It contacts an external backend, sends the machine hostname, receives an API key and short code, writes those secrets to disk, and prints service configuration details. Those are materially different behaviors and capabilities from the declared purpose, especially credential provisioning and local secret persistence, which are undeclared. Therefore this is a clear description-behavior mismatch.
The declared purpose describes a routing/front-door skill that directs users to other skills for various tasks. The supplied code instead implements a utility that reads a local file and converts its contents to base64. This is a materially different primary purpose and introduces file-access behavior that is not reflected in the description. While such encoding might be a supporting detail inside a promo-video workflow, this chunk by itself does not behave like a router/front door, so the description does not accurately represent the code.
The declared description says this skill acts as a user-facing routing/front-door layer that sends users to the right skill for certain task categories. The supplied code does not implement routing logic or selection among presentation/social/video skills. Instead, it is a generic API client wrapper for a promo-video-maker component: it bootstraps, reads an API key from a config directory, and sends arbitrary authenticated HTTP requests to a configured base URL. Reading local secrets and invoking arbitrary backend paths are undeclared capabilities materially different from the declared front-door routing purpose. While this could be a supporting utility for some larger system, this code chunk itself does not match the stated primary behavior.
The declared description says this skill is a high-level routing/front-door capability that helps users get sent to the correct skill without exposing implementation details. The supplied code does not perform routing, skill selection, or user-facing orchestration. Instead, it implements a concrete backend utility for promotional media processing: repeatedly querying /api/v1/hub/tasks/{kind}/{task_id} to monitor an image or video task until completion, failure, or timeout. That is a materially different primary purpose from the declared front-door router, so this is a description/behavior mismatch.
The declared purpose describes an orchestration/router skill that helps users reach the correct skill for presentations, social operations, or promo video production. The supplied code instead implements a narrow helper script that posts a request body to a quote endpoint. That is a materially different primary behavior from user routing/orchestration. While it may be a supporting component within a larger system, this code chunk itself exposes an undeclared capability—requesting quote data from an API—and does not reflect the described front-door routing behavior.
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
if [[ ! -f "$KEY_FILE" || ! -s "$KEY_FILE" ]]; then
MACHINE_ID="$(hostname)"
CURL_OPTS=(--http1.1 -sS)
PROVISION_RESULT="$(curl "${CURL_OPTS[@]}" -X POST "$BASE_URL/api/v1/provision" \
-H "Content-Type: application/json" \
-d "{\"machine_id\":\"$MACHINE_ID\"}")"
Without declared permissions the skill's intent is opaque and cannot be validated.
The hub uses broad activation phrasing such as being the public 'front door' for users who do not know which skill to call, plus expansive example requests. In an agent environment, overly broad invocation criteria can cause this router to intercept many unrelated requests and steer users into downstream skills without adequate intent disambiguation, increasing the chance of unintended actions or data exposure across skill boundaries.
All example user requests and the ambiguity-resolution question are written in Chinese, which implies a default language behavior for user-facing interaction. There is no statement that the user may choose another language or that the skill is intentionally limited to a Chinese-speaking context.
The skill description is broad enough to capture many presentation-related requests without defining exclusion conditions or precedence rules. In a multi-skill environment, this can cause over-routing, unintended activation, and inappropriate handling of user tasks by this skill when a narrower or safer skill should have been selected.
The natural-language trigger examples are highly permissive and include vague user phrases like 'help me make a PPT' or 'I don't know how to start,' which can match ordinary brainstorming, summarization, or document-organization requests. That increases the chance of this skill activating too early and taking control before the user's actual need is disambiguated.
This markdown file presents its guidance almost entirely in Chinese, with no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
Everything else should default to internal team judgment unless the user explicitly asked to review intermediate work.
## Do Not Ask the User to Decide
- card layout vs split layout
- palette tuning inside an already-fit style
This markdown file contains natural-language guidance entirely in Chinese, beginning with a direct instruction at L003, with no indication that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy concern.
Line L03 states the architecture guidance in Chinese and uses directive language without any indication that language selection is optional. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation unless clearly justified as region-specific.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
- handing off either final outputs or a web project workspace
Do not split this into multiple public skills.
Do not ask the user to choose internal roles.
## Front-Door Rule
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
- handing off either final outputs or a web project workspace
Do not split this into multiple public skills.
Do not ask the user to choose internal roles.
## Front-Door Rule
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
- handing off either final outputs or a web project workspace
Do not split this into multiple public skills.
Do not ask the user to choose internal roles.
## Front-Door Rule
The trigger list is broad and includes generic phrases like 'promo video', 'teaser', 'explainer', and '帮我做一个视频', which can cause the skill to capture requests that may belong to other workflows or require additional consent before routing into a production pipeline. In this skill, unintended invocation is more dangerous because downstream behavior includes quoting, project selection/creation, cloud persistence, workspace link generation, and helper-script/API execution, so misrouting can expose user data or start paid operations under the wrong context.
The project-mode intake and rules require persisted cloud project state and workspace access, but the public skill text does not clearly warn users that their materials, outputs, and metadata may be stored remotely and made accessible through a web workspace. This creates a consent and privacy gap, especially for creative briefs or source materials that may contain sensitive business or personal content.
The skill states that helper scripts and Hub execution reuse the same cloud account and API key flow, but it does not clearly disclose this operational boundary or associated risks to users. If the skill is invoked unexpectedly or with untrusted inputs, this shared credential model can lead to unintended API actions, billing exposure, or broader account impact because transport scripts execute under the product's cloud identity.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
## What it should not do
- hide all intermediate stages in a black box
- create duplicate projects without checking
- pretend rough generated assets are a finished episode
## Suggested phase targets
The routing rule hard-codes a clarification question in Chinese without checking the user's language or offering localization. This can confuse users, degrade informed consent around workflow selection, and create a poor or exclusionary experience, especially when the surrounding interaction is otherwise in another language.
The script persists an API key and short code under a user config directory without clearly justifying why a routing hub needs durable service credentials. Persistent local secrets increase exposure to local compromise, accidental reuse, and confusion about what authority the hub now has on behalf of the user.
The bootstrap script goes beyond a routing-only hub role by contacting a remote provisioning service, obtaining credentials, and persisting them locally. That creates an undisclosed trust boundary and expands the blast radius: running the skill causes account/bootstrap state to be created on an external service and leaves usable credentials on disk.
No suspicious patterns detected.