Back to skill

Security audit

Seedream 图片生成

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Seedream image-generation API helper, with ordinary API-key and third-party data-sharing cautions but no hidden or destructive behavior in the inspected artifact.

Use this only with a Volcengine Ark key you are comfortable using for image generation. Prefer ARK_API_KEY or a managed secret over the --api-key command option, and do not send confidential prompts, private images, regulated data, or secrets to the external service unless you have reviewed the provider's data handling terms.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:39
Finding

API Key Exposure Through Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 39–42
Vulnerability Type: Sensitive credential exposure through process arguments and shell history
Risk Level: Medium

Vulnerable Code

bash
or pass it in the command:
```bash
python3 {baseDir}/scripts/seedream.py --api-key "your-api-key" ...
text

### Technical Analysis

The documentation recommends supplying the `ARK_API_KEY` directly through the `--api-key` command-line option. Secrets passed as command-line arguments can be recorded in shell history, terminal-session logs, process-monitoring systems, diagnostic reports, and automation logs. Depending on operating-system configuration, process arguments may also be visible to other local users or processes while the command is running.

Although the referenced `scripts/seedream.py` implementation is absent and its internal credential handling cannot be verified, the documented invocation itself creates a credential-exposure risk.

### Attack Path

1. A user follows the documented example and supplies a valid API key using `--api-key`.
2. The complete command is retained in shell history, captured by logging or monitoring software, or temporarily exposed through process metadata.
3. A local attacker, compromised process, support operator, or user with access to collected logs retrieves the key.
4. The attacker reuses the credential against services accessible under the key.

### Impact Assessment

Successful exploitation exposes the privileges associated with the compromised API key. An attacker could consume the victim's service quota, incur charges, invoke authorized API operations, or access other resources available to that credential. The exact scope depends on the server-side permissions assigned to the key; no evidence establishes broader local-system privileges.
Remediation
View remediation

Remediation Suggestions

  1. Remove the command-line API-key example and discourage passing secrets in process arguments.
  2. Require the existing ARK_API_KEY environment variable or use a credential file with restrictive filesystem permissions.
  3. If command-line compatibility must be retained, deprecate --api-key, emit a warning, and ensure the value is never written to logs or error output.
  4. Prefer an operating-system secret store or managed credential provider for long-lived credentials.
  5. Document key rotation and revocation procedures for users who may previously have exposed keys through command history.
  6. Recommend short-lived, least-privilege credentials and ensure generated keys are scoped only to required Seedream operations.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation encourages users to provide prompts, image inputs, and optional web-search queries to a third-party image generation API, but it does not clearly disclose that this data leaves the local environment and is transmitted to an external service. This can lead users to unintentionally send sensitive text, proprietary images, or privacy-sensitive search-derived content to a remote provider under assumptions of local-only processing.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.