Back to skill

Security audit

Deepseek Api Guide

Security checks for vulnerabilities and agentic risk

Overview

This is a static DeepSeek API setup guide with expected external API examples, but users should handle API keys more carefully than the guide explains.

Before installing, understand that this guide is for using DeepSeek's API and may send prompts or account requests to DeepSeek when you follow its examples. Keep API keys in environment variables or a secrets manager, do not commit them to code, and rotate the key if it is exposed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (7)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide tells users to create and copy an API key but does not state that the key is a sensitive secret that must not be shared, logged, or committed to source control. In a setup guide, this omission can lead inexperienced users to expose credentials and enable unauthorized use of their paid API account.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

~/.openclaw/config.yaml

model: deepseek-chat api_key: ${DEEPSEEK_API_KEY} base_url: https://api.deepseek.com/v1

text

### Python

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

~/.openclaw/config.yaml

model: deepseek-chat api_key: ${DEEPSEEK_API_KEY} base_url: https://api.deepseek.com/v1

text

### Python

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 82)May include surrounding context.

~/.openclaw/config.yaml

model: deepseek-chat api_key: ${DEEPSEEK_API_KEY} base_url: https://api.deepseek.com/v1

text

### Python

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 162)May include surrounding context.

~/.openclaw/config.yaml

model: deepseek-chat api_key: ${DEEPSEEK_API_KEY} base_url: https://api.deepseek.com/v1

text

### Python

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The Python and Node.js examples hardcode an API key placeholder directly in source, which normalizes embedding secrets in code. Users often copy such patterns into real projects, increasing the chance of accidental credential leakage through version control, logs, or code sharing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Natural-language policy requires avoiding forced language or locale constraints unless users are given a choice or the restriction is clearly justified. This guide presents all instructions in Chinese and includes China-specific assumptions, but it does not state that it is a China/Chinese-only guide or offer alternatives.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.