T09 · Insecure Skill Coding Practices
- Location
scripts/types.mjs:250- Finding
Arbitrary Local File Disclosure Through Unvalidated Image Inputs
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This appears to be a real Baidu vision client, but it can upload any local file path it is given to Baidu and lacks clear file-scope safeguards.
Install only if you are comfortable sending selected local images, video frames, prompts, and workspace skill metadata to Baidu Yijian using your API key. Avoid letting untrusted prompts choose file paths, and prefer running it in a constrained workspace until file validation, upload confirmation, and pinned dependencies are added.
scripts/types.mjs:250Arbitrary Local File Disclosure Through Unvalidated Image Inputs
package.json:23Mutable Git Branch Dependency Without a Committed Lockfile
The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
export function getApiKey() {
const key = process.env.YIJIAN_API_KEY;
if (!key) {
throw new Error('YIJIAN_API_KEY environment variable is not set. Please configure it in ~/.claude/settings.json under "env".');
}
return key;
}
The primary heading and the rest of the operational documentation are presented in Chinese, and the examples/instructions assume Chinese-language interaction. There is no statement offering users a language choice or documenting a justified locale restriction, which can violate language/locale policy requirements.
This markdown file uses only Chinese for all instructions and examples, which can amount to a language/locale policy violation when no user opt-in or alternative language is provided. The document does not indicate that the skill is region-specific or that users may choose another language.
On failure of public skills, the code enumerates private workspace skills and returns their IDs, names, and descriptions. This broadens the skill from image/video analysis into internal capability discovery and may leak metadata about private tools to any caller who can trigger this path.
The user-facing hint string is written only in Chinese, which imposes a specific language choice on downstream users or agents regardless of their locale. This is a natural-language policy issue because the file provides no opt-in, language selection, or justification for restricting the message to Chinese.
If no matching specialized vision skill succeeds, the router silently falls back to a generic multimodal model, expanding behavior beyond the advertised Yijian vision scope. This can bypass capability boundaries, produce lower-assurance outputs for safety-critical use cases, and send sensitive image/task data to a broader backend than the caller expected.
This code sends user-supplied inputs and a bearer API key to a remote endpoint, but the file provides no explicit user-facing notice, consent step, or data handling warning before transmitting potentially sensitive image/video data. In a vision-analysis skill, inputs may contain personal, proprietary, or safety-monitoring imagery, so silent transmission to a third-party service creates a real privacy and compliance risk even if the behavior is functionally expected.
When a local file path is provided, the code converts the image to a data URI and includes the file contents in an outbound HTTPS request to a remote multimodal API. This can cause unintentional exfiltration of sensitive local images because the CLI and function do not require explicit confirmation, warning, or clear consent before transmitting local data off host.
This code reads arbitrary local files as images and converts their contents to base64 for downstream API use, which can expose user data from the filesystem. Although the functions are commented for developers, there is no user-facing confirmation, warning, or visible disclosure in this file about reading and serializing local file contents.
This helper reads a local file path and converts the full file contents into a base64 data URI, which may later be embedded or transmitted. There is no user-facing warning, confirmation, or disclosure in this code path about reading local files and transforming their contents.
该工作流全文以中文指令和示例呈现,且未说明可根据用户偏好切换语言,也未声明这是仅限中文场景的技能。按规则,强制特定语言而没有用户选择或合理、明确的地域性说明,属于自然语言政策违规。
该 markdown 文档从标题开始即以中文呈现,全文未说明这是特定区域/用户群的限定版本,也未提供语言选择。根据规则,强制特定语言而无用户 opt-in 属于自然语言层面的语言/区域策略违规。
The dependency uses a caret range (^7.0.1), which allows future minor and patch releases to be installed. This weakens build reproducibility and can introduce unexpected vulnerable or malicious code through the supply chain, though here it is limited to a devDependency and does not by itself prove compromise.
"test:all": "npm test && npm run test:integration"
},
"devDependencies": {
"archiver": "^7.0.1",
"openclaw": "github:openclaw/openclaw#main"
},
"optionalDependencies": {
The openclaw dependency is pulled directly from github:openclaw/openclaw#main, which tracks a moving branch rather than a fixed release or commit. Because advisories are known for this package and the exact resolved revision is not pinned, consumers may unknowingly install an affected or newly introduced vulnerable state, significantly increasing supply-chain risk.
The optional dependency sharp is specified with a caret range (^0.33.0), so installs may resolve to newer releases than originally tested. That creates a supply-chain and reproducibility risk, although the practical impact is somewhat reduced because the package is optional rather than mandatory.
"openclaw": "github:openclaw/openclaw#main"
},
"optionalDependencies": {
"sharp": "^0.33.0"
}
}
The script retrieves an API key and uses it in an Authorization header for a network request. While this is functionally expected for an API client, this file does not include a visible disclosure or warning to users that credentials are required and will be used for outbound authentication.
The only usage examples shown to users are Chinese prompts, which implicitly steer usage toward a specific language without offering alternatives or stating that the tool is region-specific. This can conflict with language/locale neutrality expectations when no opt-in or justification is provided.
The function opens a user-supplied file path and reads up to 64 KB to compute a stable identifier, which is access to local user data. The code has developer comments but no user-facing notice that file contents are being read for fingerprinting.
No suspicious patterns detected.