T09 · Insecure Skill Coding Practices
- Location
SKILL.md:84- Finding
Unvalidated Remote Image URLs Enable Server-Side Request Forgery
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill’s core purpose is coherent, but it requires direct use of unvalidated remote image URLs and creates HTML reports from user/API data without clear escaping or URL safety controls.
Review before installing. Use this only if you trust RedFox as the data/API provider, can revoke the REDFOX_API_KEY, and are comfortable with the agent fetching API-returned image URLs and writing a local HTML report. Prefer running it in a network-restricted environment and opening generated HTML cautiously until URL validation and HTML escaping are added.
SKILL.md:84Unvalidated Remote Image URLs Enable Server-Side Request Forgery
references/report_template.md:21Unescaped User and API Data Can Be Injected into Generated HTML Reports
SKILL.md:53Unpinned Requests Dependency Creates a Supply-Chain Risk
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
print(f"URL: {url}", file=sys.stderr)
print(f"参数: {params}", file=sys.stderr)
response = requests.get(url, params=params, headers=headers, timeout=30)
if debug:
print(f"状态码: {response.status_code}", file=sys.stderr)
The skill advertises a narrowly scoped design-analysis function, but its instructions require external API usage, credential handling, direct URL fetching, and HTML file generation that are not transparently declared in its stated behavior. This mismatch can bypass user and platform expectations, making risky operations appear as benign design assistance and reducing informed consent around data access and file creation.
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
<body style="font-family:-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;line-height:1.6;color:#333;background:#f5f5f5;padding:20px">
<div style="max-width:1200px;margin:0 auto;background:#fff;border-radius:12px;padding:30px;box-shadow:0 2px 12px rgba(0,0,0,0.08)">
<!-- 报告标题 -->
<h1 style="color:#1a1a1a;margin-bottom:30px;font-size:28px;border-bottom:3px solid #1890ff;padding-bottom:15px">📊 爆款封面分析报告</h1>
<!-- 数据来源信息 -->
The README says users can 'Simply describe your niche, content topic, or cover needs in natural language — no commands to memorize,' which does not define clear activation boundaries or exclusions. This broad phrasing overlaps with ordinary design-related conversation and could cause unintended invocation because there are no negative examples or explicit trigger constraints.
The skill invites activation via unconstrained natural-language requests such as '直接用自然语言说出你的赛道、内容主题或封面需求即可', which makes accidental or ambiguous invocation more likely. In an agent environment, broad triggers can cause the skill to run in contexts the user did not clearly intend, potentially sending user prompts or uploaded images to external services and consuming privileged resources like API-backed analysis/generation.
The example phrases are generic everyday requests like '帮我设计美妆教程封面' and '参考这张图帮我设计封面', which overlap with normal conversation and can be matched too loosely by orchestrators. Because this skill can analyze user-provided content and generate outputs via an external API, overly generic triggers increase the risk of unintended invocation, data sharing, and unnecessary tool execution.
The skill explicitly instructs use of environment credentials, external API access, and file writes, but declares no tool scope or permissions boundaries. In an agent environment, this creates an authorization gap where the skill may gain or assume broader capabilities than users or platform policy expect, increasing the risk of unintended network access, secret use, and filesystem modification.
The top-level trigger wording is broad enough that ordinary user requests about covers, images, or article analysis could activate the skill without clear user intent to use external data sources or generate files. Over-broad activation raises the chance of surprising tool use, unintended network requests, and accidental handling of user-provided content under a more privileged workflow.
The trigger rule table uses ambiguous conditions like users providing themes, copy, or images, which are common across many benign conversations and could route unrelated content into this skill. In context, that matters because the workflow then performs network-backed querying, image fetching, and file output, so ambiguous routing increases the blast radius of unintended execution.
The template sets lang="zh-CN" and all visible interaction text is fixed in Chinese, which can force a specific language/locale experience. Under SQP-3, this is a natural-language policy concern unless the skill offers a language choice or clearly documents that it is intentionally region-specific.
The file mandates '统一使用"爆款封面",禁止使用' several alternate terms, imposing a fixed wording policy regardless of user preference or context. This is a natural-language policy concern because it forces terminology choice without offering the user any language or phrasing opt-in.
This markdown file instructs the skill to generate and save an HTML report file in the current working directory. For markdown files, SQP-2 applies when the description omits warnings about behaviors that affect user data or the local system, and there is no disclosure here that a file will be created.
No suspicious patterns detected.