T09 · Insecure Skill Coding Practices
- Location
SKILL.md:33- Finding
Bearer Token Exposure Through Command-Line Arguments
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a straightforward Hidream text-to-image API helper, but users should avoid putting real API tokens directly in command-line arguments.
Install only if you are comfortable sending prompts and an API token to Hidream. Prefer setting HIDREAM_AUTHORIZATION through a protected environment or secret manager, avoid putting real tokens in shell commands, rotate any token previously pasted into history, and use a limited-scope token where the provider supports it.
SKILL.md:33Bearer Token Exposure Through Command-Line Arguments
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
gen_task_url = f"{DEFAULT_ENDPOINT}/api-pub/gw/v3/image/txt2img/async"
get_task_result_url = gen_task_url + "/results"
submit_resp = requests.post(gen_task_url, json=payload, headers=headers, timeout=30)
if submit_resp.status_code != 200:
raise RuntimeError(f"http error: {submit_resp.status_code} {submit_resp.text}")
resp_json = submit_resp.json()
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
start = time.time()
while True:
print(f"Query Task result ...")
query_resp = requests.get(
get_task_result_url,
params={"task_id": task_id},
headers=headers,
The skill enables code behavior that uses environment access and network calls, but the manifest does not declare any tool scope or permission boundaries. This increases the chance that an agent or reviewer will underestimate the skill's capabilities, leading to overbroad execution in contexts where network or secret access should have been explicitly approved.
The documentation instructs users to pass an authorization token directly on the command line, which can leak via shell history, process listings, audit logs, CI logs, and terminal recordings. Because this token authorizes access to a remote image-generation API, exposure could enable unauthorized API use, quota abuse, or access under the user's identity.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
gen_task_url = f"{DEFAULT_ENDPOINT}/api-pub/gw/v3/image/txt2img/async"
get_task_result_url = gen_task_url + "/results"
submit_resp = requests.post(gen_task_url, json=payload, headers=headers, timeout=30)
if submit_resp.status_code != 200:
raise RuntimeError(f"http error: {submit_resp.status_code} {submit_resp.text}")
resp_json = submit_resp.json()
Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.
start = time.time()
while True:
print(f"Query Task result ...")
query_resp = requests.get(
get_task_result_url,
params={"task_id": task_id},
headers=headers,
The only user-facing prompt example is written in Chinese, which implicitly steers usage toward a specific language without stating that other languages are supported or that Chinese is required. This can conflict with language/locale policy expectations when no opt-in or justification is provided.
This code includes a hard-coded Chinese message literal ("生成失败") in user-visible output. The file provides no language selection or documented locale constraint, so it enforces a specific language without user opt-in.
No suspicious patterns detected.