T09 · Insecure Skill Coding Practices
- Location
references/api-workflows.md:408- Finding
Unconsented Upload of User Media to Public Third-Party File Hosts
- Content
View full analysis
Vulnerability Details
File Location:
references/api-workflows.md:408-418
Vulnerability Type: Insecure handling and external disclosure of user-provided media
Risk Level: MediumVulnerable Code
markdown ## 9. 媒体文件托管(用户发来的图片/视频需上传) OpenCreator 输入只接受直链 URL,本地文件需先上传托管。 | 优先级 | 服务 | 适用 | 命令 | |---|---|---|---| | 1 | **tmpfiles.org** | 视频 + 图片 | `curl -F "file=@file.mp4" https://tmpfiles.org/api/v1/upload` | | 2 | **catbox.moe** | 仅图片 | `curl -F "reqtype=fileupload" -F "fileToUpload=@file.png" https://catbox.moe/user/api.php` | | 3 | 告知用户 | — | 全部失败时暂停,请用户提供直链 | > ⚠️ **tmpfiles 必须把 URL 改成 `/dl/` 直链**: > `http://tmpfiles.org/12345/file.mp4` → `http://tmpfiles.org/dl/12345/file.mp4`Technical Analysis
The mandatory workflow documentation instructs the agent to upload locally supplied user images and videos to
tmpfiles.orgorcatbox.moe. These services are separate from the declared OpenCreator production API.The upload procedure does not require:
- Explicit informed consent before disclosure to the third party
- A check for personal, confidential, proprietary, or regulated content
- Authentication or access controls for the resulting media URL
- A documented retention period or deletion procedure
- Verification of the service's privacy and security guarantees
- Confirmation that the user is authorized to redistribute the media
- HTTPS for every subsequent retrieval operation
The example converts the upload response into an
http://download URL. If followed literally, this may expose media retrieval to passive monitoring, content substitution, or link manipulation on an untrusted network.Although uploading media is functionally related to providing URL-based input to OpenCreator, automatically using unrelated public file hosts exceeds the minimum privacy-preserving scope required. First-party authenticated storage, user-controlled storage, or an explicit consent boun ...[truncated 1558 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace public third-party hosts with authenticated, first-party OpenCreator upload storage.
- If first-party storage is unavailable, require the user to provide a URL from storage they control.
- Before any third-party upload, obtain explicit consent identifying:
- The destination service
- The type of data being uploaded
- The possibility of public URL access
- Applicable retention and deletion limitations
- Reject or pause uploads involving confidential, regulated, biometric, or otherwise sensitive media unless an approved private storage path is available.
- Use HTTPS exclusively. Remove the documented
http://tmpfiles.orgconversion example. - Prefer short-lived, signed URLs with narrowly scoped read access.
- Strip unnecessary metadata, including EXIF and location data, before upload when the user approves.
- Document deletion and retention procedures and, where supported, delete temporary media immediately after workflow completion.
- Avoid printing upload URLs in logs and redact them from diagnostic output.
- Add an allowlist for approved storage domains and prevent arbitrary fallback uploads.
