T09 · Insecure Skill Coding Practices
- Location
config.json:1- Finding
Plaintext API credentials stored in the Skill directory
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill matches its VolcEngine video-generation purpose, but it asks users to store API keys in a local skill file and can send prompts or task IDs to an external paid API under broad triggers.
Review before installing. Use a dedicated low-privilege VolcEngine key with quotas, avoid putting secrets in the skill directory, do not commit or share config.json, and avoid sending private, proprietary, or personal information in prompts unless you intend it to be processed by VolcEngine.
config.json:1Plaintext API credentials stored in the Skill directory
The README describes sending prompts and task IDs to VolcEngine but does not warn users that their input and related task data are transmitted to a third-party external API. This can lead to unintentional disclosure of sensitive prompts, internal project details, or identifiers, especially if users assume the skill operates locally or do not understand the data-sharing implications.
The description does not warn users that their prompts and related task data will be transmitted to a third-party API. This creates a privacy and data-handling risk because users may include sensitive, proprietary, or personal information in prompts without realizing it leaves the local environment.
The trigger phrases are broad enough to match many ordinary user requests about making or checking videos, which can cause the skill to activate unexpectedly. In this skill’s context, unintended activation is more dangerous because it may route user prompts and task identifiers to an external video-generation service without clear user intent or informed consent.
Documenting API credentials in a local config.json file without guidance on access controls, secret rotation, exclusion from version control, or safer secret storage encourages insecure secret management. If the file is exposed through source control, logs, backups, or permissive filesystem access, an attacker could steal the keys and abuse the external API account.
The code performs an outbound HTTP POST to visual.volcengineapi.com, transmitting the task identifier and signed request metadata. While the function purpose implies querying a remote service, the code lacks an explicit warning or disclosure that user-supplied task data will be sent over the network.
This code accesses sensitive credentials by loading access_key and secret_key from config.json when they are not passed explicitly. Although the function docstring describes the parameters, there is no warning in code comments, prompts, or user-facing output that local credentials will be read automatically.
With no manifest available, the only explicit intent comes from the code's video-generation docstring. The function goes beyond prompt-to-video transformation by sourcing secrets from environment variables, which is a privileged capability not justified by the stated functional description alone; the CLI path also reads secrets from config.json.
The script sends the user-supplied prompt directly to an external VolcEngine API, but there is no explicit user-facing notice or consent step at the point of transmission. If prompts contain proprietary, personal, or otherwise sensitive data, this can cause unintended disclosure to a third party despite the HTTPS transport.
The file contains user-visible natural-language text in multiple languages, including a Chinese comment alongside otherwise English-facing strings. This can violate a language/locale policy when the skill does not explicitly offer or document language selection or localization behavior.
No suspicious patterns detected.