Back to skill

Security audit

三剪客 · AI换装

Security checks for vulnerabilities and agentic risk

Overview

The skill is a real third-party AI try-on client, but it bundles a broader marketplace client that can call and enumerate services beyond the advertised try-on workflow.

Install only if you are comfortable giving this package an a7w API key that can be used by a generic marketplace client, not just the dressing_diffusion try-on API. Use a limited/revocable key if available, avoid uploading sensitive personal images without consent, and review commands carefully because arbitrary app/API calls may consume account points.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (22)

Tainted flow: 'req' from os.environ.get (line 151, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/client.py (reported line 111)May include surrounding context.

python
headers["Content-Type"] = "application/json"
    req = urllib.request.Request(url, data=data, headers=headers, method=method)
    try:
        with urllib.request.urlopen(req, timeout=timeout) as resp:
            raw = resp.read().decode("utf-8", "replace")
            status = resp.status
    except urllib.error.HTTPError as exc:

Tainted flow: 'req' from os.environ.get (line 151, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/client.py (reported line 153)May include surrounding context.

python
headers["Content-Type"] = "application/json"
    req = urllib.request.Request(url, data=data, headers=headers, method=method)
    try:
        with urllib.request.urlopen(req, timeout=timeout) as resp:
            raw = resp.read().decode("utf-8", "replace")
            status = resp.status
    except urllib.error.HTTPError as exc:

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as a narrowly scoped virtual try-on tool, but the bundled client reportedly supports generic app enumeration, schema export, arbitrary app/API invocation, points inspection, and local API-key persistence. This mismatch is dangerous because users and orchestration systems may grant trust or permissions appropriate for image try-on while the client can operate as a broader API wrapper with access to other services and locally stored credentials.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
成试穿效果生成。支持上衣、下装、全身换装。模型可在后台 extra_config 中切换。支持 提交换装任务、查询换装结果。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.c

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 7)May include surrounding context.

md
成试穿效果生成。支持上衣、下装、全身换装。模型可在后台 extra_config 中切换。支持 提交换装任务、查询换装结果。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.c

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language guidance section ('使用提示') and its warnings are written exclusively in Chinese. Under the policy, forcing a specific language without user opt-in is a locale/language policy violation unless the constraint is clearly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill documentation is written entirely in Chinese and presents usage instructions only in that language. Under the policy, forcing a specific language without user opt-in or a documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill advertises executable client commands and apparently includes code capabilities (env, filesystem, network, shell) but does not declare any tool scope or permission boundaries. In an agent setting, this makes the effective privileges ambiguous and can allow broader-than-expected access if the client or wrapper is invoked automatically.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
78% confidence
Finding

The skill explicitly directs users to an external service and requires an API key for api.a7w.cn, meaning user data and credentials will be used with a third-party system outside the local skill environment. External transmission is expected for this type of service, but it remains a security-relevant behavior because images and API usage data leave the platform.

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
name: dressing-diffusion
slug: dressing-diffusion
displayName: 三剪客 · AI换装
description: "智能图片换装,上传模特图和服装图,AI 自动完成试穿效果生成。支持上衣、下装、全身换装。模型可在后台 extra_config 中切换。支持 提交换装任务、查询换装结果。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「AI换装」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This skill processes user-supplied model and garment images through a third-party API, but the description does not prominently warn that potentially sensitive photos will be transmitted off-platform. That omission undermines informed consent and increases privacy risk, especially for personal images that may contain biometric or other sensitive data.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 11)May include surrounding context.

md
displayName: 三剪客 · AI换装
description: "智能图片换装,上传模特图和服装图,AI 自动完成试穿效果生成。支持上衣、下装、全身换装。模型可在后台 extra_config 中切换。支持 提交换装任务、查询换装结果。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「AI换装」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT
tags:
  - 三剪客

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 95)May include surrounding context.

md
displayName: 三剪客 · AI换装
description: "智能图片换装,上传模特图和服装图,AI 自动完成试穿效果生成。支持上衣、下装、全身换装。模型可在后台 extra_config 中切换。支持 提交换装任务、查询换装结果。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「AI换装」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT
tags:
  - 三剪客

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 104)May include surrounding context.

md
displayName: 三剪客 · AI换装
description: "智能图片换装,上传模特图和服装图,AI 自动完成试穿效果生成。支持上衣、下装、全身换装。模型可在后台 extra_config 中切换。支持 提交换装任务、查询换装结果。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「AI换装」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT
tags:
  - 三剪客

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 7)May include surrounding context.

md
displayName: 三剪客 · AI换装
description: "智能图片换装,上传模特图和服装图,AI 自动完成试穿效果生成。支持上衣、下装、全身换装。模型可在后台 extra_config 中切换。支持 提交换装任务、查询换装结果。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「AI换装」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT
tags:
  - 三剪客

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

md
displayName: 三剪客 · AI换装
description: "智能图片换装,上传模特图和服装图,AI 自动完成试穿效果生成。支持上衣、下装、全身换装。模型可在后台 extra_config 中切换。支持 提交换装任务、查询换装结果。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「AI换装」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT
tags:
  - 三剪客

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation instructs users to upload model and garment image URLs to a third-party remote API but does not warn that these images may contain sensitive personal data, biometric characteristics, or other privacy-relevant content. In an image-processing skill centered on human photos, this omission increases the risk of users sharing personal images without informed consent or understanding of external data handling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill guidance is written in Chinese and includes Chinese-only UI labels and instructions, but it does not indicate that the skill is region-specific or offer any alternative language option. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The bundled code is a generic marketplace client that can enumerate and interact with any plugin on the remote platform, while the skill metadata presents it as a dedicated dressing-diffusion try-on tool. This scope mismatch expands the attack surface and enables capabilities unrelated to the declared purpose, which can mislead operators and permit unintended remote actions through the skill.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The bulk schema-dump logic discovers all available apps and exports their schemas, which is unrelated to the stated limited try-on workflow. In an agent setting, this broadens reconnaissance over the remote service and gives the skill visibility into capabilities far beyond its advertised function.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The call command allows arbitrary app/API invocation with attacker-controlled request bodies, exceeding the manifest's description of a specialized image dressing skill. In practice this turns the package into a general remote execution broker for the a7w marketplace, enabling unintended access to other plugins and actions under the user's API key.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The CLI entrypoint exposes the generic remote plugin execution features to any caller, despite the skill being represented as a specific image dressing tool. This mismatch is dangerous in agent ecosystems because a seemingly narrow skill can be used as a covert gateway to broader remote capabilities and billing-consuming actions on unrelated plugins.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

All user-facing documentation in this file is presented only in Chinese, with no indication that other languages are supported or that the locale is intentionally restricted. This can violate language/locale policy when a skill imposes a specific language without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.