Back to skill

Security audit

设计框架套件 - 生图交付

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent but should be reviewed because it automatically sends user-derived design text and generated images to the bot owner through external scripts after a loosely defined confirmation flow.

Install only if the intended operators understand that design framework text and generated concept images may be privately sent to the bot owner and processed through the referenced image-generation/messaging scripts. Review the companion design-framework-sender skill, recipient configuration, API credentials, and confirmation workflow before using it with confidential client or proprietary design material.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill description says it will privately send generated framework text and concept images to the Bot owner, but it does not present this as a clear, explicit user-facing warning or informed-consent requirement. Because the skill handles user-derived content and automatically forwards it to a third party, this creates a meaningful privacy and data-exfiltration risk, especially if users assume outputs stay within the current conversation or group.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The natural-language content of the skill is entirely in Chinese and includes fixed Chinese notification text, with no indication that users can opt into another language. Under the policy, forcing a specific language without user choice or explicit documented justification is a locale-policy issue.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The description says the skill proceeds 'after confirmation' to automatically generate and deliver content, but it does not define precise trigger conditions, scope limits, or who must confirm. Ambiguous invocation rules increase the risk of unintended activation or misuse, especially in an automation context tied to external messaging and image generation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description is written entirely in Chinese and presents the skill behavior in that language without indicating any user language choice or that the skill is intended only for a Chinese-speaking or region-specific context. This can violate language/locale policy when a skill implicitly constrains interaction language without opt-in or justification.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The metadata explicitly states that user-request-derived concept images are automatically sent privately to the bot owner after confirmation. This creates a clear data disclosure pathway to a third party and may expose sensitive user inputs, proprietary designs, or confidential visual outputs without clear, granular, user-facing consent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.