Back to skill

Security audit

ai-poster-generator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward AI poster-generation guide that uses an external API and share links, with privacy caveats users should understand.

Install only if you are comfortable using the Craftsman/DeepNLP external service and providing its API key. Avoid submitting confidential, personal, copyrighted, or unreleased business material unless you have reviewed the provider's access controls, retention policy, and sharing behavior for generated workspace and export URLs.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill instructs users to send prompts and uploaded images to external services and repeatedly exposes results through public share/workspace/export URLs, but it does not clearly warn users about the third-party transmission and possible public accessibility of generated assets and embedded text. In a design tool context, prompts and images often contain sensitive business, personal, or copyrighted material, so this omission can lead to unintentional disclosure.

Static analysis

No suspicious patterns detected.