Back to skill

Security audit

architecture-generator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a documented, user-directed wrapper for sending toy or 3D model generation requests to an external OneKey gateway, with no hidden local code or persistence in the artifact.

Only use this skill with prompts, images, and designs you are comfortable sending to the OneKey gateway and downstream generation providers. Avoid secrets, private personal data, or confidential proprietary designs unless your organization has approved that external processing.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill documentation clearly instructs users to send prompts, image URLs, and generation requests to external services through the OneKey Agent Gateway and downstream 3D providers, but it does not warn users that their data and generated assets leave the local environment. This creates a privacy and data-governance risk because users may submit sensitive prompts, proprietary designs, or internal image references without informed consent or awareness of third-party processing.

Static analysis

No suspicious patterns detected.