Back to skill

Security audit

IMA Studio All-in-One — Image, Video, Music, SeeDream, Veo, Suno. Banana

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches an AI media-generation purpose, but it needs review because a script option can redirect authenticated API traffic and error logs can retain sensitive prompts or media URLs.

Install only if you are comfortable sending prompts, generation settings, and any local input images you provide to IMA/CDN services. Use a scoped or test IMA_API_KEY, avoid passing custom --base-url values, and periodically review/delete ~/.openclaw/logs/ima_skills because failed requests may record sensitive prompt or media details.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/ima_create.py:1605
Finding

Unrestricted API Base URL Allows Bearer Credential Exfiltration

Content
View full analysis
dict: return { "Authorization": f"Bearer {api_key}", "Content-Type": "application/json", "x-app-source": "ima_skills", "x_app_language": language, } ``` ```python p.add_argument("--base-url", default=DEFAULT_BASE_URL, help="API base URL") ``` ```python def main(): args = build_parser().parse_args() base = args.base_url apikey = args.api_key ``` The resulting user-controlled base URL is subsequently used for authenticated requests: ```python url = f"{base_url}/open/v1/product/list" params = {"app": app, "platform": platform, "category": category} headers = make_headers(api_key, language) resp = requests.get(url, params=params, headers=headers, timeout=30) ``` ```python url = f"{base_url}/open/v1/tasks/create" headers = make_headers(api_key) resp = requests.post(url, json=payload, headers=headers, timeout=30) ``` ### Technical Analysis The `--base-url` command-line option accepts an arbitrary URL and is used directly as the origin for API requests. These requests include the IMA API key in an `Authorization: Bearer ...` header. There is no validation that the supplied URL: - Uses HTTPS. - Resolves to the documented `api.imastudio.com` service. - Belongs to an approved hostname allowlist. - Retains the expected origin after redirects. Consequently, any party able to influence the Skill's invocation arguments can redirect authenticated traffic to an attacker-controlled server. This behavior exceeds the documented minimum network privilege, which states that the credential is sent to IMA-owned endpoints. The issue does not require command injection or local code execution. The le ...[truncated 1788 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/ima_create.py:717
Finding

Task Failure Logging Persists Sensitive Prompts and Media URLs

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (21)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Yes, this code chunk does not match the declared description. The description promises a multi-model AI content creation/orchestration platform covering images, video, music, and TTS. The actual code shown is only a support module for logging. While logging can be a legitimate supporting detail, this chunk by itself performs materially different behavior than the declared end-user purpose and exposes undeclared filesystem interaction by creating, writing, rotating, and deleting log files in the user's home directory. There is no evidence in this code of any content-generation, model selection, workflow orchestration, or knowledge-base functionality.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 390)May include surrounding context.

md
**Data control:**
- ✅ **View stored data**: `cat ~/.openclaw/memory/ima_prefs.json`
- ✅ **Delete preferences**: `rm ~/.openclaw/memory/ima_prefs.json` (resets to defaults)
- ✅ **Delete logs**: `rm -rf ~/.openclaw/logs/ima_skills/` (auto-cleanup after 7 days anyway)

### ⚠️ Advanced Users: Fork & Modify

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 391)May include surrounding context.

md
**Data control:**
- ✅ **View stored data**: `cat ~/.openclaw/memory/ima_prefs.json`
- ✅ **Delete preferences**: `rm ~/.openclaw/memory/ima_prefs.json` (resets to defaults)
- ✅ **Delete logs**: `rm -rf ~/.openclaw/logs/ima_skills/` (auto-cleanup after 7 days anyway)

### ⚠️ Advanced Users: Fork & Modify

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 391)May include surrounding context.

md
**Data control:**
- ✅ **View stored data**: `cat ~/.openclaw/memory/ima_prefs.json`
- ✅ **Delete preferences**: `rm ~/.openclaw/memory/ima_prefs.json` (resets to defaults)
- ✅ **Delete logs**: `rm -rf ~/.openclaw/logs/ima_skills/` (auto-cleanup after 7 days anyway)

### ⚠️ Advanced Users: Fork & Modify

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 391)May include surrounding context.

md
**Data control:**
- ✅ **View stored data**: `cat ~/.openclaw/memory/ima_prefs.json`
- ✅ **Delete preferences**: `rm ~/.openclaw/memory/ima_prefs.json` (resets to defaults)
- ✅ **Delete logs**: `rm -rf ~/.openclaw/logs/ima_skills/` (auto-cleanup after 7 days anyway)

### ⚠️ Advanced Users: Fork & Modify

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · SKILL.md (reported line 395)May include surrounding context.

md
### ⚠️ Advanced Users: Fork & Modify

If you need to modify this skill for your use case:
1. **Fork the repository** (don't modify the original)
2. **Update your fork** with your changes
3. **Test thoroughly** with limited API keys

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill advertises and documents environment-variable use, persistent file writes, and outbound network access, but does not declare an explicit tool scope such as permissions or allowed-tools. That makes the effective capability boundary implicit rather than enforceable, increasing the risk that an agent runtime grants broader access than users expect.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 364)May include surrounding context.

md
## Overview

Call IMA Open API to create AI-generated content. All endpoints require an `ima_*` API key. The core flow is: **query products → create task → poll until done**.

---

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The instruction 'Match the user's language (Chinese/English)' imposes a binary language policy and excludes users who may prefer other languages. This is a natural-language policy concern because the skill hardcodes locale behavior rather than offering user choice or documenting a justified regional constraint.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The document repeatedly claims that user_id is never sent to IMA servers and is only local, yet the upload example mixes credential and identity concepts in a way that contradicts that assurance. In security-sensitive integrations, contradictory identity-handling guidance can cause developers to pass user identifiers or API keys to remote services incorrectly, leading to privacy leakage or credential misuse.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The sample invocation of get_upload_token does not match the documented signature and authentication narrative, which can cause implementers to pass the wrong parameters into an upload-token request. In this context, bad examples are dangerous because they directly influence how credentials are transmitted to a secondary domain and may result in accidental disclosure or broken auth flows.

Content

No source excerpt is available for this finding.

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

The skill instructs polling until completion and even warns against looping forever, but it does not specify a hard stop, retry budget, or absolute timeout in the documented control flow. An attacker-controlled or malfunctioning backend could keep the agent polling indefinitely, consuming runtime, tying up worker capacity, and potentially spamming progress updates.

Content

Scanner excerpt · SKILL.md (reported line 2115)May include surrounding context.

md
| Single-poll instead of loop | Poll until `resource_status == 1` for ALL medias |
| Missing `app` / `platform` in parameters | Required fields — use `ima` / `web` |
| `category` mismatch | `parameters[].category` must match top-level `task_type` |
| `resource_status == 2` not handled | Check for failure, don't loop forever |
| `status == "failed"` ignored | `resource_status=1` + `status="failed"` means actual failure |
| `n > 1` and only checking first media | All `n` media items must reach `resource_status == 1` |

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/ima_create.py (reported line 712)May include surrounding context.

python
f"credit={credit}, attribute_id={attribute_id}")

    try:
        resp = requests.post(url, json=payload, headers=headers, timeout=30)
        resp.raise_for_status()
        data = resp.json()

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/ima_create.py (reported line 780)May include surrounding context.

python
f"credit={credit}, attribute_id={attribute_id}")

    try:
        resp = requests.post(url, json=payload, headers=headers, timeout=30)
        resp.raise_for_status()
        data = resp.json()

Tainted flow: 'task_id' from requests.post (line 726, network input) → requests.post (network output)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/ima_create.py (reported line 780)May include surrounding context.

python
"Check the IMA dashboard for status."
            )

        resp = requests.post(url, json={"task_id": task_id},
                             headers=headers, timeout=30)
        resp.raise_for_status()
        data = resp.json()

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script automatically uploads any local file path provided in --input-images to a remote CDN using the user's API key, with only a progress message and no explicit consent or warning about external transmission. In an agent/skill context, this can cause unintended exfiltration of sensitive local images or other files if a caller passes a local path without realizing it will leave the host.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file's natural-language documentation is entirely in Chinese, including the module docstring and inline comments, with no indication that the skill is China-specific or that users may choose another language. This creates a language/locale policy issue because it imposes a specific language without opt-in or documented justification.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
92% confidence
Finding

The dependency is specified as requests>=2.25.0, which allows installation of any future version and does not guarantee a tested or known-safe release. This weakens supply-chain integrity and reproducibility, and can unintentionally pull in vulnerable or breaking versions during later installs.

Content

Scanner excerpt · requirements.txt (reported line 4)May include surrounding context.

text
# Python dependencies for ima-all-ai skill
# Install with: pip install -r requirements.txt

requests>=2.25.0

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
88% confidence
Finding

Because the manifest does not pin a specific requests version, it is impossible to verify whether deployed environments will install a release affected by one of the known advisories. In a skill that likely makes outbound HTTP requests to many AI/media services, use of a vulnerable HTTP client library could expose credentials, request integrity, or sensitive data depending on the installed version.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The header builder defaults the API language to "en" and always sends that locale in requests. This imposes a specific language choice unless the user knows to override it, which is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Dynamic attribute access via getattr()

Low
Category
Dangerous Code Execution
Confidence
50% confidence
Finding

Dynamic getattr() with a non-literal attribute name can access arbitrary object attributes, potentially bypassing access controls.

Content

Scanner excerpt · scripts/ima_logger.py (reported line 83)May include surrounding context.

python
# 默认 WARNING (只显示警告和错误)
        # 可设置 IMA_CONSOLE_LOG_LEVEL=INFO 查看详细日志
        console_level = os.getenv("IMA_CONSOLE_LOG_LEVEL", "WARNING")
        console_handler.setLevel(getattr(logging, console_level.upper(), logging.WARNING))
        console_handler.setFormatter(formatter)
        logger.addHandler(console_handler)

Static analysis

Detected: suspicious.destructive_delete_command

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
SKILL.md:391