Back to skill

Security audit

image2生图助手

Security checks for vulnerabilities and agentic risk

Overview

This skill is not plainly malicious, but it should be reviewed because it sends user image materials and an API key to a remote service while its diagnostic-versus-generation purpose and invocation scope are unclear.

Install only if you trust ai-skills.ai and the publisher with API-key-authenticated requests, uploaded/reference image materials, prompts, brand requirements, and profile context. Review or remove AISKILLS_BASE_URL overrides, use a limited-scope API key, and treat this as an externally processed image-generation/diagnosis workflow rather than a purely local image quality checker.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/run.py:25
Finding

API credential disclosure through an attacker-controlled service endpoint

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
ai-gpt-image-2/scripts/run.py:25
Finding

Duplicated runner forwards API credentials to an unrestricted configurable endpoint

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (23)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A second aspect of the mismatch is that the skillId-driven remote call is not verifiably tied to the specific promised visual-diagnostics function, so the real remote behavior is opaque. In security terms, opaque remote delegation plus credentialed access can enable unexpected data handling, billing actions, or outputs beyond user expectations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A second aspect of the mismatch is that the skillId-driven remote call is not verifiably tied to the specific promised visual-diagnostics function, so the real remote behavior is opaque. In security terms, opaque remote delegation plus credentialed access can enable unexpected data handling, billing actions, or outputs beyond user expectations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest advertises a diagnostic skill that helps decide whether an existing image is ready to publish, but the actual form is built around generating new images with GPT Image 2. This mismatch can mislead users into providing the wrong inputs, receiving outputs they did not intend, and potentially bypassing review or approval workflows because the skill’s safety expectations do not match its real behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The stated user intent asks whether an image is suitable for publication, but the form instructs users to submit generation requirements, reference images, and prompts for GPT Image 2. This contradiction creates a deceptive interaction surface where users may believe they are getting a compliance or quality assessment when they are actually invoking content generation, increasing the chance of unsafe publication decisions or unauthorized derivative content creation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The schema solicits inputs for generating images (prompt text, reference uploads, public URLs, style/brand requirements), while the skill metadata describes an image quality diagnosis assistant. This mismatch can mislead users into providing different content than expected and can cause the agent to perform a materially different action than its declared purpose, undermining trust, consent, and review controls.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill advertises use of environment variables and an external API but does not declare any explicit tool scope or allowed-tools boundary. That makes the capability surface less transparent to reviewers and downstream users, increasing the chance that network access and secret-backed operations are invoked without informed approval.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger language is broad enough that the skill may activate for loosely related image-quality questions without clear consent boundaries. In this context, over-broad activation is risky because activation can cause user-supplied images, URLs, and text to be forwarded to an external service unexpectedly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The entire skill description, usage guidance, and examples are written only in Chinese, with no indication that users may interact in another language or that the skill is intentionally limited to a Chinese-language audience. Under the stated policy, forcing a specific language without opt-in can be a natural-language policy issue.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The 'when to use' section describes expansive, ambiguous conditions that could capture many marketing, media, and e-commerce image tasks. Because the skill relies on an external API, ambiguous boundaries raise the likelihood of accidental invocation and unintended disclosure of business-sensitive creative assets or campaign materials.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation asks users to provide image URLs, files, and text materials but does not clearly warn that these inputs are sent to an external API for processing. This omission creates a meaningful privacy and confidentiality risk, especially for unpublished creatives, customer data, licensed assets, or internal brand materials.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The metadata and default prompt are entirely in Chinese and orient the skill toward a single locale without indicating user choice or fallback behavior. This can cause the system to respond in an unexpected language, mis-handle user intent, or silently reduce transparency and usability for non-Chinese users, especially if the skill is invoked implicitly.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill enables implicit invocation without any visible trigger constraints or scoping, which increases the chance the assistant will auto-select this skill in situations the user did not clearly request. Because this skill is an image-quality diagnostic assistant, unintended invocation could cause inappropriate routing of user input, privacy-sensitive image handling, or confusing outputs without explicit user consent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The top-level skill description is broad enough to match many common image-related requests without clear limits, which can cause the agent to invoke this skill in situations the user did not specifically intend. Over-broad activation increases the chance of unnecessary external API use and accidental disclosure of user-provided image content, prompts, or business materials.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The 'when to use' section covers very common marketing, media, and ecommerce image tasks in a way that is too expansive, making accidental or excessive routing likely. In a tool that can accept links, files, and text for external processing, broad activation criteria increase the risk of sending sensitive assets or proprietary campaign materials when a narrower local response would suffice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs users to provide accessible URLs and uploaded materials that are sent to an external API, but it does not clearly warn that these materials will leave the local environment or may contain sensitive business, personal, copyright, or licensed content. This creates a real data-handling risk because users may share confidential images, product drafts, or internal brand assets without informed consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest presents the skill name and description only in Chinese while the default prompt is written in English, but nowhere indicates that the user can choose or opt into a language/locale. This creates a language-policy concern because the skill appears to impose language behavior implicitly rather than documenting or offering a locale choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JSON schema contains user-facing labels, placeholders, descriptions, and validation messages exclusively in Chinese. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The user-facing question, skill name, placeholders, labels, and descriptions are all written in Chinese, indicating the skill is intended to operate in a fixed language. There is no visible opt-in, locale selector, or justification that this is a region-specific skill, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code emits a billing error message in Chinese only: "余额不足,请前往 ... 充值后重试". That imposes a specific language on all users without any locale selection or documented regional justification, which is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JSON schema contains user-facing placeholder text, labels, descriptions, and validation messages entirely in Chinese. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest question and description position the skill as a visual quality diagnostic assistant that evaluates existing images and produces conclusions and action advice. However, the input fields and placeholder repeatedly describe 'GPT 图片生成需求', '用于直接生成图片', and using reference materials '用于 GPT Image 2 参考生成或风格改写', which indicates image generation/prompt construction rather than publication-readiness diagnosis of an existing image.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This manifest uses Chinese for the user-facing question, skill name, placeholders, labels, and descriptions, which effectively forces a specific language experience. There is no indication that users can opt into another language or that the skill is intentionally restricted to a Chinese-speaking region or audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The HTTP error handler emits a fixed Simplified Chinese message for insufficient billing balance. This imposes a specific language on all users and there is no nearby opt-in, locale detection, or documentation showing that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.