T01 · Skill Instruction Hijacking
- Location
styles/brand-colors.md:133- Finding
Unauthorized Third-Party Branding Injected into User-Generated Content
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This image-generation skill has a coherent purpose, but it asks the agent to run unpinned external scripts and handle user content through unsafe shell and temporary-file patterns.
Review before installing. Use it only with non-sensitive content unless you are comfortable sending article text and prompts to Gemini, avoid literal execution of the documented shell templates, pin and inspect the external scripts/dependencies first, and remove or customize the Axton watermark/branding if generated images will be used commercially.
styles/brand-colors.md:133Unauthorized Third-Party Branding Injected into User-Generated Content
SKILL.md:206Execution of Mutable and Unaudited Scripts Outside the Audited Skill Package
SKILL.md:245Shell Command Injection Through Unquoted User-Derived Values
SKILL.md:236Predictable Shared Temporary Files Permit Collision and Symbolic-Link Attacks
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
# Analyze article and auto-generate illustrations (default)
/smart-illustrator path/to/article.md
# Output prompts only, don't auto-generate images
/smart-illustrator path/to/article.md --prompt-only
# Specify style (loads from styles/ directory)
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
# Analyze article and auto-generate illustrations (default)
/smart-illustrator path/to/article.md
# Output prompts only, don't auto-generate images
/smart-illustrator path/to/article.md --prompt-only
# Specify style (loads from styles/ directory)
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
## Background: the Make workflow version (auto-illustrate + WeChat publish)
Before packaging this into a Skill, I had already built an end-to-end Make workflow:
**search → write → auto-illustrate → format/publish (WeChat Official Account)**.
Full walkthrough (workflow logic & design trade-offs):
https://youtu.be/TbyJ3imLuXQ
The README advertises Gemini API-based generation and a --prompt-only mode but does not explicitly warn that article text, prompts, or derived content may be sent to Google's external service during normal operation. This can expose proprietary drafts, internal documents, or sensitive content to a third-party API without sufficiently informed consent.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The 'Critical Rules' section says prompts must include specific Chinese phrases such as '请为我绘制 N 张图片' and use a Chinese role label to trigger desired behavior. This is a language/locale constraint presented as mandatory behavior, but the README does not offer an opt-in choice or explain that the feature is intentionally Chinese-specific.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The trigger list includes broad everyday terms such as 'PPT', 'slides', 'cover', and 'thumbnail', which can cause the skill to activate in contexts unrelated to intentional image generation. Over-broad invocation increases the chance that user content is processed, files are read, or external tools/APIs are called without the user clearly intending to invoke this capability.
The skill defaults to sending slide content to the Gemini API but does not prominently warn users in the description that their content will be transmitted to an external service. In a document-processing skill, that omission is risky because users may provide proprietary, private, or regulated material under the assumption that processing is local.
The skill description does not warn users that --prompt-only mode automatically copies generated content to the clipboard and writes a backup file. This can expose sensitive article content or derived prompts to other local processes, clipboard history tools, shared desktops, or later unintended disclosure from /tmp storage.
The skill instructs the agent to execute npx -y bun ... without pinning a specific package or runtime version, which introduces a supply-chain risk and makes execution non-reproducible. If a compromised or unexpected package/runtime version is resolved at execution time, the skill could run attacker-controlled code on the host.
This invocation again relies on npx -y bun with no version pinning, so the command may fetch or resolve an unexpected runtime at execution time. That creates a clear supply-chain execution path in a skill that processes user-provided content and writes files, increasing the danger of remote code execution or host compromise.
The Gemini image-generation command uses npx -y bun without version pinning, creating the same supply-chain risk while also handling prompts derived from user content and API credentials. If dependency resolution is subverted, an attacker could gain code execution and potentially access sensitive environment variables such as GEMINI_API_KEY.
No suspicious patterns detected.