Back to skill

Security audit

Smart Illustrator

Security checks for vulnerabilities and agentic risk

Overview

This image-generation skill has a coherent purpose, but it asks the agent to run unpinned external scripts and handle user content through unsafe shell and temporary-file patterns.

Review before installing. Use it only with non-sensitive content unless you are comfortable sending article text and prompts to Gemini, avoid literal execution of the documented shell templates, pin and inspect the external scripts/dependencies first, and remove or customize the Axton watermark/branding if generated images will be used commercially.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T01 · Skill Instruction Hijacking

Warning
Location
styles/brand-colors.md:133
Finding

Unauthorized Third-Party Branding Injected into User-Generated Content

Content
View full analysis
Remediation
View remediation

T07 · Tool Hijacking and Spoofing

Error
Location
SKILL.md:206
Finding

Execution of Mutable and Unaudited Scripts Outside the Audited Skill Package

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:245
Finding

Shell Command Injection Through Unquoted User-Derived Values

Content
View full analysis
/tmp/smart-illustrator-prompt.json echo "✓ 备份已保存到 /tmp/smart-illustrator-prompt.json" ``` ### Technical Analysis The command templates interpolate dynamic values directly into shell syntax: - `{输出路径}` is an output path derived from the user's requested destination. - `{文章名}` is derived from the input article filename. - `{生成的 JSON}` is generated from user-controlled article content and prompt data. The output path and article name are not shell-quoted. A value containing whitespace or shell metacharacters such as `;`, `&`, command substitution, redirection, or newline characters can alter command parsing. The generated JSON is enclosed in single quotes, but JSON content can contain apostrophes originating from the article. A single quote terminates the shell string, after which additional shell tokens may be interpreted as commands. The vulnerability occurs when an Agent materializes these templates as shell commands without applying robust argument separation and escaping. ### Attack Path One possible filename-based exploitation path is: 1. An attacker supplies an article with a filename containing shell metacharacters. 2. The Skill derives `{文章名}` or `{输出路径}` from that filename. 3. The Agent inserts the value into the documented unquoted `--output` argument. 4. ...[truncated 1106 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:236
Finding

Predictable Shared Temporary Files Permit Collision and Symbolic-Link Attacks

Content
View full analysis
/tmp/image-prompt.txt <<'EOF' {从 style 文件提取的 System Prompt} **内容**:{配图内容} EOF ``` ```bash cat > /tmp/cover-prompt.txt <<'EOF' {从 style-cover.md 提取的 System Prompt} **内容**: - 核心概念:{主题} - 视觉隐喻:{设计} EOF ``` ```bash echo '{生成的 JSON}' > /tmp/smart-illustrator-prompt.json echo "✓ 备份已保存到 /tmp/smart-illustrator-prompt.json" ``` ### Technical Analysis The Skill uses fixed names in the globally shared `/tmp` directory: - `/tmp/image-prompt.txt` - `/tmp/cover-prompt.txt` - `/tmp/smart-illustrator-prompt.json` Fixed temporary paths permit collisions between concurrent Skill runs. On systems where another local user or process can create entries in `/tmp`, an attacker may precreate one of these paths as a symbolic link to another writable target. The subsequent shell redirection follows the link and overwrites the target. The fixed paths also allow another process to replace prompt content between the write and the image-generation command. Depending on system permissions and `umask`, generated prompts may also be readable by other local users. ### Attack Path 1. A local attacker predicts one of the fixed temporary filenames. 2. The attacker creates a symbolic link at that path pointing to a file writable by the victim, or repeatedly replaces the temporary file. 3. The user invokes the Skill. 4. Shell redirection writes prompt or JSON data through the attacker-controlled path. 5. The target file is overwritten, or the image generator consumes attacker-substituted prompt content. A concurrent-run variant occurs when two legitimate Skill executions use the same path, causing one run to overwrite or consume the other run's data. ### Impact Assessment The impact is limited to files writable by the Agent account but may include: - Overwritin ...[truncated 362 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (39)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · README.md (reported line 90)May include surrounding context.

md
# Analyze article and auto-generate illustrations (default)
/smart-illustrator path/to/article.md

# Output prompts only, don't auto-generate images
/smart-illustrator path/to/article.md --prompt-only

# Specify style (loads from styles/ directory)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · README.md (reported line 118)May include surrounding context.

md
# Analyze article and auto-generate illustrations (default)
/smart-illustrator path/to/article.md

# Output prompts only, don't auto-generate images
/smart-illustrator path/to/article.md --prompt-only

# Specify style (loads from styles/ directory)

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 36)May include surrounding context.

md
## Background: the Make workflow version (auto-illustrate + WeChat publish)

Before packaging this into a Skill, I had already built an end-to-end Make workflow:
**search → write → auto-illustrate → format/publish (WeChat Official Account)**.

Full walkthrough (workflow logic & design trade-offs):
https://youtu.be/TbyJ3imLuXQ

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README advertises Gemini API-based generation and a --prompt-only mode but does not explicitly warn that article text, prompts, or derived content may be sent to Google's external service during normal operation. This can expose proprietary drafts, internal documents, or sensitive content to a third-party API without sufficiently informed consent.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The 'Critical Rules' section says prompts must include specific Chinese phrases such as '请为我绘制 N 张图片' and use a Chinese role label to trigger desired behavior. This is a language/locale constraint presented as mandatory behavior, but the README does not offer an opt-in choice or explain that the feature is intentionally Chinese-specific.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes broad everyday terms such as 'PPT', 'slides', 'cover', and 'thumbnail', which can cause the skill to activate in contexts unrelated to intentional image generation. Over-broad invocation increases the chance that user content is processed, files are read, or external tools/APIs are called without the user clearly intending to invoke this capability.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill defaults to sending slide content to the Gemini API but does not prominently warn users in the description that their content will be transmitted to an external service. In a document-processing skill, that omission is risky because users may provide proprietary, private, or regulated material under the assumption that processing is local.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill description does not warn users that --prompt-only mode automatically copies generated content to the clipboard and writes a backup file. This can expose sensitive article content or derived prompts to other local processes, clipboard history tools, shared desktops, or later unintended disclosure from /tmp storage.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The skill instructs the agent to execute npx -y bun ... without pinning a specific package or runtime version, which introduces a supply-chain risk and makes execution non-reproducible. If a compromised or unexpected package/runtime version is resolved at execution time, the skill could run attacker-controlled code on the host.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This invocation again relies on npx -y bun with no version pinning, so the command may fetch or resolve an unexpected runtime at execution time. That creates a clear supply-chain execution path in a skill that processes user-provided content and writes files, increasing the danger of remote code execution or host compromise.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The Gemini image-generation command uses npx -y bun without version pinning, creating the same supply-chain risk while also handling prompts derived from user content and API credentials. If dependency resolution is subverted, an attacker could gain code execution and potentially access sensitive environment variables such as GEMINI_API_KEY.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.