Back to skill

Security audit

Visual Muse

Security checks for vulnerabilities and agentic risk

Overview

The skill can generate images as advertised, but its setup and support files use broad local installation, network exposure, Docker control, and risky cleanup commands.

Review this before installing. Use it only if you are comfortable running a full local ComfyUI setup, downloading large third-party model files, and giving the skill access to OpenClaw workspace paths. Bind ComfyUI to 127.0.0.1 unless you intentionally need remote access, verify downloaded artifacts where possible, and do not copy the troubleshooting cleanup commands unless you have checked the targets and made a verified backup.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
scripts/setup.sh:68
Finding

Unpinned Remote Dependencies and Unverified Model Downloads

Content
View full analysis

Vulnerability Details

File Location: scripts/setup.sh:68-69, scripts/setup.sh:89-90, scripts/setup.sh:97-99, and scripts/setup.sh:144-165
Vulnerability Type: Supply-chain exposure through mutable dependencies and unverified artifacts
Risk Level: Medium

Vulnerable Code

bash
git clone --depth 1 https://github.com/comfyanonymous/ComfyUI.git "$COMFY_DIR" || \
git clone --depth 1 https://ghfast.top/https://github.com/comfyanonymous/ComfyUI.git "$COMFY_DIR" || {
  err "ComfyUI clone failed; check the network and retry"
  exit 1
}
bash
pip install --upgrade pip setuptools wheel -q
pip install torch torchvision torchaudio -q
pip install -r "$COMFY_DIR/requirements.txt" -q
bash
git clone --depth 1 https://github.com/ltdrdata/ComfyUI-Manager.git "$COMFY_DIR/custom_nodes/ComfyUI-Manager" || \
git clone --depth 1 https://ghfast.top/https://github.com/ltdrdata/ComfyUI-Manager.git "$COMFY_DIR/custom_nodes/ComfyUI-Manager" || \
warn "ComfyUI-Manager installation failed; core functionality is unaffected"
bash
download() {
  local url="$1" output="$2" name="$3"
  if [ -s "$output" ]; then
    local size; size="$(du -h "$output" | awk '{print $1}')"
    warn "$name already exists ($size); skipping"
    return 0
  fi
  log "Downloading $name..."
  curl -L -C - --progress-bar -o "$output" "$url" || \
  curl -L -C - --progress-bar -o "$output" "$(echo "$url" | sed 's|https://huggingface.co|https://hf-mirror.com|')" || {
    warn "$name download failed; it can be downloaded manually later"
    rm -f "$output"
    return 0
  }
  ok "$name download complete"
}

download \
  "https://huggingface.co/stabilityai/stable-diffusion-xl-base-1.0/resolve/main/sd_xl_base_1.0.safetensors" \
  "$MODELS_DIR/checkpoints/sd_xl_base_1.0.safetensors" \
  "SDXL Base 1.0 (6.5GB)"

download \
  "https://huggingface.co/stabilityai/sdxl-vae/resolve/main/sdxl_vae.saf
...[truncated 2558 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin ComfyUI and ComfyUI-Manager to reviewed commit hashes or signed release tags. Clone first, verify the remote URL, and explicitly check out the approved commit.
  2. Maintain a dependency lockfile containing exact Python versions and hashes. Install with hash enforcement, such as pip install --require-hashes.
  3. Avoid silently falling back to third-party Git proxies or mirrors. If mirrors are necessary, document their trust model and require explicit user opt-in.
  4. Publish expected SHA-256 or stronger digests for every model artifact and reject any download that does not match.
  5. Download to a temporary file, verify the digest, and atomically move the artifact into the model directory only after successful verification.
  6. Run ComfyUI in a dedicated, unprivileged account or container with minimal filesystem mounts and restricted outbound network access.
  7. Separate the lightweight API client from the full installer so users with an existing ComfyUI deployment do not need to grant installation privileges.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/setup.sh:118
Finding

Generated ComfyUI Launcher Exposes an Unauthenticated API on All Interfaces

Content
View full analysis

Vulnerability Details

File Location: scripts/setup.sh:118-126
Vulnerability Type: Unnecessary network exposure and insecure default configuration
Risk Level: Medium

Vulnerable Code

bash
cat > "$AI_STUDIO_DIR/start_comfyui.sh" << 'STARTEOF'
#!/usr/bin/env bash
set -euo pipefail
source "$HOME/ai-studio/comfyui-venv/bin/activate"
cd "$HOME/ai-studio/comfyui"
echo "[Information] Starting ComfyUI (listen 0.0.0.0:8188 --highvram --fp32-vae)..."
echo "[Information] Open http://127.0.0.1:8188 in a browser"
echo "[Information] Press Ctrl+C to stop"
python main.py --listen 0.0.0.0 --port 8188 --highvram --fp32-vae
STARTEOF

Technical Analysis

The generated startup script binds ComfyUI to 0.0.0.0, making port 8188 available on every network interface. The surrounding documentation describes ComfyUI as a local service, and the generated script does not configure authentication, authorization, TLS, firewall restrictions, or a trusted reverse proxy.

Binding to all interfaces exceeds the minimum network privileges needed for local image generation. A loopback binding would be sufficient for a client running on the same host. Container-to-host access should instead be enabled through an explicitly restricted network design rather than exposing the API indiscriminately.

The script's browser message references 127.0.0.1, which may also give users the mistaken impression that the service is loopback-only even though it is listening globally.

Attack Path

  1. A user runs the generated start_comfyui.sh.
  2. ComfyUI listens on port 8188 across all host interfaces.
  3. A remote party on a reachable local, container, VPN, cloud, or public network discovers the open port.
  4. The party calls available ComfyUI API endpoints without authentication.
  5. The party submits workflows, queries service or history data, retrieves accessible outputs, or causes expensive generation jobs.
  6. If the inst ...[truncated 750 chars]
Remediation
View remediation

Remediation Suggestions

  1. Bind to 127.0.0.1 by default:
    bash
    python main.py --listen 127.0.0.1 --port 8188 --highvram --fp32-vae
    
  2. Require an explicit configuration option before permitting non-loopback access.
  3. For remote use, place ComfyUI behind an authenticated reverse proxy with TLS and strict request-size and rate limits.
  4. Restrict port 8188 using host and cloud firewalls to specifically authorized source addresses.
  5. Isolate ComfyUI in a dedicated container or unprivileged account with minimal host mounts.
  6. Ensure documentation clearly distinguishes loopback-only, container-accessible, and remotely accessible deployments.
  7. Add a startup warning when the configured listener is not loopback and no authentication gateway is configured.

T09 · Insecure Skill Coding Practices

Note
Location
TROUBLESHOOTING.md:48
Finding

Troubleshooting Guidance Deletes All Main-Agent Session State

Content
View full analysis

Vulnerability Details

File Location: TROUBLESHOOTING.md:48-53
Vulnerability Type: Overly broad destructive file operation
Risk Level: Low

Vulnerable Code

bash
mkdir -p ~/.openclaw/workspace/archive
mv ~/.openclaw/workspace/*.log ~/.openclaw/workspace/archive/ 2>/dev/null
cp -r ~/.openclaw/agents/main/sessions ~/.openclaw/agents/main/sessions.bak
rm -rf ~/.openclaw/agents/main/sessions/*
docker restart openclaw-gateway

Technical Analysis

The troubleshooting documentation recommends recursively deleting every entry in the main agent's session directory as a response to excessive token usage. The command is not scoped to this Skill, a particular painter session, a time range, or confirmed stale records.

A backup is attempted before deletion, which reduces but does not eliminate risk. The commands do not verify that the backup completed successfully, that sufficient space exists, that the source path is the intended installation, or that no active session is using the files. The use of rm -rf against a broad wildcard can disrupt unrelated agent activity.

Removing global main-agent session state is not necessary for the declared image-generation functionality and exceeds the minimum filesystem scope required by the Skill.

Attack Path

  1. A user experiences high token consumption and follows the documented cleanup procedure.
  2. The backup command fails partially or produces an incomplete copy, or the user does not recognize that unrelated sessions are included.
  3. The recursive deletion removes all files beneath ~/.openclaw/agents/main/sessions/.
  4. The gateway is restarted immediately afterward.
  5. Active or unrelated sessions lose their persisted state and may be unrecoverable if the backup is incomplete or later overwritten.

Impact Assessment

The operation can cause loss of conversation or session state for unrelated workloads, interruption of active agents, and opera ...[truncated 414 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the blanket deletion command from the default troubleshooting workflow.
  2. Identify and delete only stale sessions associated with the affected agent, using explicit IDs and an age threshold.
  3. Stop or quiesce the relevant agent before modifying active session state.
  4. Create a timestamped backup and verify its file count, size, readability, and available disk space before deletion.
  5. Use an interactive cleanup utility that displays candidate sessions and requests confirmation.
  6. Document a tested restoration command and warn clearly that session history may be lost.
  7. Prefer configuration changes, compaction, log rotation, and per-session archival over destructive global cleanup.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (57)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Advertising a full-featured image-generation system while actually persisting run-tracking data and omitting the claimed core capabilities is a material behavior mismatch. Undisclosed local persistence adds privacy risk, especially when paired with claims about remembering user preferences, because users may not realize data is being stored.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Advertising a full-featured image-generation system while actually persisting run-tracking data and omitting the claimed core capabilities is a material behavior mismatch. Undisclosed local persistence adds privacy risk, especially when paired with claims about remembering user preferences, because users may not realize data is being stored.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Advertising a full-featured image-generation system while actually persisting run-tracking data and omitting the claimed core capabilities is a material behavior mismatch. Undisclosed local persistence adds privacy risk, especially when paired with claims about remembering user preferences, because users may not realize data is being stored.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

Advertising a full-featured image-generation system while actually persisting run-tracking data and omitting the claimed core capabilities is a material behavior mismatch. Undisclosed local persistence adds privacy risk, especially when paired with claims about remembering user preferences, because users may not realize data is being stored.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Advertising a full-featured image-generation system while actually persisting run-tracking data and omitting the claimed core capabilities is a material behavior mismatch. Undisclosed local persistence adds privacy risk, especially when paired with claims about remembering user preferences, because users may not realize data is being stored.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Advertising a full-featured image-generation system while actually persisting run-tracking data and omitting the claimed core capabilities is a material behavior mismatch. Undisclosed local persistence adds privacy risk, especially when paired with claims about remembering user preferences, because users may not realize data is being stored.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

A broad trigger phrase like '画一张图' overlaps with normal conversation and can cause accidental activation. In a skill that may invoke shell, network, filesystem, or setup behavior, unintended triggering materially increases the risk of unplanned actions, resource consumption, or execution in the wrong context.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
94% confidence
Finding

rm -rf ~/.openclaw/agents/main/sessions/* performs irreversible recursive deletion using a wildcard in a persistent application directory. In a troubleshooting document for an agent system, users may run it without inspection; if path expansion behaves unexpectedly, if the directory is symlinked, or if needed session records are removed, this can cause significant data loss and hinder investigation or rollback.

Content

Scanner excerpt · TROUBLESHOOTING.md (reported line 52)May include surrounding context.

mkdir -p ~/.openclaw/workspace/archive mv ~/.openclaw/workspace/.log ~/.openclaw/workspace/archive/ 2>/dev/null cp -r ~/.openclaw/agents/main/sessions ~/.openclaw/agents/main/sessions.bak rm -rf ~/.openclaw/agents/main/sessions/ docker restart openclaw-gateway

text

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
94% confidence
Finding

rm -rf ~/.openclaw/agents/main/sessions/* performs irreversible recursive deletion using a wildcard in a persistent application directory. In a troubleshooting document for an agent system, users may run it without inspection; if path expansion behaves unexpectedly, if the directory is symlinked, or if needed session records are removed, this can cause significant data loss and hinder investigation or rollback.

Content

Scanner excerpt · TROUBLESHOOTING.md (reported line 52)May include surrounding context.

mkdir -p ~/.openclaw/workspace/archive mv ~/.openclaw/workspace/.log ~/.openclaw/workspace/archive/ 2>/dev/null cp -r ~/.openclaw/agents/main/sessions ~/.openclaw/agents/main/sessions.bak rm -rf ~/.openclaw/agents/main/sessions/ docker restart openclaw-gateway

text

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
91% confidence
Finding

The command deletes all .svg files in the workspace via wildcard with no review or confirmation. In this skill context, the workspace likely contains user-generated image artifacts, so broad deletion can remove legitimate outputs or evidence needed for debugging.

Content

Scanner excerpt · TROUBLESHOOTING.md (reported line 122)May include surrounding context.

md
cp /home/node/.openclaw/agents/painter/agent/SOUL.md \
   /home/node/.openclaw/workspace-painter/SOUL.md
# 清理垃圾文件
rm -f /home/node/.openclaw/workspace-painter/*.svg
rm -f /home/node/.openclaw/workspace-painter/*.py
rm -f /home/node/.openclaw/workspace-painter/cyberpunk_cat.*
docker restart openclaw-gateway

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
92% confidence
Finding

Deleting all .py files from the workspace with a wildcard is risky because it can erase user scripts, diagnostic tooling, or other legitimate files placed there. The troubleshooting text frames them as 'garbage files' without requiring validation, which increases the chance of over-deletion.

Content

Scanner excerpt · TROUBLESHOOTING.md (reported line 123)May include surrounding context.

/home/node/.openclaw/workspace-painter/SOUL.md

清理垃圾文件

rm -f /home/node/.openclaw/workspace-painter/.svg rm -f /home/node/.openclaw/workspace-painter/.py rm -f /home/node/.openclaw/workspace-painter/cyberpunk_cat.* docker restart openclaw-gateway

text

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
88% confidence
Finding

rm -f /home/node/.openclaw/workspace-painter/cyberpunk_cat.* removes any file with that prefix regardless of extension, which may include outputs or unrelated files sharing the basename. The use of a wildcard in a user/workspace path makes accidental deletion plausible, especially when operators copy commands verbatim.

Content

Scanner excerpt · TROUBLESHOOTING.md (reported line 124)May include surrounding context.

清理垃圾文件

rm -f /home/node/.openclaw/workspace-painter/.svg rm -f /home/node/.openclaw/workspace-painter/.py rm -f /home/node/.openclaw/workspace-painter/cyberpunk_cat.* docker restart openclaw-gateway

text

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script invokes 'docker exec' and 'docker restart' against the gateway container, giving the skill package the ability to modify runtime configuration and disrupt or reconfigure a central service. In the context of an image-generation skill, these container-management capabilities exceed expected privileges and could be abused to change models, degrade availability, or enable broader compromise if an operator runs the script on the host.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill metadata describes an image-generation capability, but the actual skill implements image review, local file inspection, and logging. This mismatch can cause the agent or user to invoke a skill under false expectations, increasing the chance of unintended access to prior outputs and execution of side-effecting actions that were not clearly disclosed.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · tools/paint-dispatch.sh (reported line 59)May include surrounding context.

sh
# Step 1.5: 校验 checkpoint 是否可用,不可用则回退到 ComfyUI 当前可用的第一个模型
if [ -n "$CHECKPOINT" ]; then
    AVAILABLE_CKPT=$(
        curl -s --connect-timeout 5 http://host.docker.internal:8188/object_info/CheckpointLoaderSimple \
        | python3 -c "import json,sys; d=json.load(sys.stdin); arr=d.get('CheckpointLoaderSimple',{}).get('input',{}).get('required',{}).get('ckpt_name',[[]])[0]; print(','.join(arr) if isinstance(arr,list) else '')" \
        2>/dev/null || true
    )

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The README says users can generate images by speaking Chinese and repeatedly describes the flow as understanding Chinese input and converting it to English prompts. This presents a language-specific usage expectation without an explicit opt-in, alternative language support, or justification for the locale constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README explicitly advertises preference memory and run tracking, which implies storage of user prompts, preferences, and possibly generated-image metadata, but it provides no notice about what is stored, where it is stored, retention, or how users can delete it. In a skill that processes natural-language requests and potentially sensitive creative prompts, this creates a real privacy and compliance risk because users may unknowingly disclose personal or confidential information that is then persisted.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill advertises operational capabilities that imply access to environment variables, networking, shell execution, and filesystem changes, but it does not declare any explicit tool scope or permissions. This creates a transparency and containment problem: users and the platform cannot easily constrain what the skill may do, increasing the chance of unexpected system modification or data exposure during setup or runtime.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill description specifies “你说中文需求 → 自动生成英文 prompt,” indicating a Chinese-only input expectation without any stated user opt-in or language-choice mechanism. This is a natural-language policy concern because it constrains the interaction language by default rather than offering a locale choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill says it records user aesthetic preferences but gives no notice about retention, storage, sharing, or deletion controls. Preference data can reveal personal tastes and usage patterns, and undisclosed persistence undermines informed consent and creates avoidable privacy risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The usage examples suggest the skill can be activated through broad, ordinary natural-language requests without clearly stating limits, confirmation steps, or side effects. This can mislead users into triggering the skill unintentionally or invoking actions without understanding that local services, files, or external components may be used.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The troubleshooting guide instructs users to move logs, back up sessions, and then recursively delete all current session contents, but it does not clearly warn that this will erase active conversational state and potentially unrecoverable data if the backup step fails or is skipped. In an agent skill context, operators may copy-paste commands directly, so omission of a prominent data-loss warning materially increases the chance of destructive misuse.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
74% confidence
Finding

The session cleanup sequence explicitly manipulates persistent workspace and session directories, including copying and then deleting stored session data. In this context, persistence handling is risky because it normalizes direct operator access to agent state and can destroy auditability, recovery capability, and prior conversation data.

Content

Scanner excerpt · TROUBLESHOOTING.md (reported line 49)May include surrounding context.

清理workspace和session:

bash
mkdir -p ~/.openclaw/workspace/archive
mv ~/.openclaw/workspace/*.log ~/.openclaw/workspace/archive/ 2>/dev/null
cp -r ~/.openclaw/agents/main/sessions ~/.openclaw/agents/main/sessions.bak
rm -rf ~/.openclaw/agents/main/sessions/*

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

These instructions overwrite SOUL.md and delete matching files in the workspace without a clear warning that user customizations, generated artifacts, or debugging evidence may be lost. Because this is presented as a routine fix for agent behavior, users are likely to execute it verbatim, making accidental data loss a realistic outcome.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The natural-language description and all operating instructions are written entirely in Chinese, and there is no indication that the skill supports other languages or asks the user for language preference. Under the policy, a skill that effectively enforces a specific language without opt-in is a locale-policy violation unless the restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.destructive_delete_command

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
TROUBLESHOOTING.md:52