Back to skill

Security audit

Chinese Ink Painting Generator

Security checks for vulnerabilities and agentic risk

Overview

This image-generation skill is purpose-aligned, but it handles an API token only through command-line arguments and uses mutable install instructions, so users should review it before installing.

Install only if you are comfortable sending prompts, optional reference IDs, and your Neta token to the TalesOfAI/Neta service. Prefer a pinned or verified install source, avoid putting real tokens directly in shell commands where possible, and rotate the token if it may have been exposed in command history, logs, or process monitoring.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
README.md:7
Finding

Unpinned Third-Party Installer and Skill Source

Content
View full analysis

Vulnerability Details

File Location: README.md:7-15, SKILL.md:31-34
Vulnerability Type: Supply-chain risk caused by mutable, unverified third-party dependencies
Risk Level: Medium

Vulnerable Code

README.md:7-15:

bash
## Install

```bash
npx skills add blammectrappora/chinese-ink-painting-generator

Or with ClawHub:

bash
clawhub install chinese-ink-painting-generator
text

`SKILL.md:31-34`:

```bash
## Install
```bash
npx skills add blammectrappora/chinese-ink-painting-generator
text

### Technical Analysis

The documented installation command invokes the `skills` package through `npx` without specifying an immutable package version. The skill source is also identified by a mutable repository or registry name rather than a reviewed commit hash or version.

When the requested package is not already available locally, `npx` can download and execute the package currently published under that name. The project does not provide a lockfile, integrity hash, cryptographic signature, pinned installer version, or pinned skill revision. Consequently, the code executed by a future installation may differ from the artifact covered by this audit.

No malicious dependency is present in the audited artifact. Exploitation depends on compromise, replacement, or malicious modification of an upstream installer, package release, registry entry, or skill source.

### Attack Path

1. An attacker compromises the account, registry package, repository, or distribution infrastructure associated with the unpinned installer or skill.
2. The attacker publishes a modified release containing malicious installation logic or skill content.
3. A user follows the documented `npx skills add blammectrappora/chinese-ink-painting-generator` command.
4. `npx` resolves and runs the mutable package version available at installation time.
5. The malicious code executes with the permissions of the us
...[truncated 489 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin the skills installer to a reviewed, explicit version instead of allowing npx to resolve the latest release.
  • Pin the installed skill to an immutable version or commit hash.
  • Publish and verify cryptographic integrity hashes or signatures for released artifacts.
  • Use a lockfile or equivalent reproducible dependency manifest where supported.
  • Document a verification procedure that users can perform before installation.
  • Avoid recommending elevated privileges for installation, and execute installers in a restricted environment where practical.
  • Periodically review pinned dependencies and update them through a controlled security-review process.

T09 · Insecure Skill Coding Practices

Warning
Location
chineseinkpaintinggenerator.js:22
Finding

API Token Exposed Through Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: chineseinkpaintinggenerator.js:22-27, chineseinkpaintinggenerator.js:40-49, README.md:56-70
Vulnerability Type: Sensitive credential supplied through process arguments
Risk Level: Medium

Vulnerable Code

chineseinkpaintinggenerator.js:22-27:

javascript
const a = args[i];
if (a === '--size') {
  size = args[++i];
} else if (a === '--token') {
  tokenFlag = args[++i];
} else if (a === '--ref') {

chineseinkpaintinggenerator.js:40-49:

javascript
async function main() {
  const { prompt, size, tokenFlag, ref } = parseArgs(argv.slice(2));

  const TOKEN = tokenFlag;

  if (!TOKEN) {
    console.error('\n✗ Token required. Pass via: --token YOUR_TOKEN');
    console.error('  Get yours at: https://www.neta.art/open/');
    process.exit(1);
  }

README.md:56-70:

bash
## Token Setup

This skill requires a Neta API token. Get a free trial token at <https://www.neta.art/open/>.

Pass the token with the `--token` flag every time you invoke the script:

```bash
node chineseinkpaintinggenerator.js "ancient pine tree on a cliff" --token YOUR_TOKEN

You can keep your token in a shell variable and expand it at call time:

bash
node chineseinkpaintinggenerator.js "cranes flying over a lake at dawn" --token "$NETA_TOKEN"

The --token flag is the only way the script accepts a token.

text

### Technical Analysis

The application accepts the Neta API credential exclusively through the `--token` command-line argument. Command-line arguments may be exposed through process-inspection interfaces, diagnostic and monitoring tools, command auditing, process listings, and shell history.

Expanding an environment variable into the argument does not resolve the process-list exposure because the shell substitutes the variable value before starting Node.js. The process may remain active for approximately three minute
...[truncated 1328 chars]
Remediation
View remediation

Remediation Suggestions

  • Support reading the token from a dedicated environment variable such as NETA_TOKEN without placing its value in the command line.
  • Prefer a non-echoing interactive prompt or standard input for manual use.
  • Support a protected configuration or credential file with restrictive filesystem permissions where appropriate.
  • If --token remains available for compatibility, document its process-list and shell-history exposure clearly.
  • Establish a precedence order such as protected credential storage, environment variable, interactive input, and finally the deprecated command-line flag.
  • Never include token values in errors, diagnostics, telemetry, or debug output.
  • Document token rotation and revocation procedures for users who suspect exposure.
  • Consider using short-lived, narrowly scoped API credentials where the service supports them.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README instructs users to pass prompts and an API token to an external image-generation service but does not clearly warn that both the prompt contents and credential are transmitted off-host. This omission can cause users to unknowingly send sensitive creative content, personal data, or secrets in prompts to a third party, increasing privacy and credential-handling risk in a skill specifically designed to proxy user input to a remote API.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares only the Bash tool and does not explicitly scope or disclose its network behavior, yet the documented usage clearly sends prompts and tokens to an external Neta API. This creates a transparency and least-privilege problem: users and hosting platforms may not realize the skill exfiltrates user input and credentials over the network, increasing the chance of unsafe execution in environments that expect local-only behavior.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

The installation command uses an unpinned npx skills reference, which can resolve to whatever package/version is current at execution time. This exposes users to supply-chain risk, where a compromised or malicious updated package could execute arbitrary code during install or skill retrieval.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script accepts an API token via the --token command-line argument and then sends it in request headers. Command-line arguments are commonly exposed through shell history, process listings, CI logs, and telemetry, which can leak the credential to other local users or logging systems.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · chineseinkpaintinggenerator.js (reported line 83)May include surrounding context.

js
let submitRes;
  try {
    submitRes = await fetch('https://api.talesofai.com/v3/make_image', {
      method: 'POST',
      headers,
      body: JSON.stringify(body),

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · chineseinkpaintinggenerator.js (reported line 83)May include surrounding context.

js
let submitRes;
  try {
    submitRes = await fetch('https://api.talesofai.com/v3/make_image', {
      method: 'POST',
      headers,
      body: JSON.stringify(body),

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · chineseinkpaintinggenerator.js (reported line 119)May include surrounding context.

js
let submitRes;
  try {
    submitRes = await fetch('https://api.talesofai.com/v3/make_image', {
      method: 'POST',
      headers,
      body: JSON.stringify(body),

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The README presents the skill as generating only traditional Chinese ink painting and related East Asian styles, without indicating whether users can choose other language or locale conventions. This can be a natural-language policy concern when a skill imposes a specific cultural or locale framing without opt-in or clarification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The default prompt forces a 'traditional Chinese ink painting' and related 'oriental aesthetic' style whenever no prompt is supplied. This imposes a specific locale/cultural output mode by default rather than offering a neutral default or explicit user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The package description explicitly frames the skill as a 'Chinese Ink Painting Generator,' which imposes a specific cultural/language context without any indication of user choice or a documented region-specific justification. Under the policy, locale-specific constraints should either be optional or clearly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.