T09 · Insecure Skill Coding Practices
- Location
foodphotographygenerator.js:18- Finding
API Token Exposure Through Command-Line Arguments
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears to generate food images as advertised, but it needs review because it handles API tokens unsafely and uses broad, mutable installation and execution paths.
Review before installing. Use a minimally privileged API token, avoid putting secrets directly in commands where they may be logged, and prefer installing from a pinned, reviewed version or checksum if available. Do not submit confidential recipes, customer data, or proprietary campaign details unless you are comfortable sending them to the external image-generation provider.
foodphotographygenerator.js:18API Token Exposure Through Command-Line Arguments
SKILL.md:30Unpinned Remote Package Execution in Installation Instructions
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The README instructs users to submit free-form prompts and optional reference-image identifiers to an external image-generation API, but it does not clearly warn that this content leaves the local environment and is processed by a third party. In this skill context, prompts may contain unpublished recipes, campaign plans, customer data, or proprietary visual concepts, so the omission creates a real privacy and data-handling risk through uninformed disclosure.
The skill declares only tools: Bash and omits any explicit permissions or allowed-tools scope, even though the documented workflow requires outbound network access to the Neta API. Without clear tool scoping, an agent runtime may grant broader shell/network capability than necessary, increasing the risk of unintended external access or abuse if the script or prompt handling is compromised.
The invocation rule, 'Use when someone asks to generate or create ai food photography generator images,' is broad and underspecified, which can cause the agent to invoke this skill in loosely related image-generation requests. In a skill that accepts tokens and uses networked image generation, overbroad triggering can lead to unnecessary external API calls, data leakage in prompts, or unintended spending.
The install command uses npx skills add blammectrappora/food-photography-generator without pinning a version or immutable reference. This creates a supply-chain risk: a later malicious or compromised package update could be pulled automatically by users or agents, changing the skill behavior without review.
The skill metadata and user-facing description claim it uses the Neta AI API, but the implementation sends prompts and tokens to TalesOfAI endpoints with custom headers. This mismatch is security-relevant because users may disclose API credentials and prompts under false assumptions about the receiving service, defeating informed consent and supply-chain transparency.
The hardcoded TalesOfAI base URL confirms that user data leaves the local environment and is sent to a third-party API. In isolation this is normal for SaaS-backed image generation, but within this skill it is risky because the external service conflicts with the advertised provider, making the transmission deceptive in context.
console.error(`→ Submitting prompt (${dims.width}×${dims.height})...`);
const submitRes = await fetch('https://api.talesofai.com/v3/make_image', {
method: 'POST',
headers,
body: JSON.stringify(body),
The hardcoded TalesOfAI base URL confirms that user data leaves the local environment and is sent to a third-party API. In isolation this is normal for SaaS-backed image generation, but within this skill it is risky because the external service conflicts with the advertised provider, making the transmission deceptive in context.
console.error(`→ Submitting prompt (${dims.width}×${dims.height})...`);
const submitRes = await fetch('https://api.talesofai.com/v3/make_image', {
method: 'POST',
headers,
body: JSON.stringify(body),
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
for (let attempt = 0; attempt < 90; attempt++) {
await new Promise((r) => setTimeout(r, 2000));
const pollRes = await fetch(`https://api.talesofai.com/v1/artifact/task/${taskUuid}`, {
method: 'GET',
headers,
});
No suspicious patterns detected.