Back to skill

Security audit

Food Photography Generator

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to generate food images as advertised, but it needs review because it handles API tokens unsafely and uses broad, mutable installation and execution paths.

Review before installing. Use a minimally privileged API token, avoid putting secrets directly in commands where they may be logged, and prefer installing from a pinned, reviewed version or checksum if available. Do not submit confidential recipes, customer data, or proprietary campaign details unless you are comfortable sending them to the external image-generation provider.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
foodphotographygenerator.js:18
Finding

API Token Exposure Through Command-Line Arguments

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:30
Finding

Unpinned Remote Package Execution in Installation Instructions

Content
View full analysis
Remediation
View remediation
add ... ``` 2. Pin the skill itself to an immutable release version or commit hash where the installer supports it. 3. Publish and verify cryptographic checksums or signatures for released skill artifacts. 4. Document the expected package publisher, source repository, version, and integrity digest. 5. Avoid installation commands that silently accept the newest remote executable package. 6. Review installer lifecycle behavior and transitive dependencies before recommending it. 7. In CI/CD, install from a lockfile-controlled or internally mirrored package source and use a minimally privileged account without unnecessary secrets. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README instructs users to submit free-form prompts and optional reference-image identifiers to an external image-generation API, but it does not clearly warn that this content leaves the local environment and is processed by a third party. In this skill context, prompts may contain unpublished recipes, campaign plans, customer data, or proprietary visual concepts, so the omission creates a real privacy and data-handling risk through uninformed disclosure.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill declares only tools: Bash and omits any explicit permissions or allowed-tools scope, even though the documented workflow requires outbound network access to the Neta API. Without clear tool scoping, an agent runtime may grant broader shell/network capability than necessary, increasing the risk of unintended external access or abuse if the script or prompt handling is compromised.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The invocation rule, 'Use when someone asks to generate or create ai food photography generator images,' is broad and underspecified, which can cause the agent to invoke this skill in loosely related image-generation requests. In a skill that accepts tokens and uses networked image generation, overbroad triggering can lead to unnecessary external API calls, data leakage in prompts, or unintended spending.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The install command uses npx skills add blammectrappora/food-photography-generator without pinning a version or immutable reference. This creates a supply-chain risk: a later malicious or compromised package update could be pulled automatically by users or agents, changing the skill behavior without review.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill metadata and user-facing description claim it uses the Neta AI API, but the implementation sends prompts and tokens to TalesOfAI endpoints with custom headers. This mismatch is security-relevant because users may disclose API credentials and prompts under false assumptions about the receiving service, defeating informed consent and supply-chain transparency.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The hardcoded TalesOfAI base URL confirms that user data leaves the local environment and is sent to a third-party API. In isolation this is normal for SaaS-backed image generation, but within this skill it is risky because the external service conflicts with the advertised provider, making the transmission deceptive in context.

Content

Scanner excerpt · foodphotographygenerator.js (reported line 74)May include surrounding context.

js
console.error(`→ Submitting prompt (${dims.width}×${dims.height})...`);

  const submitRes = await fetch('https://api.talesofai.com/v3/make_image', {
    method: 'POST',
    headers,
    body: JSON.stringify(body),

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The hardcoded TalesOfAI base URL confirms that user data leaves the local environment and is sent to a third-party API. In isolation this is normal for SaaS-backed image generation, but within this skill it is risky because the external service conflicts with the advertised provider, making the transmission deceptive in context.

Content

Scanner excerpt · foodphotographygenerator.js (reported line 74)May include surrounding context.

js
console.error(`→ Submitting prompt (${dims.width}×${dims.height})...`);

  const submitRes = await fetch('https://api.talesofai.com/v3/make_image', {
    method: 'POST',
    headers,
    body: JSON.stringify(body),

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · foodphotographygenerator.js (reported line 105)May include surrounding context.

js
for (let attempt = 0; attempt < 90; attempt++) {
    await new Promise((r) => setTimeout(r, 2000));
    const pollRes = await fetch(`https://api.talesofai.com/v1/artifact/task/${taskUuid}`, {
      method: 'GET',
      headers,
    });

Static analysis

No suspicious patterns detected.