T09 · Insecure Skill Coding Practices
- Location
mechaartgenerator.js:20- Finding
API Token Exposure Through Command-Line Arguments
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a simple external image-generation client, with caution needed around API-token handling and the unpinned install command.
Before installing, confirm you are comfortable sending image prompts, optional reference UUIDs, and a Neta/TalesOfAI API token to the external service. Prefer ClawHub or a pinned installer over the unpinned npx command, and avoid placing real tokens directly in shell commands when possible.
mechaartgenerator.js:20API Token Exposure Through Command-Line Arguments
README.md:18Unpinned Third-Party Package Execution During Installation
The declared behavior says the skill uses the Neta API, but the analyzed behavior indicates it actually talks to a different backend/service and uses inconsistent external endpoints. This mismatch is dangerous because it defeats user trust and consent boundaries: tokens, prompts, and possibly reference-image identifiers may be sent to an undeclared third party, which is a strong indicator of deceptive or covert exfiltration behavior.
The README says the skill is powered by an external API but does not clearly warn users that their prompts and reference-image UUIDs are transmitted to a third-party service. This creates a privacy and data-handling risk because users may submit sensitive prompts, proprietary concepts, or identifiers without understanding that the data leaves the local environment.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
| — |
| Size | Dimensions |
|---|---|
square | 1024 × 1024 |
portrait | 832 × 1216 |
landscape | 1216 × 832 |
tall | 704 × 1408 |
A Neta API token is required. Pass it on every invocation via the --token flag:
node mechaartgenerator.js "a fierce red mecha in combat" --token YOUR_TOKEN
You can keep your token in a shell variable for convenience:
node mechaartgenerator.js "a fierce red mecha in combat" --token "$NETA_TOKEN"
This skill requires a Neta API token (free trial available at https://www.neta.art/open/).
The skill declares only the Bash tool and does not define any explicit tool scope or allowed-tools restrictions despite requiring outbound API access. In practice, this means the runtime may permit broader behavior than users expect, increasing the risk that the skill performs uncontrolled network operations or additional shell actions beyond simple image generation.
The activation description says to use the skill when someone asks to "generate or create mecha anime art generator images," which is loosely phrased and does not clearly distinguish this skill from other generic image-generation requests. It also provides no negative examples or boundary conditions for when the skill should not activate.
Using npx skills add blammectrappora/mecha-art-generator without a pinned version allows the installed package or fetched content to change over time. This creates a supply-chain risk where a later malicious or compromised upstream release could be pulled automatically and executed by users without review.
The skill metadata and help text claim to use the Neta AI API, but the implementation actually sends the supplied token, prompt, and optional reference UUID to api.talesofai.com with different branding headers. This mismatch is a real trust-boundary violation because users may disclose credentials and content under false assumptions about the recipient service, and a disguised backend can enable credential harvesting or unauthorized third-party data sharing.
This POST transmits the user's API token in the x-token header and sends the prompt plus optional reference identifiers to an external host that does not match the advertised provider. In the context of an agent skill, that is dangerous because users may unknowingly leak credentials, creative inputs, and reference linkage data to an undisclosed third party.
body.inherit_params = { collection_uuid: ref, picture_uuid: ref };
}
const res = await fetch(`https://api.talesofai.com/v3/make_image`, {
method: 'POST',
headers: {
'x-token': token,
The polling request repeatedly sends the same API token to the external service for up to 90 attempts, expanding the exposure window and reinforcing reliance on the undisclosed backend. While it mainly retrieves task status, it still discloses credentials and task linkage information to the third party and compounds the risk created by the provider mismatch.
async function pollTask({ token, taskUuid }) {
for (let attempt = 0; attempt < 90; attempt++) {
const res = await fetch(`https://api.talesofai.com/v1/artifact/task/${taskUuid}`, {
method: 'GET',
headers: {
'x-token': token,
No suspicious patterns detected.