Back to skill

Security audit

Mecha Art Generator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a simple external image-generation client, with caution needed around API-token handling and the unpinned install command.

Before installing, confirm you are comfortable sending image prompts, optional reference UUIDs, and a Neta/TalesOfAI API token to the external service. Prefer ClawHub or a pinned installer over the unpinned npx command, and avoid placing real tokens directly in shell commands when possible.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
mechaartgenerator.js:20
Finding

API Token Exposure Through Command-Line Arguments

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:18
Finding

Unpinned Third-Party Package Execution During Installation

Content
View full analysis
Remediation
View remediation
add blammectrappora/mecha-art-generator ``` 2. Document the expected package publisher, registry, version, and cryptographic integrity information. 3. Prefer a previously installed and organization-approved CLI rather than downloading executable code at invocation time. 4. Use lockfiles or another reproducible installation mechanism where applicable. 5. Review the pinned package and its transitive dependencies before recommending it. 6. Avoid running the installation command with administrator or root privileges. 7. Provide a manual installation method that retrieves a versioned artifact and verifies its checksum or signature before use. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared behavior says the skill uses the Neta API, but the analyzed behavior indicates it actually talks to a different backend/service and uses inconsistent external endpoints. This mismatch is dangerous because it defeats user trust and consent boundaries: tokens, prompts, and possibly reference-image identifiers may be sent to an undeclared third party, which is a strong indicator of deceptive or covert exfiltration behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README says the skill is powered by an external API but does not clearly warn users that their prompts and reference-image UUIDs are transmitted to a third-party service. This creates a privacy and data-handling risk because users may submit sensitive prompts, proprietary concepts, or identifiers without understanding that the data leaves the local environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

YARA rule 'network_reconnaissance': Network reconnaissance and scanning patterns [hacktools]

Medium
Category
YARA Match
Confidence
65% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · README.md (reported line 80)May include surrounding context.

| — |

Sizes

SizeDimensions
square1024 × 1024
portrait832 × 1216
landscape1216 × 832
tall704 × 1408

Token setup

A Neta API token is required. Pass it on every invocation via the --token flag:

bash
node mechaartgenerator.js "a fierce red mecha in combat" --token YOUR_TOKEN

You can keep your token in a shell variable for convenience:

bash
node mechaartgenerator.js "a fierce red mecha in combat" --token "$NETA_TOKEN"

This skill requires a Neta API token (free trial available at https://www.neta.art/open/).

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares only the Bash tool and does not define any explicit tool scope or allowed-tools restrictions despite requiring outbound API access. In practice, this means the runtime may permit broader behavior than users expect, increasing the risk that the skill performs uncontrolled network operations or additional shell actions beyond simple image generation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation description says to use the skill when someone asks to "generate or create mecha anime art generator images," which is loosely phrased and does not clearly distinguish this skill from other generic image-generation requests. It also provides no negative examples or boundary conditions for when the skill should not activate.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
83% confidence
Finding

Using npx skills add blammectrappora/mecha-art-generator without a pinned version allows the installed package or fetched content to change over time. This creates a supply-chain risk where a later malicious or compromised upstream release could be pulled automatically and executed by users without review.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill metadata and help text claim to use the Neta AI API, but the implementation actually sends the supplied token, prompt, and optional reference UUID to api.talesofai.com with different branding headers. This mismatch is a real trust-boundary violation because users may disclose credentials and content under false assumptions about the recipient service, and a disguised backend can enable credential harvesting or unauthorized third-party data sharing.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

This POST transmits the user's API token in the x-token header and sends the prompt plus optional reference identifiers to an external host that does not match the advertised provider. In the context of an agent skill, that is dangerous because users may unknowingly leak credentials, creative inputs, and reference linkage data to an undisclosed third party.

Content

Scanner excerpt · mechaartgenerator.js (reported line 64)May include surrounding context.

js
body.inherit_params = { collection_uuid: ref, picture_uuid: ref };
  }

  const res = await fetch(`https://api.talesofai.com/v3/make_image`, {
    method: 'POST',
    headers: {
      'x-token': token,

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The polling request repeatedly sends the same API token to the external service for up to 90 attempts, expanding the exposure window and reinforcing reliance on the undisclosed backend. While it mainly retrieves task status, it still discloses credentials and task linkage information to the third party and compounds the risk created by the provider mismatch.

Content

Scanner excerpt · mechaartgenerator.js (reported line 100)May include surrounding context.

js
async function pollTask({ token, taskUuid }) {
  for (let attempt = 0; attempt < 90; attempt++) {
    const res = await fetch(`https://api.talesofai.com/v1/artifact/task/${taskUuid}`, {
      method: 'GET',
      headers: {
        'x-token': token,

Static analysis

No suspicious patterns detected.