Back to skill

Security audit

Miniature World Generator

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it claims, but users should understand it sends prompts and a token to an external image API and currently documents a less-safe token workflow.

Install only from a source/version you trust, avoid putting long-lived API tokens directly in shell history, and do not submit confidential prompts or reference identifiers unless you are comfortable sharing them with the Neta/TalesOfAI image service.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
miniatureworldgenerator.js:9
Finding

API Token Exposed Through Command-Line Arguments

Content
View full analysis
"your prompt" --token YOUR_TOKEN ``` ``` `README.md:25-31`: ```markdown Pass it via the `--token` flag: ```bash node
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:31
Finding

Unpinned Installation Commands Create Supply-Chain Exposure

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented behavior says the skill uses the Neta API, but the analysis indicates the implementation actually calls a different external service and supports reference-based generation not fully disclosed in the description. This mismatch is dangerous because users may provide prompts, tokens, or images under false assumptions about where data is sent and how it is processed, increasing privacy, trust, and data-handling risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README describes generating images through an external API but does not clearly warn users that their prompts, token, and any reference-image identifiers are transmitted to a third-party service. In a creative skill, prompts may contain sensitive or proprietary ideas, so the lack of an explicit privacy/data-sharing notice can lead to inadvertent disclosure.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
83% confidence
Finding

The README instructs users to install and run tooling via npx skills without pinning a specific version. That creates a supply-chain risk because users may fetch and execute whatever package/version is current at install time, including a compromised or typosquatted release.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares Bash usage and appears to require outbound network access to an external image API, but it does not restrict or declare tool scope with permissions or allowed-tools. That omission increases the attack surface because a consumer cannot easily tell what external actions the skill may perform, and a Bash-based implementation with implicit network capability can be repurposed for unintended exfiltration or arbitrary remote access.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
82% confidence
Finding

Using npx skills add blammectrappora/miniature-world-generator without a pinned version introduces supply-chain risk because the fetched package can change over time. An attacker who compromises the publisher account or a dependency path could cause users to install a different, potentially malicious version than the one originally reviewed.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This finding points to the hardcoded external destination itself. While contacting an external image API is expected for this skill, the mismatch between the advertised Neta AI service and the actual talesofai.com endpoint creates a supply-chain/trust issue: prompts, reference UUIDs, and authentication material are sent to a different service than users may expect.

Content

Scanner excerpt · miniatureworldgenerator.js (reported line 67)May include surrounding context.

js
};
  }

  const res = await fetch('https://api.talesofai.com/v3/make_image', {
    method: 'POST',
    headers: HEADERS,
    body: JSON.stringify(body),

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This finding points to the hardcoded external destination itself. While contacting an external image API is expected for this skill, the mismatch between the advertised Neta AI service and the actual talesofai.com endpoint creates a supply-chain/trust issue: prompts, reference UUIDs, and authentication material are sent to a different service than users may expect.

Content

Scanner excerpt · miniatureworldgenerator.js (reported line 67)May include surrounding context.

js
};
  }

  const res = await fetch('https://api.talesofai.com/v3/make_image', {
    method: 'POST',
    headers: HEADERS,
    body: JSON.stringify(body),

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · miniatureworldgenerator.js (reported line 95)May include surrounding context.

js
for (let attempt = 0; attempt < maxAttempts; attempt++) {
    await new Promise(r => setTimeout(r, 2000));

    const res = await fetch(`https://api.talesofai.com/v1/artifact/task/${taskUuid}`, {
      headers: HEADERS,
    });

Static analysis

No suspicious patterns detected.