T09 · Insecure Skill Coding Practices
- Location
petmemorialportraitgenerator.js:14- Finding
API Token Exposed Through Command-Line Arguments
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a coherent cloud image-generation helper for pet memorial portraits, with notable but disclosed risks around sending prompts and tokens to an external service.
Before installing, verify that you trust the Neta/talesofai service and avoid putting sensitive personal details in prompts unless you are comfortable sending them to that provider. Use a safer token mechanism if possible, such as an environment variable, and prefer pinned or reviewed installation sources over the unversioned npx command.
petmemorialportraitgenerator.js:14API Token Exposed Through Command-Line Arguments
README.md:9Unpinned Third-Party Installer and Mutable Skill Source
The static finding indicates the implemented behavior diverges materially from the declared purpose: it may use a different service than advertised, accepts arbitrary prompts beyond memorial portraits, and supports reference-based inheritance/editing that is not disclosed. This mismatch is dangerous because users and reviewers may grant trust or credentials based on a benign description while the code exercises broader capabilities than expected.
The README encourages users to submit pet descriptions and optional reference-image identifiers to an external image-generation API but does not clearly disclose that this data leaves the local environment. In this memorial context, prompts may contain sensitive emotional content, names, and potentially identifying details, so lack of transparency can cause unintentional privacy exposure and informed-consent failures.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The skill declares only tools: Bash and does not disclose or constrain its network behavior through explicit tool scope such as permissions or allowed-tools. Because the skill is designed to call an external image API, this omission reduces transparency and can allow broader-than-expected outbound access, making review and enforcement harder.
The skill instructs users to pass an API token on the command line, which can expose credentials through shell history, process listings, logs, or telemetry. In an agent or shared environment, this increases the chance of credential leakage and unauthorized API use.
The phrase "Use when someone asks to generate or create pet memorial portrait images" gives a very general activation condition and does not define boundaries, exclusions, or specific trigger phrases. Without negative examples or narrower context, the skill could be invoked for a wide range of ordinary memorial-art requests unintentionally.
The install instruction uses npx skills add blammectrappora/pet-memorial-portrait-generator without pinning a version, so consumers may fetch changed code over time. This creates supply-chain risk because a later malicious or compromised release could be installed implicitly without review.
The script transmits the user's prompt, optional reference identifier, and token to a remote API without any in-script disclosure beyond requiring a token. In a skill context, this is risky because users may reasonably assume local processing or the advertised provider, while sensitive memorial text or account tokens are sent off-device to a third party.
The hardcoded use of https://api.talesofai.com at the image creation step confirms outbound data flow to an external domain. On its own this would be normal for a cloud image service, but in this skill it becomes dangerous due to the provider mismatch and the inclusion of authentication material in headers.
body.inherit_params = { collection_uuid: ref, picture_uuid: ref };
}
const res = await fetch("https://api.talesofai.com/v3/make_image", {
method: "POST",
headers: {
"x-token": token,
The hardcoded use of https://api.talesofai.com at the image creation step confirms outbound data flow to an external domain. On its own this would be normal for a cloud image service, but in this skill it becomes dangerous due to the provider mismatch and the inclusion of authentication material in headers.
body.inherit_params = { collection_uuid: ref, picture_uuid: ref };
}
const res = await fetch("https://api.talesofai.com/v3/make_image", {
method: "POST",
headers: {
"x-token": token,
The skill metadata says it uses the Neta AI API, but the implementation actually sends the user's prompt and bearer-style token to api.talesofai.com with a mismatched x-platform value. That discrepancy is dangerous because it can mislead users into disclosing credentials and content to a different third party than advertised, undermining informed consent and creating a token exfiltration risk.
The polling request repeatedly contacts the same external domain using the supplied token, extending the exposure window for credentials and linking task identifiers to the user's session. While polling is functionally normal, it still represents ongoing transmission to an unexpected third-party backend given the mismatch between the skill's description and code.
}
async function pollTask({ token, taskUuid }) {
const url = `https://api.talesofai.com/v1/artifact/task/${taskUuid}`;
for (let i = 0; i < 90; i++) {
const res = await fetch(url, {
headers: {
No suspicious patterns detected.