Back to skill

Security audit

Pet Memorial Portrait Generator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent cloud image-generation helper for pet memorial portraits, with notable but disclosed risks around sending prompts and tokens to an external service.

Before installing, verify that you trust the Neta/talesofai service and avoid putting sensitive personal details in prompts unless you are comfortable sending them to that provider. Use a safer token mechanism if possible, such as an environment variable, and prefer pinned or reviewed installation sources over the unversioned npx command.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
petmemorialportraitgenerator.js:14
Finding

API Token Exposed Through Command-Line Arguments

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:9
Finding

Unpinned Third-Party Installer and Mutable Skill Source

Content
View full analysis
Remediation
View remediation
add @ ``` The placeholders should be replaced with actual reviewed values, and the installer should verify the downloaded Skill against a published digest or signature. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The static finding indicates the implemented behavior diverges materially from the declared purpose: it may use a different service than advertised, accepts arbitrary prompts beyond memorial portraits, and supports reference-based inheritance/editing that is not disclosed. This mismatch is dangerous because users and reviewers may grant trust or credentials based on a benign description while the code exercises broader capabilities than expected.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README encourages users to submit pet descriptions and optional reference-image identifiers to an external image-generation API but does not clearly disclose that this data leaves the local environment. In this memorial context, prompts may contain sensitive emotional content, names, and potentially identifying details, so lack of transparency can cause unintentional privacy exposure and informed-consent failures.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill declares only tools: Bash and does not disclose or constrain its network behavior through explicit tool scope such as permissions or allowed-tools. Because the skill is designed to call an external image API, this omission reduces transparency and can allow broader-than-expected outbound access, making review and enforcement harder.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs users to pass an API token on the command line, which can expose credentials through shell history, process listings, logs, or telemetry. In an agent or shared environment, this increases the chance of credential leakage and unauthorized API use.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The phrase "Use when someone asks to generate or create pet memorial portrait images" gives a very general activation condition and does not define boundaries, exclusions, or specific trigger phrases. Without negative examples or narrower context, the skill could be invoked for a wide range of ordinary memorial-art requests unintentionally.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
81% confidence
Finding

The install instruction uses npx skills add blammectrappora/pet-memorial-portrait-generator without pinning a version, so consumers may fetch changed code over time. This creates supply-chain risk because a later malicious or compromised release could be installed implicitly without review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script transmits the user's prompt, optional reference identifier, and token to a remote API without any in-script disclosure beyond requiring a token. In a skill context, this is risky because users may reasonably assume local processing or the advertised provider, while sensitive memorial text or account tokens are sent off-device to a third party.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The hardcoded use of https://api.talesofai.com at the image creation step confirms outbound data flow to an external domain. On its own this would be normal for a cloud image service, but in this skill it becomes dangerous due to the provider mismatch and the inclusion of authentication material in headers.

Content

Scanner excerpt · petmemorialportraitgenerator.js (reported line 41)May include surrounding context.

js
body.inherit_params = { collection_uuid: ref, picture_uuid: ref };
  }

  const res = await fetch("https://api.talesofai.com/v3/make_image", {
    method: "POST",
    headers: {
      "x-token": token,

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The hardcoded use of https://api.talesofai.com at the image creation step confirms outbound data flow to an external domain. On its own this would be normal for a cloud image service, but in this skill it becomes dangerous due to the provider mismatch and the inclusion of authentication material in headers.

Content

Scanner excerpt · petmemorialportraitgenerator.js (reported line 41)May include surrounding context.

js
body.inherit_params = { collection_uuid: ref, picture_uuid: ref };
  }

  const res = await fetch("https://api.talesofai.com/v3/make_image", {
    method: "POST",
    headers: {
      "x-token": token,

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill metadata says it uses the Neta AI API, but the implementation actually sends the user's prompt and bearer-style token to api.talesofai.com with a mismatched x-platform value. That discrepancy is dangerous because it can mislead users into disclosing credentials and content to a different third party than advertised, undermining informed consent and creating a token exfiltration risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

The polling request repeatedly contacts the same external domain using the supplied token, extending the exposure window for credentials and linking task identifiers to the user's session. While polling is functionally normal, it still represents ongoing transmission to an unexpected third-party backend given the mismatch between the skill's description and code.

Content

Scanner excerpt · petmemorialportraitgenerator.js (reported line 68)May include surrounding context.

js
}

async function pollTask({ token, taskUuid }) {
  const url = `https://api.talesofai.com/v1/artifact/task/${taskUuid}`;
  for (let i = 0; i < 90; i++) {
    const res = await fetch(url, {
      headers: {

Static analysis

No suspicious patterns detected.