Back to skill

Security audit

Steampunk Art Generator

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward Neta-based steampunk image generator, with manageable cautions around token handling and unpinned npx installation instructions.

Install through ClawHub or a pinned, trusted installer when possible. Use a dedicated Neta token with limited value, avoid pasting raw tokens into shell history, and rotate the token if it may have appeared in command logs or process monitoring.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:31
Finding

Unpinned Third-Party Package Execution Through npx

Content
View full analysis
Remediation
View remediation
add blammectrappora/steampunk-art-generator ``` 2. Verify the pinned package's provenance and integrity before recommending it. 3. Document the expected npm registry and advise users not to run the installation through an untrusted registry or proxy. 4. Prefer an installation method backed by a lockfile and integrity hashes where feasible. 5. Review new installer versions before changing the documented pinned version. 6. Warn users not to invoke installation commands with elevated privileges. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
steampunkartgenerator.js:10
Finding

API Token Exposed Through Command-Line Arguments

Content
View full analysis
). Pass it via the `--token` flag. ```bash node
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

The README instructs users to run npx skills add blammectrappora/steampunk-art-generator without pinning a specific package or version. This can cause users to fetch and execute whatever version is current at install time, increasing supply-chain risk if the package, dependency chain, or distribution channel is later compromised.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill explicitly uses Bash and instructs the user to invoke a Node-based generator that depends on an external API token, which implies network access, but it does not declare any tool scope such as allowed-tools or permissions. This creates an unnecessary trust gap: a consumer cannot tell from the manifest what external capabilities the skill may exercise, increasing the chance of unintended outbound requests or misuse of secrets.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

The installation command uses npx skills add blammectrappora/steampunk-art-generator without pinning a specific version or immutable reference. That allows whatever package or remote content is current at install time to be fetched and executed, exposing users to supply-chain compromise, typosquat/republication risk, or malicious updates after review.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · steampunkartgenerator.js (reported line 69)May include surrounding context.

js
};
  }

  const res = await fetch('https://api.talesofai.com/v3/make_image', {
    method: 'POST',
    headers: HEADERS,
    body: JSON.stringify(body),

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · steampunkartgenerator.js (reported line 69)May include surrounding context.

js
};
  }

  const res = await fetch('https://api.talesofai.com/v3/make_image', {
    method: 'POST',
    headers: HEADERS,
    body: JSON.stringify(body),

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · steampunkartgenerator.js (reported line 98)May include surrounding context.

js
};
  }

  const res = await fetch('https://api.talesofai.com/v3/make_image', {
    method: 'POST',
    headers: HEADERS,
    body: JSON.stringify(body),

Static analysis

No suspicious patterns detected.