Back to skill

Security audit

Codex Image Server

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly aligned with its image-server purpose, but its server template has under-disclosed remote OpenAI use and unsafe unauthenticated file-serving behavior that users should review before installing.

Review this skill before installing. Require an explicit backend choice, disable automatic OpenAI fallback unless intended, add authentication and an origin allowlist, bind only to loopback unless protected, fix decoded path traversal before serving files, and define cleanup/retention for generated and reference images.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
templates/codex-image-server.js:1203
Finding

Encoded Path Traversal Permits Unauthorized Local Image File Disclosure

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
templates/codex-image-server.js:96
Finding

Unauthenticated Wildcard-CORS API Enables Cross-Origin Generation and Resource Abuse

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (15)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

md
- Use `templates/codex-image-server.js` as a concrete Node server template when the target repo has no implementation.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest frames the skill as turning local Codex image generation into a local HTTP server, but this code can instead call remote OpenAI image endpoints. That mismatch is security-relevant because users or integrators may assume local-only processing while prompts and reference images are actually transmitted off-host.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill directs the agent to inspect installations/repos, add an HTTP server, and run network-facing verification commands, but it does not declare any explicit tool scope or permissions. That mismatch weakens reviewability and least-privilege controls, increasing the chance that code, environment, or network access is used without clear user visibility.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill recommends making authentication optional by default for a local HTTP server without explaining the security tradeoffs. Even loopback services can be abused by other local processes, browser-based attacks against localhost, shared-machine users, containers, or port-forwarding/misbind mistakes, enabling unauthorized image generation or access to stored files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs storing generated files in a stable output directory and serving them back over HTTP, but provides no warning about persistence, retention, or exposure of potentially sensitive prompts/images. In image workflows, generated or reference images may contain proprietary or personal data, so persistent local serving can unintentionally disclose data to other local users, processes, or misconfigured clients.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

Then test the consuming app:

bash
curl -sS http://127.0.0.1:17341/v1/capabilities
curl -sS -m 3 http://127.0.0.1:17341/v1/images/generate \
  -H 'Content-Type: application/json' \
  -d '{"prompt":"cancel test","count":4,"size":"1024x1024","quality":"low"}' || true

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill is configured for implicit invocation and uses a generic default prompt to add a local HTTP image server, which creates a broad activation surface without strong user-intent constraints. Because it exposes local server functionality, accidental or context-inappropriate invocation could lead an agent to modify a project to open network-facing routes or introduce unsafe HTTP endpoints without sufficiently explicit user confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file describes a POST request that includes a base64-encoded image payload in the references field, which is user data that may be sensitive. The contract does not include any warning or disclosure about sending image contents to the service, retention, or privacy implications, so users lack notice about a data-affecting behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Multiple user-facing strings, validation errors, and capability labels are fixed in Chinese, which can force a specific language experience on users regardless of their preferences. The file does not provide language selection, opt-in, or a documented region-specific justification for the locale constraint.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file reads API credentials from environment variables and uses them to select a remote OpenAI backend, which expands the trust boundary beyond a purely local HTTP image server. This can cause prompts and reference images to leave the local machine unexpectedly, especially because backend selection defaults to OpenAI whenever a key is present.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

When the OpenAI backend is used, user prompts and reference images are sent to a remote API with no in-file disclosure or consent mechanism. In a local image-server context, this is dangerous because users may pass sensitive internal artwork or prompts under the assumption that processing stays on the local machine.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

The code contains direct transmission to https://api.openai.com for image generation and editing, meaning prompts and reference images can be exfiltrated to an external service. In the context of a supposedly local image server, that external transmission materially increases privacy and compliance risk.

Content

Scanner excerpt · templates/codex-image-server.js (reported line 962)May include surrounding context.

js
}

  const hasReferences = Array.isArray(body.references) && body.references.length > 0
  const endpoint = hasReferences ? 'https://api.openai.com/v1/images/edits' : 'https://api.openai.com/v1/images/generations'
  let payload

  if (hasReferences) {

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The response example hard-codes the label 生成图, which implies a specific language output in natural-language content. There is no indication that the user can choose the language or that the API is intentionally locale-specific, which conflicts with the policy against forcing a language without opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill accesses sensitive credentials via CODEX_IMAGE_SERVER_OPENAI_API_KEY or OPENAI_API_KEY. This file does not include a user-facing warning, comment, or other disclosure explaining that sensitive environment variables are consumed for external API access.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The stated purpose is to expose image generation over local HTTP, but the implementation achieves this by launching a separate codex process and managing its lifecycle. While related to the feature, subprocess execution is a materially broader capability than the manifest describes and may matter to users evaluating operational risk.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
templates/codex-image-server.js:188

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
templates/codex-image-server.js:10