T05 · Unauthorized Access and Privilege Escalation
- Location
templates/codex-image-server.js:1203- Finding
Encoded Path Traversal Permits Unauthorized Local Image File Disclosure
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is mostly aligned with its image-server purpose, but its server template has under-disclosed remote OpenAI use and unsafe unauthenticated file-serving behavior that users should review before installing.
Review this skill before installing. Require an explicit backend choice, disable automatic OpenAI fallback unless intended, add authentication and an origin allowlist, bind only to loopback unless protected, fix decoded path traversal before serving files, and define cleanup/retention for generated and reference images.
templates/codex-image-server.js:1203Encoded Path Traversal Permits Unauthorized Local Image File Disclosure
templates/codex-image-server.js:96Unauthenticated Wildcard-CORS API Enables Cross-Origin Generation and Resource Abuse
Referenced artifact was not completely inspected
- Use `templates/codex-image-server.js` as a concrete Node server template when the target repo has no implementation.
The manifest frames the skill as turning local Codex image generation into a local HTTP server, but this code can instead call remote OpenAI image endpoints. That mismatch is security-relevant because users or integrators may assume local-only processing while prompts and reference images are actually transmitted off-host.
The skill directs the agent to inspect installations/repos, add an HTTP server, and run network-facing verification commands, but it does not declare any explicit tool scope or permissions. That mismatch weakens reviewability and least-privilege controls, increasing the chance that code, environment, or network access is used without clear user visibility.
The skill recommends making authentication optional by default for a local HTTP server without explaining the security tradeoffs. Even loopback services can be abused by other local processes, browser-based attacks against localhost, shared-machine users, containers, or port-forwarding/misbind mistakes, enabling unauthorized image generation or access to stored files.
The skill instructs storing generated files in a stable output directory and serving them back over HTTP, but provides no warning about persistence, retention, or exposure of potentially sensitive prompts/images. In image workflows, generated or reference images may contain proprietary or personal data, so persistent local serving can unintentionally disclose data to other local users, processes, or misconfigured clients.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Then test the consuming app:
curl -sS http://127.0.0.1:17341/v1/capabilities
curl -sS -m 3 http://127.0.0.1:17341/v1/images/generate \
-H 'Content-Type: application/json' \
-d '{"prompt":"cancel test","count":4,"size":"1024x1024","quality":"low"}' || true
The skill is configured for implicit invocation and uses a generic default prompt to add a local HTTP image server, which creates a broad activation surface without strong user-intent constraints. Because it exposes local server functionality, accidental or context-inappropriate invocation could lead an agent to modify a project to open network-facing routes or introduce unsafe HTTP endpoints without sufficiently explicit user confirmation.
This markdown file describes a POST request that includes a base64-encoded image payload in the references field, which is user data that may be sensitive. The contract does not include any warning or disclosure about sending image contents to the service, retention, or privacy implications, so users lack notice about a data-affecting behavior.
Multiple user-facing strings, validation errors, and capability labels are fixed in Chinese, which can force a specific language experience on users regardless of their preferences. The file does not provide language selection, opt-in, or a documented region-specific justification for the locale constraint.
The file reads API credentials from environment variables and uses them to select a remote OpenAI backend, which expands the trust boundary beyond a purely local HTTP image server. This can cause prompts and reference images to leave the local machine unexpectedly, especially because backend selection defaults to OpenAI whenever a key is present.
When the OpenAI backend is used, user prompts and reference images are sent to a remote API with no in-file disclosure or consent mechanism. In a local image-server context, this is dangerous because users may pass sensitive internal artwork or prompts under the assumption that processing stays on the local machine.
The code contains direct transmission to https://api.openai.com for image generation and editing, meaning prompts and reference images can be exfiltrated to an external service. In the context of a supposedly local image server, that external transmission materially increases privacy and compliance risk.
}
const hasReferences = Array.isArray(body.references) && body.references.length > 0
const endpoint = hasReferences ? 'https://api.openai.com/v1/images/edits' : 'https://api.openai.com/v1/images/generations'
let payload
if (hasReferences) {
The response example hard-codes the label 生成图, which implies a specific language output in natural-language content. There is no indication that the user can choose the language or that the API is intentionally locale-specific, which conflicts with the policy against forcing a language without opt-in.
The skill accesses sensitive credentials via CODEX_IMAGE_SERVER_OPENAI_API_KEY or OPENAI_API_KEY. This file does not include a user-facing warning, comment, or other disclosure explaining that sensitive environment variables are consumed for external API access.
The stated purpose is to expose image generation over local HTTP, but the implementation achieves this by launching a separate codex process and managing its lifecycle. While related to the feature, subprocess execution is a materially broader capability than the manifest describes and may matter to users evaluating operational risk.
Detected: suspicious.dangerous_exec, suspicious.env_credential_access