Back to skill

Security audit

Image Forge

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly performs disclosed image generation, but it needs Review because some bundled prompt templates can steer the agent outside image generation and one backend can forward credentials and images to any configured URL.

Install only if you are comfortable sending prompts and selected reference images to the configured GPT/Gemini/CRS backends. Before broad use, remove or quarantine reference prompts that perform agent workflows, visible passport/ID verification imagery, or personal profiling; pin dependencies; and restrict CRS_BASE_URL to an approved HTTPS host or local loopback service.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
references/app-web-design.json:1
Finding

Untrusted reference prompt can hijack Agent behavior

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/gpt_image2.py:2
Finding

Runtime dependencies are not reproducibly pinned

Content
View full analysis
=2.28.0"] # /// ``` `scripts/generate_image.py:2-7`: ```python # /// script # dependencies = [ # "google-genai>=1.0.0", # "pillow>=10.0.0", # ] # /// ``` `scripts/reverse_style.py:2-6`: ```python # /// script # dependencies = [ # "google-genai>=1.0.0", # ] # /// ``` The documented execution pattern in `SKILL.md` invokes these scripts through `uv run`: ```bash uv run {baseDir}/scripts/gpt_image2.py generate \ --prompt "" \ --output /path/out.png \ --size 1536x1024 \ --quality high ``` ```bash uv run {baseDir}/scripts/generate_image.py \ --prompt "" \ --filename "~/.openclaw/workspace/tmp/image-forge/$(date +%Y-%m-%d-%H-%M-%S)-.png" \ --aspect-ratio "<1:1|3:4|4:3|9:16|16:9>" ``` ### Technical Analysis The inline dependency declarations specify only minimum versions. They do not impose exact versions, hashes, or an upper compatibility boundary. When `uv run` resolves the script environment, a later package version satisfying the constraint can be installed and executed even though that version was not part of the audited project. These dependencies execute in the same process context as the Skill scripts. In particular: - `requests` executes while the CRS API credential is in the process environment. - `google-genai` executes while a Gemini API key and user-selected images are available. - Pillow parses attacker-influenced or user-provided image files. The issue is not evidence that the currently named packages are malicious. The vulnerability is that the reviewed source does not reproducibly identify the dependency code that future executions will load. ### A ...[truncated 1076 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/gpt_image2.py:36
Finding

CRS bearer credential can be forwarded to an unrestricted configured endpoint

Content
View full analysis
dict: if not CRS_KEY: print("Error: CRS_API_KEY not set", file=sys.stderr) sys.exit(1) return {"Authorization": f"Bearer {CRS_KEY}"} ``` ```python resp = requests.post( f"{CRS_BASE}/openai/v1/images/generations", headers=get_headers(), json=payload, timeout=args.timeout, ) ``` ```python resp = requests.post( f"{CRS_BASE}/openai/v1/images/edits", headers=get_headers(), json=payload, timeout=args.timeout, ) ``` The edit payload includes the complete Base64-encoded contents of each selected reference image: ```python images = [] for img_path in args.image: mime = detect_mime(img_path) b64 = read_image_b64(img_path) images.append({"image_url": f"data:{mime};base64,{b64}"}) ``` ### Technical Analysis `CRS_BASE_URL` accepts an arbitrary URL. The script does not validate: - Whether the scheme is HTTPS. - Whether the destination host is trusted. - Whether a non-loopback plaintext HTTP endpoint is being used. - Whether the configured host is authorized to receive `CRS_API_KEY`. - Whether the selected backend differs from the expected local CRS service. The same bearer credential is attached to every configured destination. For edit operations, complete user-selected image contents are sent alongside the credential and prompt. The default loopback endpoint is consistent with the declared functionality. The unsafe aspect is that the credential is not bound to a trusted endpoint profile and can be forwarded to any destination selected through the environment. The Base64 encoding itself is not covert exfiltration. It ...[truncated 1325 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
Findings (96)

Tainted flow: 'CRS_BASE' from os.environ.get (line 38, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/gpt_image2.py (reported line 89)May include surrounding context.

python
if args.background:
        payload["background"] = args.background

    resp = requests.post(
        f"{CRS_BASE}/openai/v1/images/generations",
        headers=get_headers(),
        json=payload,

Tainted flow: 'CRS_BASE' from os.environ.get (line 38, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/gpt_image2.py (reported line 119)May include surrounding context.

python
"response_format": "b64_json",
    }

    resp = requests.post(
        f"{CRS_BASE}/openai/v1/images/edits",
        headers=get_headers(),
        json=payload,

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 29)May include surrounding context.

复制 .env.example 并填入你的 key:

bash
cp .env.example .env

| 变量 | 说明 | 必填 |

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a high-level, feature-rich image skill orchestrator with extensive routing, curated style/use-case libraries, and backend selection between GPT Image 2 and Gemini. The supplied code does not implement those behaviors. It is a straightforward command-line utility that takes a prompt, optional input images, an aspect ratio, and a Gemini model/API key, then calls Gemini's generate_content API and saves a PNG. It does support basic text-to-image plus image editing/composition via input images, which partially overlaps with the description, but the primary declared functionality—routing, style systems, backend dispatch, logo showcase handling, and reference-style inference—is absent. Therefore the description materially overstates and misrepresents the actual code behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a high-level image-generation orchestrator with extensive routing, curated style systems, use-case presets, and backend selection between GPT Image 2 and Gemini. The supplied code chunk is materially narrower: it is a simple Python CLI wrapper that sends requests to CRS OpenAI-compatible image generation/edit endpoints using the gpt-image-2 model. It supports generate and edit with optional multiple reference images, output sizing/quality/format, and local file saving. While some declared capabilities partially overlap (text-to-image, image editing, multi-reference input), the core represented purpose—central routing hub with rich style/use-case libraries and dual-backend scheduling—is not implemented in this code. Therefore the description overstates the actual behavior in a material way.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file contains a prompt explicitly instructing creation of a character holding a passport with clearly visible identity fields such as name, affiliation, and birth date. Even if framed as fictional or illustrative, this normalizes and operationalizes production of document-verification imagery that can support impersonation, fraud enablement, or social engineering artifacts.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The prompt directly requests identity-verification imagery with a clearly visible passport and personal details in plain language, making the harmful use case explicit rather than incidental. In the context of a centralized image-generation skill, this materially lowers the barrier to producing deceptive identity artifacts and increases abuse potential.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
88% confidence
Finding

The file embeds extensive high-priority prompt templates, including pseudo-system instructions and rigid output-control text. In a skill-routing context, treating this repository content as trusted instructions could let embedded prompt text override user intent, steer model behavior unexpectedly, or cause unauthorized disclosure/reuse of proprietary prompt assets.

Content

Scanner excerpt · references/game-asset.json (reported line 1)May include surrounding context.

json
arrative Micro-Detail (The Greebles):\n   Scale Indicators: Embed tiny technical details to sell the scale.\n       Vents: Cooling fans or intake grilles.\n       Text: Tiny white serial numbers and warning labels (e.g., \"CAUTION: HOT\", \"NO STEP\") printed on the casing.\n       The \"City\" (Optional): If the object is large enough, tiny architectural elements (antennas, platforms) can grow out of the mechanical base.\n\n4. Visual Syntax & Composition:\n   Background: Clean Studio Grey (Infinite Curve). The focus is entirely on the object's silhouette.\n   Lighting:\n       Key Light: Soft white studio light to highlight the texture of the carbon fiber weave.\n       Rim Light: A sharp backlight to define the edge of the object against the grey background.\n       Bloom: The internal colored LEDs must have a soft \"Octane Bloom\" effect.\n\n5. Render Style:\n   Aesthetic: Hard Surface Modeling, \"Tech-Wear\" Fashion, High-End Automotive Design.\n   Camera: Isometric or 3/4 Product Shot angle.\n\nOutput: Photorealistic 3D Render, 8k, Highly Detailed Textures (Carbon Fiber, Brushed Metal, Rubber).\n</instructions>","title":"Cyber-Industrial Exoskeleton Object Transformation Prompt","description":"A system instruction prompt designed to reimagine any input object (like a sneaker or a skull) as a complex, high-performance Cyber-Industrial Assembly. It specifies deconstruction into segmented carbon fiber panels, internal mechanics with glowing industrial cabling, and detailed greebles, rendered as a photorealistic 3D product shot with specific studio lighting and Octane Bloom effects.","sourceMedia":["https://cms-assets.youmind.com/media/1767682161991_14se7x_G9tjMDjXgAAOKBz.jpg"],"needReferenceImages":false},{"content":"{\n  \"subject\": {\n    \"description\": \"Athletic woman in a warrior-like kneeling stance on dusty terrain, holding a vertical spear with a firm, dominant grip while looking directly at the camera with a stoic gaze.\",\n    \"facial features\": \"A
...[truncated 27 chars]

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · references/comic-storyboard.json (reported line 1)May include surrounding context.

json
[{"content":"Input Variable: [insert product name]\nLanguage: [insert language]\n\nSystem Instruction:\nCreate an image of premium liquid glass Bento grid product infographic with 8 modules (card 2 to 8 show text titles only).\n1) Product Analysis:\n→ Identify product's dominant natural color → \"hero color\"\n→ Identify category: FOOD / MEDICINE / TECH\n2) Color Palette (derived from hero):\n→ Product + accents: full saturation hero color\n→ Icons, borders: muted hero (30-40% saturation, never black)\n3) Visual Style:\n→ Hero product: real photography (authentic, premium), 3D Glass version [choose one]\n→ Cards: Apple liquid glass (85-90% transparent) with Whisper-thin borders and Subtle drop shadow for floating depth and reflecting the background color\n→ Background stays behind cards and high blur where cards are [choose one]:\n  - Ethereal: product essence, light caustics, abstract glow\n  - Macro: product texture close-up, heavily blurred\n  - Pattern: product repeated softly at 10-15% opacity\n  - Context: relevant environment, blurred + desaturated\n→ Add subtle motion effect\n→ Asymmetric Bento grid, 16:9 landscape\n→ Hero card: 28-30% | Info modules: 70-72%\n4) Module Content (8 Cards):\nM1 — Hero: Product displayed as real photo / 3D glass / stylized interpretation (choose one)in beautiful form + product name label\nM2 — Core Benefits: 4 unique benefits + hero-color icons\nM3 — How to Use: 4 usage methods + icons\nM4 — Key Metrics: 5 EXACT data points\nFormat: [icon] [Label] [Bold Value] [Unit]\nFOOD: Calories: [X] kcal/100g, Carbs: [X]g (fiber [X]g, sugar [X]g), Protein: [X]g, [Key Vitamin]: [X]mg ([X]% DV), [Key Mineral]: [X]mg ([X]% DV)\nMEDICINE:Active: [name], Strength: [X] mg, Onset: [X] min, Duration: [X] hrs, Half-life: [X] hrs \nTECH:Chip: [model], Battery: [X] hrs, Weight: [X]g,[Key spec]: [value], Connectivity: [protocols]\nM5 — Who It's For: 4 recommended groups with green checkmark icons | 3 caution groups with amber warning icons\nM6 — Import
...[truncated 28 chars]

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · references/infographic-edu-visual.json (reported line 1)May include surrounding context.

json
[{"content":"Input Variable: [insert product name]\nLanguage: [insert language]\n\nSystem Instruction:\nCreate an image of premium liquid glass Bento grid product infographic with 8 modules (card 2 to 8 show text titles only).\n1) Product Analysis:\n→ Identify product's dominant natural color → \"hero color\"\n→ Identify category: FOOD / MEDICINE / TECH\n2) Color Palette (derived from hero):\n→ Product + accents: full saturation hero color\n→ Icons, borders: muted hero (30-40% saturation, never black)\n3) Visual Style:\n→ Hero product: real photography (authentic, premium), 3D Glass version [choose one]\n→ Cards: Apple liquid glass (85-90% transparent) with Whisper-thin borders and Subtle drop shadow for floating depth and reflecting the background color\n→ Background stays behind cards and high blur where cards are [choose one]:\n  - Ethereal: product essence, light caustics, abstract glow\n  - Macro: product texture close-up, heavily blurred\n  - Pattern: product repeated softly at 10-15% opacity\n  - Context: relevant environment, blurred + desaturated\n→ Add subtle motion effect\n→ Asymmetric Bento grid, 16:9 landscape\n→ Hero card: 28-30% | Info modules: 70-72%\n4) Module Content (8 Cards):\nM1 — Hero: Product displayed as real photo / 3D glass / stylized interpretation (choose one)in beautiful form + product name label\nM2 — Core Benefits: 4 unique benefits + hero-color icons\nM3 — How to Use: 4 usage methods + icons\nM4 — Key Metrics: 5 EXACT data points\nFormat: [icon] [Label] [Bold Value] [Unit]\nFOOD: Calories: [X] kcal/100g, Carbs: [X]g (fiber [X]g, sugar [X]g), Protein: [X]g, [Key Vitamin]: [X]mg ([X]% DV), [Key Mineral]: [X]mg ([X]% DV)\nMEDICINE:Active: [name], Strength: [X] mg, Onset: [X] min, Duration: [X] hrs, Half-life: [X] hrs \nTECH:Chip: [model], Battery: [X] hrs, Weight: [X]g,[Key spec]: [value], Connectivity: [protocols]\nM5 — Who It's For: 4 recommended groups with green checkmark icons | 3 caution groups with amber warning icons\nM6 — Import
...[truncated 28 chars]

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · references/infographic-edu-visual.json (reported line 1)May include surrounding context.

json
[{"content":"Input Variable: [insert product name]\nLanguage: [insert language]\n\nSystem Instruction:\nCreate an image of premium liquid glass Bento grid product infographic with 8 modules (card 2 to 8 show text titles only).\n1) Product Analysis:\n→ Identify product's dominant natural color → \"hero color\"\n→ Identify category: FOOD / MEDICINE / TECH\n2) Color Palette (derived from hero):\n→ Product + accents: full saturation hero color\n→ Icons, borders: muted hero (30-40% saturation, never black)\n3) Visual Style:\n→ Hero product: real photography (authentic, premium), 3D Glass version [choose one]\n→ Cards: Apple liquid glass (85-90% transparent) with Whisper-thin borders and Subtle drop shadow for floating depth and reflecting the background color\n→ Background stays behind cards and high blur where cards are [choose one]:\n  - Ethereal: product essence, light caustics, abstract glow\n  - Macro: product texture close-up, heavily blurred\n  - Pattern: product repeated softly at 10-15% opacity\n  - Context: relevant environment, blurred + desaturated\n→ Add subtle motion effect\n→ Asymmetric Bento grid, 16:9 landscape\n→ Hero card: 28-30% | Info modules: 70-72%\n4) Module Content (8 Cards):\nM1 — Hero: Product displayed as real photo / 3D glass / stylized interpretation (choose one)in beautiful form + product name label\nM2 — Core Benefits: 4 unique benefits + hero-color icons\nM3 — How to Use: 4 usage methods + icons\nM4 — Key Metrics: 5 EXACT data points\nFormat: [icon] [Label] [Bold Value] [Unit]\nFOOD: Calories: [X] kcal/100g, Carbs: [X]g (fiber [X]g, sugar [X]g), Protein: [X]g, [Key Vitamin]: [X]mg ([X]% DV), [Key Mineral]: [X]mg ([X]% DV)\nMEDICINE:Active: [name], Strength: [X] mg, Onset: [X] min, Duration: [X] hrs, Half-life: [X] hrs \nTECH:Chip: [model], Battery: [X] hrs, Weight: [X]g,[Key spec]: [value], Connectivity: [protocols]\nM5 — Who It's For: 4 recommended groups with green checkmark icons | 3 caution groups with amber warning icons\nM6 — Import
...[truncated 28 chars]

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · references/infographic-edu-visual.json (reported line 1)May include surrounding context.

json
ted color palette to create dynamic and eye-catching composition styles\n\nTsundere expression reality editing, Nano Banana Pro uses narrative anchors to achieve emotional intensity and identity locking applications\n\nCartoon and reality split portrait, Nano Banana Pro's mixed-style technique for seamless transition of texture and detail\n\nColor illustration style matrix, Nano Banana Pro's modular library for generating multiple animated variations from photos\n\nCoffee ingredient dynamic exploded view, Nano Banana Pro combines motion prompts to achieve smooth separation and realistic texture\n\nHigh-end brand souvenir reconstruction, Nano Banana Pro's surprising design style with diverse categories and luxurious materials\n\nCelestial dream theme portrait, Nano Banana Pro's surreal technique with glowing edges and a dreamy color palette","title":"Nano Banana Pro Community Hot Prompts Compilation","description":"A compilation of several high-engagement Nano Banana Pro prompts from the community, showcasing diverse applications like Pop Art product photography, origami sculpture rendering, anatomical illustration, and cinematic portraiture, emphasizing texture, lighting, and commercial realism.","sourceMedia":["https://cms-assets.youmind.com/media/1767966155198_5xysku_G-ESn89XIAQIx2A.jpg"],"needReferenceImages":false},{"content":"Create a historical diagram-style infographic, 16:9 horizontal composition, titled \"Visual Deconstruction of the Ancient Chinese Official Attire Ranking System.\" Adopt the aesthetic of ancient canonical diagrams and draw in the style of illustrations from ancient books. The image should display a comparison of the official uniforms of nine ranks of officials from the {argument name=\"dynasty\" default=\"Qing Dynasty\"}, arranged from left to right by rank: nine standing figures from the first to the ninth rank. Above each figure, use fine-line painting (Gongbi) to label the \"Buzi (Rank Badge) Pattern\" (First Rank Crane, Second Rank Gol
...[truncated 28 chars]

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · references/infographic-edu-visual.json (reported line 1)May include surrounding context.

json
M7 — Quick Reference:\n→ FOOD: Glycemic Index + dietary tags with icons\n→ MEDICINE: Side effects + severity with icons\n→ TECH: Compatibility + certifications with icons\nM8 — Did You Know: 3 facts (origin, science, global stat) + icons\nOutput: 1 image, 16:9 landscape, ultra-premium liquid glass infographic.","title":"Premium liquid glass Bento grid product infographic with 8 modules","description":"Create an Infographics with bento grid 8 module layout, user can specify any product name in Food, Medicine, tech etc category, choose language, Background style, Hero grid style","sourceMedia":["https://cms-assets.youmind.com/media/1768962051381_l9uih4_537980579-6f29d32a-c786-40c4-bd5a-79c640737496.png","https://cms-assets.youmind.com/media/1768962076321_nu4c5q_537981099-d18d0e38-f7ac-4781-a5da-6d68e2380885.png"],"needReferenceImages":false},{"content":"Completely recreate the uploaded person.\nMake it a header image for a note article where that person introduces “Nano Banan

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · references/poster-flyer.json (reported line 1)May include surrounding context.

json
Environment\": {\"Setting\": \"Minimal studio\", \"Background\": \"Grey gradient or geometric\", \"Lighting\": {\"Style\": \"Dramatic directional\", \"Quality\": \"Hard shadows, extreme contrast\"}},\n  \"ImageQuality\": {\"Resolution\": \"8K black and white\", \"Details\": \"Fine art grain\", \"Aesthetic\": \"Irving Penn/Avedon portrait\"},\n  \"NegativePrompt\": [\"color\", \"flat lighting\", \"different face\", \"altered facial features\"],\n  \"ResponseFormat\": {\"Layout\": \"3x3 grid\", \"AspectRatio\": \"1:1\"}\n}","title":"3x3 Black and White Photo Collage","description":"A prompt designed to create a 3x3 grid photo collage in a high-contrast black and white aesthetic, reminiscent of classic photographers like Irving Penn or Avedon. It mandates strict face preservation across all nine frames while varying the pose and expression dramatically.","sourceMedia":["https://cms-assets.youmind.com/media/1768466905224_a0xyqr_G-hXc0UbYAAWMG-.jpg"],"needReferenceImages":true},{"content":"{\n  \"meta\": {\n    \"image_quality\": \"High\",\n    \"image_type\": \"Digital Advertisement / Composite Photo Manipulation\",\n    \"resolution_estimation\": \"High resolution, likely 1080x1080 or higher\",\n    \"file_characteristics\": {\n      \"compression_artifacts\": \"Low\",\n      \"noise_level\": \"Low (natural grain added as effect)\",\n      \"lens_type_estimation\": \"Portrait/Telephoto (approx 85mm equivalent)\"\n    }\n  },\n  \"global_context\": {\n    \"scene_description\": \"A vertical promotional graphic featuring a waist-up portrait of a young woman holding a digital tablet. She is styled in streetwear ({argument name=\"jacket color\" default=\"orange\"} bomber jacket, beige beanie). Behind her, massive typography spells 'DESIGN'. To her left, text in English is visible. The aesthetic is urban, grunge, and modern, with a textured overlay resembling scratched film or worn paper. The bottom of the image features {argument name=\"smoke color\" default=\"orange\"}, s
...[truncated 28 chars]

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · references/poster-flyer.json (reported line 1)May include surrounding context.

json
fetti. The background features a yellow sun, the text \"Complete Success\", smiley faces, and sunflowers. The puzzle pieces converge from the four corners to the center to form a complete picture. Clear makeup, bright ring light, 85mm lens, f/1.8 aperture, four-panel composition with puzzle interaction, fashion magazine style.","title":"New Year's Day Special: Four-Panel Puzzle for 2026 Blessing","description":"A detailed multi-panel prompt for Nano Banana Pro, creating a 2x2 grid photo collage where a single female character, in four different outfits and settings, pieces together a puzzle that spells '2026 New Year's Day Happy' in the center. The prompt specifies precise facial feature retention, clothing details, background elements, and photographic parameters for a fashion magazine style.","sourceMedia":["https://cms-assets.youmind.com/media/1767455034932_ivuvu0_G9V-MszakAEAIBw.jpg"],"needReferenceImages":true},{"content":"A Japanese Edo-period Ukiyo-e woodblock print. The overall

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/ecommerce-main-image.json (reported line 1)May include surrounding context.

json
",\n    \"quality\": \"premium advertising grade\",\n    \"sharpness\": \"extreme micro-detail, crisp edges\",\n    \"noise\": \"none\",\n    \"artifacts\": \"none\",\n    \"depth_of_field\": \"shallow, subject-focused\",\n    \"motion\": \"frozen mid-air ingredients\",\n    \"background_style\": \"solid single-color studio backdrop\"\n  },\n\n  \"subject\": {\n    \"main_food\": \"chocolate chip cookies\",\n    \"quantity\": 3,\n    \"appearance\": [\n      \"golden-brown freshly baked cookies\",\n      \"soft cracked surface\",\n      \"visible melted chocolate chips\",\n      \"slightly crisp edges\",\n      \"natural handmade texture\"\n    ],\n    \"branding_rules\": [\n      \"no text\",\n      \"no logo\",\n      \"no embossing\",\n      \"no patterns\",\n      \"no symbols\"\n    ]\n  },\n\n  \"secondary_elements\": {\n    \"ingredients_flying\": [\n      \"dark chocolate chunks\",\n      \"cookie crumbs\",\n      \"fine sugar crystals\"\n    ],\n    \"motion_style\": \"dynamic

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/product-marketing.json (reported line 1)May include surrounding context.

json
",\n    \"quality\": \"premium advertising grade\",\n    \"sharpness\": \"extreme micro-detail, crisp edges\",\n    \"noise\": \"none\",\n    \"artifacts\": \"none\",\n    \"depth_of_field\": \"shallow, subject-focused\",\n    \"motion\": \"frozen mid-air ingredients\",\n    \"background_style\": \"solid single-color studio backdrop\"\n  },\n\n  \"subject\": {\n    \"main_food\": \"chocolate chip cookies\",\n    \"quantity\": 3,\n    \"appearance\": [\n      \"golden-brown freshly baked cookies\",\n      \"soft cracked surface\",\n      \"visible melted chocolate chips\",\n      \"slightly crisp edges\",\n      \"natural handmade texture\"\n    ],\n    \"branding_rules\": [\n      \"no text\",\n      \"no logo\",\n      \"no embossing\",\n      \"no patterns\",\n      \"no symbols\"\n    ]\n  },\n\n  \"secondary_elements\": {\n    \"ingredients_flying\": [\n      \"dark chocolate chunks\",\n      \"cookie crumbs\",\n      \"fine sugar crystals\"\n    ],\n    \"motion_style\": \"dynamic

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The prompt explicitly mandates broad information gathering and deduction of a named person's character, background, and worldview. This is dangerous because it directs the model to perform speculative trait inference about a real individual, which can produce invasive, defamatory, or misleading profiling from sparse or noisy public data.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/social-media-post.json (reported line 1)May include surrounding context.

json
al of Ekon Musk","description":"A prompt for generating an ultra-realistic, 8k cinematic fashion editorial featuring a laughing Ekon Musk. The image is specified to have him wearing silk pajamas with wind in his hair, captured with high-end photography specifications (Sony A7R IV, 85mm lens, f/1.8) under soft natural sunlight, emphasizing detailed skin texture.","sourceMedia":["https://cms-assets.youmind.com/media/1770706219813_fulb8p_HAtsrBiaMAAy74X.jpg"],"needReferenceImages":false},{"content":"{ \"subject\": { \"description\": \"A young Asian woman taking a high-angle selfie on a seaside balcony, exuding a playful and flirtatious holiday vibe.\", \"mirror_rules\": \"N/A\", \"age\": \"Early 20s\", \"expression\": { \"eyes\": { \"look\": \"Winking right eye, left eye gazing warmly at camera\", \"energy\": \"Playful, charming, slightly squinting against the light\", \"direction\": \"Direct eye contact\" }, \"mouth\": { \"position\": \"Soft closed smile\", \"energy\": \"Relaxed, corners uplifted\" }, \"overall\": \"Effortlessly cute and engaging\" }, \"face\": { \"preserve_original\": true, \"makeup\": \"Natural Korean style, soft coral lip tint, subtle blush\" }, \"hair\": { \"color\": \"Dark brown/Black\", \"style\": \"Shoulder-length bob, layered\", \"effect\": \"Chaotic windblown texture, strands messy across face and lips, dynamic motion\" }, \"body\": { \"frame\": \"Slim, feminine curves\", \"waist\": \"Not visible\", \"chest\": \"Visible cleavage due to low-cut top and high camera angle\", \"legs\": \"Not visible\", \"skin\": { \"visible_areas\": \"Face, neck, chest\", \"tone\": \"Fair, warm undertone\", \"texture\": \"Smooth, hydrated, soft-focus pores\", \"lighting_effect\": \"Natural daylight reflecting soft sheen on collarbones and forehead\" } }, \"pose\": { \"position\": \"Leaning slightly forward\", \"base\": \"Standing\", \"overall\": \"High-angle selfie pose, head tilted slightly to the right\" }, \"clothing\": { \"top\": { \"type\": \"Ribbed knit lon
...[truncated 28 chars]

Ssd 4

High
Category
Not specified by scanner
Confidence
92% confidence
Finding

An overhead prompt described as peeking to 'see what they are doing' semantically encodes spying rather than ordinary composition guidance. In context, this file already contains multiple voyeuristic patterns, so this wording is more concerning than it would be in an abstract cinematography guide.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · references/youtube-thumbnail.json (reported line 1)May include surrounding context.

json
[{"content":"Use Nano Banana Pro to generate a realistic character effect, and then use this image as a reference element for Seedance 2.0 to create a video","title":"Generate Realistic Character from Fantasy Image Reference Prompt","description":"This is a two-step process prompt. First, an initial fantasy image is generated (presumably via Midjourney), and then Nano Banana Pro is instructed to generate a realistic human character based on that fantasy image as a reference. The resulting realistic image is then used as a reference for a video generation model (Seedance 2.0).","sourceMedia":["https://cms-assets.youmind.com/media/1770792217949_zs9td1_HA0MoEsaAAIVs9N.jpg","https://cms-assets.youmind.com/media/1770792218224_hiasel_HA0MlWoaAAUcMhq.jpg"],"needReferenceImages":true},{"content":"{\n  \"subject\": {\n    \"name\": \"Jennie Kim\",\n    \"alias\": \"Jennie\",\n    \"group\": \"BLACKPINK\",\n    \"persona\": \"Elegant, fierce stage presence, signature 'human Chanel' style\",\n    \"expression\": \"Focused, slightly intense, sharp gaze off-camera\",\n    \"pose\": \"Dynamic three-quarter profile, mid-choreography, hair in motion\"\n  },\n  \"physical_features\": {\n    \"hair\": \"Long, dark, voluminous waves framing face and flowing down back\",\n    \"skin\": \"Dewy, hyper-reflective, glass-skin style, warm skin tone\",\n    \"makeup\": \"Soft smoky eyeshadow, winged eyeliner, gradient red lips\"\n  },\n  \"clothing\": {\n    \"top\": \"Textured white lace crop top\",\n    \"bottom\": \"High-waisted black pleated bottoms\",\n    \"style\": \"Monochrome, chic stage outfit\"\n  },\n  \"lighting\": {\n    \"type\": \"Stage spotlights\",\n    \"contrast\": \"High\",\n    \"effects\": \"Cool blue rim light highlighting hair and skin, cinematic haze/fog in air\"\n  },\n  \"atmosphere\": \"Concert/focused performance, cinematic and ethereal mood, balance of vulnerability and power\",\n  \"image_details\": {\n    \"width\": 504,\n    \"height\": 1002\n  }\n}","title"
...[truncated 28 chars]

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 52)May include surrounding context.

yaml
- id: gpt-image-2
  endpoint: "https://api.openai.com/v1/images/generations"
  auth_header: "Bearer $OPENAI_API_KEY"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill describes capabilities that read environment variables, read and write local files, and send network requests, but it does not declare any explicit tool scope or allowed-tools policy. That weakens least-privilege controls and makes unintended access or overbroad execution more likely if the skill is invoked in an environment with those capabilities.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises itself as the sole entrypoint for nearly any image-related phrasing, creating an invocation trigger that overlaps heavily with normal user language. Overbroad triggering can cause the agent to route unintended requests into a skill that performs file access and external transmission, increasing the chance of surprise data handling or policy bypass.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

This code sends user prompts and related generation parameters to an external image API endpoint using credentials from the environment. External transmission is expected for this kind of skill, but it is still security-relevant because sensitive user content may leave the local trust boundary, and the destination can be changed via environment configuration.

Content

Scanner excerpt · SKILL.md (reported line 203)May include surrounding context.

md
def gpt_image2_generate(prompt, size='1536x1024', quality='high',
                         output_format='png', filename=None):
    resp = requests.post(
        f'{CRS_BASE}/openai/v1/images/generations',
        headers={'Authorization': f'Bearer {CRS_KEY}'},
        json={'model': 'gpt-image-2', 'prompt': prompt, 'size': size,

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
references/app-web-design.json:1

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
references/product-marketing.json:1

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
references/social-media-post.json:1