Security audit
Image Skill
Security checks for vulnerabilities and agentic risk
Overview
This skill is a disclosed hosted media-generation integration with payments and tokens clearly documented, and no artifact-backed malicious behavior was found.
Install only if you want an agent to use Image Skill’s hosted service for media generation. Review the payment and token behavior first: live creates can debit prepaid credits, x402/Stripe flows involve real money, uploads and feedback go to the hosted service, and the saved restricted token should be treated as a credential.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
