T02 · Agent Memory Poisoning
- Location
skill.md:324- Finding
Skill Instructions Request Persistent Agent-Memory Modification
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly matches its Jiuma image-generation purpose, but it should be reviewed because it stores an API secret in plaintext without enforcing private permissions and asks the agent to persist a memory entry.
Install only if you are comfortable sending prompts and login workflow data to Jiuma and storing a Jiuma API key locally. Before use, prefer an isolated environment, avoid sensitive prompts, inspect or harden the key file permissions yourself, and remove the unnecessary memory-recording instruction from the skill documentation.
skill.md:324Skill Instructions Request Persistent Agent-Memory Modification
utils.py:6API Secret Is Stored in Plaintext Without Enforced Restrictive Permissions
login.py:25Login Access Token Is Transmitted in a URL Query String
LOGIN.md:15Dependency Installation Is Unpinned and Lacks Integrity Verification
The declared purpose says this skill generates images from text using the Jiuma AI API. However, the supplied code does not perform any image generation, prompt handling, or image size customization. Its primary purpose is authentication: it calls login-related endpoints, returns login QR code and URL, checks login status, obtains a secret key, and saves the API key for later use. Authentication can be a supporting detail in a broader system, but this chunk itself is materially different from the declared image-generation functionality and exposes undeclared credential-handling behavior.
Without declared permissions the skill's intent is opaque and cannot be validated.
All user-facing strings, help text, and output messages are written in Chinese, and the skill provides no option for users to select another language. This can violate language/locale policy when a specific language is forced without user opt-in or explicit documentation that the tool is intended only for that locale.
This code is explicitly designed to transmit user input to an external service endpoint, which creates data exfiltration and third-party processing risk if users provide confidential content. While external API use is expected for this skill, the transmission is still security-relevant because it occurs automatically and uses an API key for authenticated access.
import argparse
from utils import jiuma_request, get_jiuma_api_key, output_result
SUBMIT_API = "https://api.jiuma.com/api/textImage/add"
CHECK_STATUS_API = "https://api.jiuma.com/api/textImage/status"
headers = {
The status-check endpoint also involves external transmission of task identifiers to a third-party service, which reveals workflow metadata and depends on an outside system. In context this is functionally necessary, but it still represents external data sharing and trust in a remote provider.
from utils import jiuma_request, get_jiuma_api_key, output_result
SUBMIT_API = "https://api.jiuma.com/api/textImage/add"
CHECK_STATUS_API = "https://api.jiuma.com/api/textImage/status"
headers = {
"X-Secret-Key": get_jiuma_api_key()
The skill sends user-provided prompt text directly to a third-party image generation API, which can expose sensitive or personal data if users include it in prompts. There is no consent flow, privacy notice, or warning that prompt contents leave the local environment and are processed by an external service.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
from utils import jiuma_request, output_result, save_jiuma_api_key
LOGIN_API = "https://api.jiuma.com/user/getLoginQrcode"
CHECK_API = "https://api.jiuma.com/user/checkLoginStatus"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
from utils import jiuma_request, output_result, save_jiuma_api_key
LOGIN_API = "https://api.jiuma.com/user/getLoginQrcode"
CHECK_API = "https://api.jiuma.com/user/checkLoginStatus"
The skill metadata presents this as an image-generation tool, but the file implements login and credential acquisition flows that are outside that narrowly stated scope. Scope mismatch is dangerous because it can surprise users or orchestrators into granting or handling credentials they did not expect, increasing the risk of unauthorized account linkage or secret collection.
The code persists a returned secret key via save_jiuma_api_key(data["secret_key"]) even though the skill is described only as a free image generator. Storing credentials creates a durable secret on disk or in local config, which can be exposed to other processes, reused beyond the user's expectation, or abused if the host environment is compromised.
After saving the API key, the code only reports that login succeeded and the key has been saved, without prior warning, consent flow, or details about where and how the credential is stored. Silent or poorly disclosed secret storage undermines informed consent and can lead users to expose long-lived credentials unknowingly in environments with shared access or weak filesystem protections.
The skill description is broad enough to trigger on generic image-generation requests without clearly signaling that user prompts will be sent to a third-party service. In an agentic environment, overbroad activation can cause unintended routing of user content to this skill, increasing privacy and consent risks.
The documentation describes sending user prompts, task identifiers, and a login/API-key workflow to remote Jiuma endpoints, but it does not clearly warn users that their content and authentication-related data will leave the local environment. This creates a real transparency and privacy risk, especially for prompts that may contain sensitive or personal information.
This skill is designed to transmit user-supplied image prompts to an external API endpoint, which is expected functionality but still a real security and privacy concern. The danger is context-dependent: for an image-generation skill external transmission is necessary, but it becomes risky if users are not clearly informed or if sensitive prompts are sent without consent.
## API说明
### 提交图片生成API
- **URL**: `POST https://api.jiuma.com/api/textImage/add`
- **参数**:
- `text`: 图片描述文本(必需)
- `width`: 图片宽度(可选,默认832,最大832)
The task-status endpoint involves sending task identifiers to a third-party service, confirming that workflow data is externally transmitted beyond the local agent environment. While consistent with normal asynchronous image-generation behavior, it still exposes metadata and should be treated as a privacy-relevant data flow.
- `height`: 图片高度(可选,默认480,最大832)
### 查询任务状态API
- **URL**: `POST https://api.jiuma.com/api/textImage/status`
- **参数**:
- `task_id`: 任务ID(必需)
The skill creates a hidden local directory and persists a Jiuma API key to disk even though the declared functionality is only free image generation. Storing credentials locally expands the attack surface because other local users, processes, backups, or logs may expose the key, and the persistence behavior is not apparent from the manifest.
The function sends arbitrary data and optional files to a remote API using requests.post, which can transmit user or system data over the network. Although errors are reported, there is no visible warning, confirmation, or explanatory comment/docstring in this file disclosing that data and files are uploaded remotely.
The code explicitly writes and later reads a credential file from disk, which is sensitive behavior not reflected in the skill description. This creates a confidentiality risk because plaintext credentials can be recovered by other software or users on the system and may persist longer than intended.
The API key is written directly to a local file without any notice, consent, or visible safeguard. Undisclosed secret storage is risky because users may assume prompts are the only data handled, while the skill silently creates a reusable credential artifact on disk.
The surrounding document consistently describes a text-to-image generation skill, but L246-L247 says '重新使用图片编辑功能' and gives an example prompt for image editing. That directly contradicts the skill's stated purpose and usage elsewhere in the file, indicating documentation copied from a different skill.
The instruction to record the skill in memory for future use encourages unnecessary retention of operational details in agent memory. In systems with persistent memory, this can normalize storing user- or environment-related information beyond the immediate task, increasing data retention and privacy risk.
No suspicious patterns detected.