Back to skill

Security audit

pixr CLI

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed helper for a local image-generation CLI, with expected local config changes and provider/API-key use but no evidence of hidden execution, exfiltration, or destructive behavior.

Install only if you intend agents to use the local pixr CLI. Expect it to read and update ~/.pixr defaults/profiles, use images from configured asset folders, and call whichever external provider and model you select, which may consume API quota or incur cost. Keep API keys in environment variables and review model/save-directory/profile changes before letting an agent make them persistent.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · references/command-reference.md (reported line 77)May include surrounding context.

pixr profile list pixr profile show social pixr profile init social pixr profile init social --model gemini-3.1-flash-image-preview --save-dir "~/Pictures/pixr/social"

text

Notes:

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

md
- "generate an image with pixr"
- "edit an image with pixr"
- "create variations with pixr"
- "set the pixr model"
- "save images to a default folder"
- "use the refs from ~/.pixr/assets"

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill enables implicit invocation with allow_implicit_invocation: true while providing only a broad description to 'operate the local pixr image CLI and its defaults.' Because this skill can generate images, modify configuration, and manage files under ~/.pixr, a loosely scoped auto-invocation path could cause the agent to trigger it in situations the user did not clearly intend, leading to unintended local actions or configuration changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This markdown file documents that the chosen model is saved to config, that config --init scaffolds ~/.pixr/, and that profile init <name> creates multiple files and directories. Under the markdown-specific warning rule, these behaviors affect user data and the local system state, but the reference presents them as notes/examples without an explicit caution or warning section.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The markdown instructs users to verify and export PIXR_API_KEY, which involves handling sensitive credentials. There is no accompanying warning to avoid sharing, logging, or committing the key, even though the file explicitly discusses setting it in the shell.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.