Back to skill

Security audit

多商品批量生图 Batch Image

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed batch product-image generation workflow with expected cloud API use and local output files, but users should review costs and provider data sharing before running large batches.

Install only if you are comfortable sending product prompts and reference images to the configured generation provider. Start with --dry-run, a single SKU, and a small sample; set a budget limit for batches, keep manifests limited to intended image paths/URLs, and customize the example brand template before using it.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (29)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill is for bulk generation of product marketing images from a CSV/SKU list, including operational pipeline features for large runs. The supplied code instead is a standalone Python script for pre-listing compliance validation of image files. It reads one or more image paths, checks objective properties like resolution, aspect ratio, background whiteness/consistency, occupancy, alpha channel, borders, file format, and file size against marketplace-specific rules, outputs reports/JSON, and optionally writes fixed JPEGs. This is a materially different primary purpose and introduces a distinct capability (listing compliance QA/repair) that is not represented by the declared description.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 168)May include surrounding context.

md
node scripts/gen.mjs --task batch-image \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 235)May include surrounding context.

md
node scripts/gen.mjs --task batch-image \

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill includes commands that invoke external CLIs, reference network resources, and likely rely on environment-provided credentials or configuration, but it does not declare any tool scope such as allowed tools or permissions. That creates an authorization ambiguity where an agent may permit broader execution than the skill explicitly advertises, increasing the chance of unintended network access or misuse of secrets during execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The invocation phrases are broad enough to match ordinary user requests like '批量生图' or '一批商品出图,' which can cause the skill to auto-activate in contexts the user did not intend. Over-broad triggering is dangerous because this skill can lead to networked command execution, batch processing, and potentially significant spend when activated on ambiguous prompts.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 270)May include surrounding context.

md
5. **`--dry-run` 估总价**:单价 × SKU 数。
6. **全量跑**:5 路并发 + 3 次重试;SKU 很多时用 `--no-wait` 提交后统一轮询。
7. **看汇总报告**:失败的单独重跑。
8. **抽样质检**:随机抽 10% 过 [detect-task](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/detect-task/skill.md);不合格的 SKU 单独用 `gpt-image-2` 重跑。

---

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill hard-codes a model description with specific ethnicity, gender, and age characteristics ('East Asian woman, late twenties') as a default brand setting, without any user opt-in, necessity justification, or documented compliance basis. In a batch image generation pipeline, this can systematically propagate demographic bias across hundreds of outputs, creating discrimination, exclusion, or policy/legal risk at scale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file contains user-facing natural language content only in Chinese, and there is no indication that users can opt into another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the policy rule for language or locale constraints, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This reference forces a specific language for all users who consume the skill documentation. Under the policy, a language constraint should either be optional via user choice or clearly documented as justified for a region-specific skill, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

All CLI help text in this section is written only in Chinese, and the file continues to emit Chinese-only operational messages elsewhere. That forces a specific language for users without opt-in, which matches the locale-policy violation criteria for natural-language content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script emits usage and error messages in Chinese only, such as the template-missing error and command usage text. This imposes a specific language on users without offering a locale choice or documenting that the tool is intended only for a Chinese-speaking context, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest describes a batch product-image generation pipeline from CSV to commercial images with concurrency, retries, resume, cost controls, and selection sheets. This file instead performs pre-listing platform compliance validation and can automatically modify images to meet marketplace rules, which is a distinct listing-QA/remediation capability not justified by the stated batch-generation purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The module interface explicitly includes video:boolean, and multiple providers parse videos/video outputs and assign .mp4 extensions. The manifest describes a pipeline for batch product image generation (批量生图, 商拍图) rather than image-or-video generation, so adding video-capable routing is broader than the stated purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The helper functions fetch arbitrary remote URLs and read arbitrary local file paths, then convert the contents for transmission to external model providers. In an agent context, this can cause unintended disclosure of local files or server-side requests to internal resources if untrusted input controls image paths/URLs.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 134)May include surrounding context.

js
model: () => env.GEN_MODEL_OPENAI || 'gpt-image-1',
  describe(req) {
    const ep = req.images?.length ? 'images/edits' : 'images/generations'
    return `POST https://api.openai.com/v1/${ep}  model=${openai.model()} size=${mapSize(req.size)} n=${req.batch}`
  },
  async run(req) {
    const key = env.OPENAI_API_KEY

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

These provider functions send prompts and image contents to third-party APIs without any in-file enforcement of disclosure, consent, or data-classification checks. In a batch-image skill handling many products, this increases the chance of bulk leakage of proprietary images, prompts, or embedded sensitive metadata to external vendors.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This finding duplicates the actual transmission at the OpenAI edits call site. Because image contents may originate from local paths or fetched URLs, the endpoint can receive data the user did not intend to disclose if upstream inputs are not tightly controlled.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 153)May include surrounding context.

js
: await readFile(p)
        fd.append('image[]', new Blob([buf], { type: mimeOf(p) }), path.basename(p))
      }
      r = await fetch('https://api.openai.com/v1/images/edits', {
        method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
      })
    } else {

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This finding duplicates the actual transmission at the OpenAI edits call site. Because image contents may originate from local paths or fetched URLs, the endpoint can receive data the user did not intend to disclose if upstream inputs are not tightly controlled.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 153)May include surrounding context.

js
: await readFile(p)
        fd.append('image[]', new Blob([buf], { type: mimeOf(p) }), path.basename(p))
      }
      r = await fetch('https://api.openai.com/v1/images/edits', {
        method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
      })
    } else {

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This duplicate finding points to the same OpenAI generations transmission path. While expected for the skill's purpose, it still represents an external data flow that should be transparent and policy-controlled in enterprise or sensitive product environments.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 157)May include surrounding context.

js
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
      })
    } else {
      r = await fetch('https://api.openai.com/v1/images/generations', {
        method: 'POST',
        headers: { authorization: `Bearer ${key}`, 'content-type': 'application/json' },
        body: JSON.stringify({

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This duplicate finding points to the same OpenAI generations transmission path. While expected for the skill's purpose, it still represents an external data flow that should be transparent and policy-controlled in enterprise or sensitive product environments.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 157)May include surrounding context.

js
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
      })
    } else {
      r = await fetch('https://api.openai.com/v1/images/generations', {
        method: 'POST',
        headers: { authorization: `Bearer ${key}`, 'content-type': 'application/json' },
        body: JSON.stringify({

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 261)May include surrounding context.

js
model: (req) =>
    env.GEN_MODEL_REPLICATE ||
    (req?.images?.length ? 'black-forest-labs/flux-kontext-pro' : 'black-forest-labs/flux-dev'),
  describe(req) { return `POST https://api.replicate.com/v1/models/${replicate.model(req)}/predictions` },
  async run(req) {
    const input = { prompt: req.prompt, num_outputs: req.batch }
    if (req.images?.length) input.input_image = await asDataUri(req.images[0])

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This call sends prompts and optionally base64-encoded image data to Replicate, creating a third-party exfiltration path for user-supplied or locally read content. Given the skill's batch-processing role, a single run could transmit a large volume of proprietary product imagery or prompt data.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 266)May include surrounding context.

js
const input = { prompt: req.prompt, num_outputs: req.batch }
    if (req.images?.length) input.input_image = await asDataUri(req.images[0])
    const j = await postJson(
      `https://api.replicate.com/v1/models/${replicate.model(req)}/predictions`,
      { input },
      { authorization: `Bearer ${env.REPLICATE_API_TOKEN}`, prefer: 'wait' },
      req.timeoutMs,

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The natural-language note on L02 is written only in Chinese, which imposes a specific language for understanding the configuration and its operational notes. Under the stated policy, locale or language constraints should be optional or explicitly justified; no such opt-in or justification appears in this file.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest describes this skill as a pipeline for generating batches of product commercial images from CSV input, with operational features like concurrency, retries, resume, and cost controls. However, this file maps the skill namespace to text-only tasks such as detect-task and platform-compliance, and to video tasks such as main-image-video, product-video-ad, and ugc-testimonial, which are materially broader than 'batch image' generation.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/batch.mjs:96

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/lib/providers.mjs:104

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/run_loop.mjs:61

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/gen.mjs:118

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/lib/providers.mjs:21