Back to skill

Security audit

服装细节放大图 Clothing Detail

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent clothing-detail image generation helper, with expected cloud image-provider uploads that users should understand before use.

Install only if you are comfortable sending clothing images, prompts, and possibly proprietary product details to the configured cloud image provider. Use --dry-run first, choose an approved provider explicitly when needed, and avoid passing confidential designs unless that provider is acceptable for your data policies.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (26)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 106)May include surrounding context.

md
node scripts/gen.mjs --task clothing-detail \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 160)May include surrounding context.

md
node scripts/gen.mjs --task clothing-detail \

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill includes explicit command execution examples and references to networked tooling (dlazy, node scripts/gen.mjs) but does not declare any permissions or allowed-tools scope. In an agent environment, this can lead to overbroad tool access, making it easier for the skill to invoke network or environment-capable tools without transparent least-privilege constraints.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description and primary instructions are written entirely in Chinese and present the skill as operating in that language, with no indication that users may choose another language. Under the stated policy, a fixed language/locale without opt-in is a natural-language policy violation unless explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The brand configuration hard-codes a model ethnicity ('East Asian woman') for all generated images, which can systematically constrain outputs in a way that excludes user choice and may create fairness, discrimination, or policy-compliance issues. In this skill context, the setting is a shared brand-wide default used across many SKUs, so the bias is amplified rather than isolated to a single image generation case.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Comments, usage examples, and user-facing messages in this script are written in Chinese, and the CLI help/error output later in the file also uses Chinese only. This creates a locale/language constraint without offering user opt-in or documenting a justified region-specific limitation, which matches the language-policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script emits template errors, usage help, and warning messages solely in Chinese through console output. Because these are the primary interaction surfaces for users, this enforces a single language without opt-in or an explicit documented rationale.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code selects an external provider and submits a request containing the user's prompt and image inputs, which may include sensitive data. Although dry-run and status output exist, there is no explicit user-facing warning at execution time that local prompts/images will be transmitted to third-party services.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest says this skill is for generating clothing-detail closeups such as fabric texture, stitching, and craftsmanship details from clothing images. This file instead provides a generic multi-provider generation router supporting arbitrary prompts, multiple providers, batch generation, text outputs, and video-related request/response handling, which is broader than a clothing-detail-specific implementation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documented request shape includes a "video:boolean" flag and several providers map outputs from video fields such as videos/video or choose .mp4 extensions. A skill whose stated purpose is producing close-up garment detail images does not obviously require video generation or video output processing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module sends prompts and image data to external providers and may first fetch remote image URLs, but there is no built-in consent, disclosure, or trust-boundary control. In a clothing-detail skill, users may assume local image processing; silent transmission of garment photos or proprietary design images to third-party services creates a real privacy and data-governance risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 134)May include surrounding context.

js
model: () => env.GEN_MODEL_OPENAI || 'gpt-image-1',
  describe(req) {
    const ep = req.images?.length ? 'images/edits' : 'images/generations'
    return `POST https://api.openai.com/v1/${ep}  model=${openai.model()} size=${mapSize(req.size)} n=${req.batch}`
  },
  async run(req) {
    const key = env.OPENAI_API_KEY

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This finding duplicates the actual OpenAI edit request, which performs outbound transmission of image data and prompts. The risk is privacy and confidentiality loss if users are unaware their images are being sent to an external processor.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 153)May include surrounding context.

js
: await readFile(p)
        fd.append('image[]', new Blob([buf], { type: mimeOf(p) }), path.basename(p))
      }
      r = await fetch('https://api.openai.com/v1/images/edits', {
        method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
      })
    } else {

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This finding duplicates the actual OpenAI edit request, which performs outbound transmission of image data and prompts. The risk is privacy and confidentiality loss if users are unaware their images are being sent to an external processor.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 153)May include surrounding context.

js
: await readFile(p)
        fd.append('image[]', new Blob([buf], { type: mimeOf(p) }), path.basename(p))
      }
      r = await fetch('https://api.openai.com/v1/images/edits', {
        method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
      })
    } else {

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

This duplicate finding corresponds to the outbound OpenAI generation request carrying user prompt data to a third-party API. For this narrowly scoped skill, undisclosed remote submission is more concerning because users may reasonably expect simple local enhancement rather than cloud transmission.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 157)May include surrounding context.

js
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
      })
    } else {
      r = await fetch('https://api.openai.com/v1/images/generations', {
        method: 'POST',
        headers: { authorization: `Bearer ${key}`, 'content-type': 'application/json' },
        body: JSON.stringify({

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

This duplicate finding corresponds to the outbound OpenAI generation request carrying user prompt data to a third-party API. For this narrowly scoped skill, undisclosed remote submission is more concerning because users may reasonably expect simple local enhancement rather than cloud transmission.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 157)May include surrounding context.

js
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
      })
    } else {
      r = await fetch('https://api.openai.com/v1/images/generations', {
        method: 'POST',
        headers: { authorization: `Bearer ${key}`, 'content-type': 'application/json' },
        body: JSON.stringify({

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 261)May include surrounding context.

js
model: (req) =>
    env.GEN_MODEL_REPLICATE ||
    (req?.images?.length ? 'black-forest-labs/flux-kontext-pro' : 'black-forest-labs/flux-dev'),
  describe(req) { return `POST https://api.replicate.com/v1/models/${replicate.model(req)}/predictions` },
  async run(req) {
    const input = { prompt: req.prompt, num_outputs: req.batch }
    if (req.images?.length) input.input_image = await asDataUri(req.images[0])

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

This call sends prompts and potentially base64-encoded input images to Replicate, which is a concrete external data transfer. In a clothing-detail workflow, that can expose confidential garment photos, textile patterns, or unreleased product designs to a third-party service if not explicitly disclosed and governed.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 266)May include surrounding context.

js
const input = { prompt: req.prompt, num_outputs: req.batch }
    if (req.images?.length) input.input_image = await asDataUri(req.images[0])
    const j = await postJson(
      `https://api.replicate.com/v1/models/${replicate.model(req)}/predictions`,
      { input },
      { authorization: `Bearer ${env.REPLICATE_API_TOKEN}`, prefer: 'wait' },
      req.timeoutMs,

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The file is primarily written in Chinese, but the highlighted agent instruction is presented only in English as a mandatory directive. This can be a language/locale policy concern because it imposes a specific language for critical usage guidance without explicitly offering user or operator choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This file's user-facing natural language is entirely in Chinese, including the header comment and later thrown error messages, with no indication that the skill is China-specific or that users can choose another language. Under the language/locale policy, forcing a specific language without opt-in is a policy concern even when it appears in code comments or string literals.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The exceptions at these lines emit Chinese-only messages (for example, parse failures and invalid list placement), which can surface directly to users or developers consuming the parser. Because no locale selection or justification is provided, this is a natural-language locale policy violation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The interface documentation includes a "text:boolean" request field, and provider implementations return texts from dlazy and Gemini responses. Producing textual outputs is not an obvious requirement for a skill described as generating enlarged garment-detail images and closeups.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The code reads provider API credentials from environment variables such as OPENAI_API_KEY, GEMINI_API_KEY, FAL_KEY, REPLICATE_API_TOKEN, and ARK_API_KEY. Although this is expected implementation behavior, the file does not include any disclosure or warning comment that the skill depends on and accesses sensitive credentials.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The module spawns an external binary via spawn(bin, args, ...), which is a safety-relevant operation under the rule. While the provider's purpose suggests backend execution, the file lacks an explicit warning or user-facing disclosure that an external CLI may be invoked.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/lib/providers.mjs:104

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/gen.mjs:118

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/lib/providers.mjs:21