Back to skill

Security audit

商品平铺图提取 Clothing Extraction

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed image-generation workflow for turning clothing photos into flat-lay product images, with privacy and scope cautions but no artifact-backed malicious behavior.

Install only if you are comfortable sending source photos, prompts, and generated outputs to dLazy or whichever provider you configure. Use --dry-run to inspect requests, avoid uploading private or sensitive photos unless provider terms are acceptable, and invoke the documented clothing-extraction task rather than the broader shared runner capabilities unless you intentionally want those other ecommerce workflows.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (34)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 104)May include surrounding context.

md
node scripts/gen.mjs --task clothing-extraction \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 155)May include surrounding context.

md
node scripts/gen.mjs --task clothing-extraction \

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This provider library exposes broad generation capabilities across image, video, and text rather than being constrained to the skill’s declared purpose of extracting clothing into flat-lay product images. In an agent setting, this mismatch expands the skill’s operational scope and can enable unintended or policy-violating content generation through a skill that users and reviewers may believe is narrowly limited.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The OpenAI implementation explicitly falls back to the images/generations endpoint when no input image is provided, enabling pure image synthesis rather than extraction from a user-supplied clothing photo. That creates a clear capability gap between the manifest and actual behavior, allowing misuse of this skill as a general image generator.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill demonstrates command execution and references capabilities that can access environment data and the network, but it does not declare an explicit tool scope such as allowed-tools or permissions. This creates an over-privileged integration risk: a host may grant broader execution than necessary, making unintended network access or secret exposure more likely if the skill is misused or later modified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file consistently presents the skill's description, usage guidance, and operational instructions in Chinese only. This can violate a language/locale policy when users are not given an explicit choice of language or informed that the skill is intended only for a Chinese-speaking context.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 9)May include surrounding context.

md
# clothing-extraction — 从任意图中提取商品平铺图

任意一张图 → **干净的商品平铺图**。这是 [flat-lay](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/flat-lay/skill.md) 的**逆操作**。

最常见的用途是补素材:手上只有一张真人上身图 / 买家秀 / 竞品截图,但主图位需要一张干净平铺图;或者要把它作为 [to-3d](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/to-3d/skill.md)、[fabric-on-body](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/fabric-on-body/skill.md)、[flat-lay](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/flat-lay/skill.md) 的干净输入。

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 11)May include surrounding context.

md
# clothing-extraction — 从任意图中提取商品平铺图

任意一张图 → **干净的商品平铺图**。这是 [flat-lay](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/flat-lay/skill.md) 的**逆操作**。

最常见的用途是补素材:手上只有一张真人上身图 / 买家秀 / 竞品截图,但主图位需要一张干净平铺图;或者要把它作为 [to-3d](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/to-3d/skill.md)、[fabric-on-body](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/fabric-on-body/skill.md)、[flat-lay](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/flat-lay/skill.md) 的干净输入。

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 11)May include surrounding context.

md
任意一张图 → **干净的商品平铺图**。这是 [flat-lay](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/flat-lay/skill.md) 的**逆操作**。

最常见的用途是补素材:手上只有一张真人上身图 / 买家秀 / 竞品截图,但主图位需要一张干净平铺图;或者要把它作为 [to-3d](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/to-3d/skill.md)、[fabric-on-body](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/fabric-on-body/skill.md)、[flat-lay](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/flat-lay/skill.md) 的干净输入。

---

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 11)May include surrounding context.

md
任意一张图 → **干净的商品平铺图**。这是 [flat-lay](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/flat-lay/skill.md) 的**逆操作**。

最常见的用途是补素材:手上只有一张真人上身图 / 买家秀 / 竞品截图,但主图位需要一张干净平铺图;或者要把它作为 [to-3d](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/to-3d/skill.md)、[fabric-on-body](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/fabric-on-body/skill.md)、[flat-lay](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/flat-lay/skill.md) 的干净输入。

---

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The configuration hard-codes a protected demographic attribute ("East Asian woman") as the default model identity without any user choice, business justification, or fairness guardrails. In an image-generation pipeline, this can systematically bias outputs, exclude other identities, and create discriminatory behavior across all downstream skills that inherit this shared brand file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

标题及整份文档均以中文撰写,并在 L136 起对 Agent 提出硬性要求,但没有说明这是面向特定中文用户群或允许根据用户偏好切换语言。按照语言/区域策略,若技能默认强制单一语言而无用户选择或合理限定,属于自然语言政策风险。

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest describes a skill for extracting clean flat-lay product images from arbitrary photos, but this file implements a brand-constraint loader/formatter that reads brand YAML/JSON and emits prompt text plus reference-image paths for many other tasks. That behavior is not an obvious implementation detail of clothing extraction and indicates the packaged code includes functionality outside the declared skill purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This file contains user-facing messages such as errors, usage text, and warnings entirely in Chinese. That enforces a specific language for operators without offering a language choice or documenting that the tool is intentionally limited to a Chinese-speaking context.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a specific skill for turning person/street photos into clean white-background flat-lay product images. However, the file documents and implements a '统一生成入口' for all skills, with generic task selection, provider selection, brand injection, and support for text/video capabilities, which is materially broader than the claimed single-purpose clothing extraction behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The request object enables generic model/task execution and explicitly carries video and text mode flags derived from task profiles. For a skill whose stated purpose is extracting clothing into flat-lay product images, built-in support for arbitrary text/video generation is beyond the justified capability surface.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This file’s natural-language comments and user-visible error strings are written exclusively in Chinese, including guidance and parser errors. Under the stated policy, forcing a specific language without user opt-in or a documented locale justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The thrown Error messages at these lines are natural-language output that users or developers may see, and they are only available in Chinese. This enforces a specific language without opt-in and without any visible justification that the tool is region-specific.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The code imports child_process spawning and executes an external CLI backend, introducing an additional execution surface outside the reviewed HTTP-provider logic. Even without shell interpolation, invoking an external binary increases trust and supply-chain risk, especially for a narrowly scoped image-extraction skill that does not obviously need local process execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code fetches remote image URLs and base64-encodes local files for transmission to third-party providers, but there is no visible consent, disclosure, or destination restriction here. For a clothing-extraction skill, users may supply buyer photos or street photos containing people and sensitive context, making silent external transfer a meaningful privacy risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 134)May include surrounding context.

js
model: () => env.GEN_MODEL_OPENAI || 'gpt-image-1',
  describe(req) {
    const ep = req.images?.length ? 'images/edits' : 'images/generations'
    return `POST https://api.openai.com/v1/${ep}  model=${openai.model()} size=${mapSize(req.size)} n=${req.batch}`
  },
  async run(req) {
    const key = env.OPENAI_API_KEY

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

This duplicate finding identifies the same OpenAI edits transmission path. The risk remains that user images are sent off-platform to a third party in a workflow likely to involve personal photos, which matters in this skill context.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 153)May include surrounding context.

js
: await readFile(p)
        fd.append('image[]', new Blob([buf], { type: mimeOf(p) }), path.basename(p))
      }
      r = await fetch('https://api.openai.com/v1/images/edits', {
        method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
      })
    } else {

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

This duplicate finding identifies the same OpenAI edits transmission path. The risk remains that user images are sent off-platform to a third party in a workflow likely to involve personal photos, which matters in this skill context.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 153)May include surrounding context.

js
: await readFile(p)
        fd.append('image[]', new Blob([buf], { type: mimeOf(p) }), path.basename(p))
      }
      r = await fetch('https://api.openai.com/v1/images/edits', {
        method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
      })
    } else {

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This duplicate finding identifies the same OpenAI generations transmission path. Besides prompt exfiltration to a third party, the line also reflects capability drift into unrestricted generation for a skill that should require an input image.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 157)May include surrounding context.

js
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
      })
    } else {
      r = await fetch('https://api.openai.com/v1/images/generations', {
        method: 'POST',
        headers: { authorization: `Bearer ${key}`, 'content-type': 'application/json' },
        body: JSON.stringify({

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/lib/providers.mjs:104

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/gen.mjs:118

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/lib/providers.mjs:21