Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md node scripts/gen.mjs --task clothing-grass-planting \
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent image-generation helper; it does send user prompts and images to selected cloud AI providers, which is expected but privacy-relevant.
Install only if you are comfortable sending prompts and any supplied clothing/model photos to the selected cloud image provider. Use dry-run or explicit provider selection when needed, avoid uploading sensitive personal images without consent, and choose a specific save path for generated outputs.
Referenced artifact was not completely inspected
node scripts/gen.mjs --task clothing-grass-planting \
Referenced artifact was not completely inspected
node scripts/gen.mjs --task clothing-grass-planting \
The skill instructs use of external tooling and links to provider CLI/docs, implying network access and possible environment-backed credentials, but it does not declare an explicit tool/permission scope. In an agent setting, missing scope boundaries can let the skill run with broader-than-necessary capabilities, increasing the chance of unintended network access, secret exposure, or unreviewed external calls.
The activation phrases are broad and generic, covering common requests like '种草图', '小红书风格', and '换场景发帖', which can cause the skill to trigger in ambiguous contexts. Over-broad triggering is dangerous because it may invoke image editing and file-writing workflows when the user did not clearly consent to this specific transformation.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
**穿搭不动,人 / 场景 / 姿势全换**,换成社交平台的种草风格。
和 [one-shot](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/one-shot/skill.md) 的区别:one-shot 面向电商主图(保持棚拍规范、构图不动),本技能面向**内容种草**——要的是生活感、抓拍感、氛围光,构图和景别都可以变。
---
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
## 6、执行流程
1. **洗干净输入**:去掉滤镜、文字贴纸([remove-watermark](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/remove-watermark/skill.md))。
2. **逐件列穿搭**:上装 / 下装 / 鞋 / 包 / 配饰——一件一句,这段整组复用。
3. **定内容主题**:通勤 / 约会 / 旅行 / 居家 / 运动,每个主题对应一组场景 + 动作 + 光线(第三节配方)。
4. **补相机语言**:50mm、浅景深、轻微颗粒——这是「像随手拍」的关键。
This reference file presents all operational instructions in a single language and does not indicate that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. That can violate language/locale policy when skills are expected to avoid forcing a language without user opt-in.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
model: () => env.GEN_MODEL_OPENAI || 'gpt-image-1',
describe(req) {
const ep = req.images?.length ? 'images/edits' : 'images/generations'
return `POST https://api.openai.com/v1/${ep} model=${openai.model()} size=${mapSize(req.size)} n=${req.batch}`
},
async run(req) {
const key = env.OPENAI_API_KEY
This module sends user prompts and, when provided, local image contents to third-party APIs such as OpenAI, Gemini, fal, Replicate, and Ark. In a skill that transforms user-supplied clothing images, that data flow is expected functionality, but the file provides no explicit consent, warning, or policy gate before transmitting potentially sensitive local files off-device.
This finding duplicates the actual outbound upload to the OpenAI edit endpoint. Because the skill processes user photos for social-style image generation, external transmission of image content is contextually sensitive and should be treated as a genuine privacy exposure unless users explicitly approve it.
: await readFile(p)
fd.append('image[]', new Blob([buf], { type: mimeOf(p) }), path.basename(p))
}
r = await fetch('https://api.openai.com/v1/images/edits', {
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
})
} else {
This finding duplicates the actual outbound upload to the OpenAI edit endpoint. Because the skill processes user photos for social-style image generation, external transmission of image content is contextually sensitive and should be treated as a genuine privacy exposure unless users explicitly approve it.
: await readFile(p)
fd.append('image[]', new Blob([buf], { type: mimeOf(p) }), path.basename(p))
}
r = await fetch('https://api.openai.com/v1/images/edits', {
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
})
} else {
This finding duplicates the outbound generation request to OpenAI. Even without attached images, sending prompts to a third-party model provider is an external data disclosure that should be controlled and disclosed.
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
})
} else {
r = await fetch('https://api.openai.com/v1/images/generations', {
method: 'POST',
headers: { authorization: `Bearer ${key}`, 'content-type': 'application/json' },
body: JSON.stringify({
This finding duplicates the outbound generation request to OpenAI. Even without attached images, sending prompts to a third-party model provider is an external data disclosure that should be controlled and disclosed.
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
})
} else {
r = await fetch('https://api.openai.com/v1/images/generations', {
method: 'POST',
headers: { authorization: `Bearer ${key}`, 'content-type': 'application/json' },
body: JSON.stringify({
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
model: (req) =>
env.GEN_MODEL_REPLICATE ||
(req?.images?.length ? 'black-forest-labs/flux-kontext-pro' : 'black-forest-labs/flux-dev'),
describe(req) { return `POST https://api.replicate.com/v1/models/${replicate.model(req)}/predictions` },
async run(req) {
const input = { prompt: req.prompt, num_outputs: req.batch }
if (req.images?.length) input.input_image = await asDataUri(req.images[0])
The Replicate prediction request transmits user prompts and optionally base64-encoded input images to an external service. Given this skill's purpose of transforming clothing photos into social-post-style outputs, those uploads may include personal images and therefore represent a real privacy and data-handling risk if done without explicit consent and governance.
const input = { prompt: req.prompt, num_outputs: req.batch }
if (req.images?.length) input.input_image = await asDataUri(req.images[0])
const j = await postJson(
`https://api.replicate.com/v1/models/${replicate.model(req)}/predictions`,
{ input },
{ authorization: `Bearer ${env.REPLICATE_API_TOKEN}`, prefer: 'wait' },
req.timeoutMs,
The skill gives detailed instructions for generating edited images and saving them to disk, but does not explicitly warn that user-provided images will be modified and new files will be written. In agent workflows this can surprise users, create unwanted derivative content, or overwrite/store sensitive images without informed consent.
This markdown file is primarily written in Chinese, but lines L06-L07 introduce a mandatory instruction in English ('CRITICAL INSTRUCTION FOR AGENT'). That creates a language-policy inconsistency without any user opt-in or documented reason for forcing a different language in part of the skill instructions.
The file's human-readable comments and user-visible error/help strings are written in Chinese, including setup and failure guidance. Under the language policy rule, forcing a specific language without opt-in can be a policy violation when no alternative locale or choice is offered.
The dlazy provider invokes an external executable via spawn, which is a safety-relevant operation under the rule criteria. This file contains no confirmation prompt or user-facing disclosure near execution, and the surrounding comments describe architecture rather than warning the user that a local CLI will be run.
The natural-language note on L02 is written only in Chinese and provides no indication that other languages are supported or that the file is intentionally limited to a Chinese-speaking context. Under the language/locale policy, forcing a specific language without opt-in can be a policy concern when no justification or alternative is provided.
Detected: suspicious.dangerous_exec, suspicious.env_credential_access