Back to skill

Security audit

穿搭种草图 Clothing Grass Planting

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent image-generation helper; it does send user prompts and images to selected cloud AI providers, which is expected but privacy-relevant.

Install only if you are comfortable sending prompts and any supplied clothing/model photos to the selected cloud image provider. Use dry-run or explicit provider selection when needed, avoid uploading sensitive personal images without consent, and choose a specific save path for generated outputs.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (21)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 107)May include surrounding context.

md
node scripts/gen.mjs --task clothing-grass-planting \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 164)May include surrounding context.

md
node scripts/gen.mjs --task clothing-grass-planting \

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill instructs use of external tooling and links to provider CLI/docs, implying network access and possible environment-backed credentials, but it does not declare an explicit tool/permission scope. In an agent setting, missing scope boundaries can let the skill run with broader-than-necessary capabilities, increasing the chance of unintended network access, secret exposure, or unreviewed external calls.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The activation phrases are broad and generic, covering common requests like '种草图', '小红书风格', and '换场景发帖', which can cause the skill to trigger in ambiguous contexts. Over-broad triggering is dangerous because it may invoke image editing and file-writing workflows when the user did not clearly consent to this specific transformation.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 11)May include surrounding context.

md
**穿搭不动,人 / 场景 / 姿势全换**,换成社交平台的种草风格。

和 [one-shot](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/one-shot/skill.md) 的区别:one-shot 面向电商主图(保持棚拍规范、构图不动),本技能面向**内容种草**——要的是生活感、抓拍感、氛围光,构图和景别都可以变。

---

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 201)May include surrounding context.

md
## 6、执行流程

1. **洗干净输入**:去掉滤镜、文字贴纸([remove-watermark](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/remove-watermark/skill.md))。
2. **逐件列穿搭**:上装 / 下装 / 鞋 / 包 / 配饰——一件一句,这段整组复用。
3. **定内容主题**:通勤 / 约会 / 旅行 / 居家 / 运动,每个主题对应一组场景 + 动作 + 光线(第三节配方)。
4. **补相机语言**:50mm、浅景深、轻微颗粒——这是「像随手拍」的关键。

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This reference file presents all operational instructions in a single language and does not indicate that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. That can violate language/locale policy when skills are expected to avoid forcing a language without user opt-in.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 134)May include surrounding context.

js
model: () => env.GEN_MODEL_OPENAI || 'gpt-image-1',
  describe(req) {
    const ep = req.images?.length ? 'images/edits' : 'images/generations'
    return `POST https://api.openai.com/v1/${ep}  model=${openai.model()} size=${mapSize(req.size)} n=${req.batch}`
  },
  async run(req) {
    const key = env.OPENAI_API_KEY

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This module sends user prompts and, when provided, local image contents to third-party APIs such as OpenAI, Gemini, fal, Replicate, and Ark. In a skill that transforms user-supplied clothing images, that data flow is expected functionality, but the file provides no explicit consent, warning, or policy gate before transmitting potentially sensitive local files off-device.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

This finding duplicates the actual outbound upload to the OpenAI edit endpoint. Because the skill processes user photos for social-style image generation, external transmission of image content is contextually sensitive and should be treated as a genuine privacy exposure unless users explicitly approve it.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 153)May include surrounding context.

js
: await readFile(p)
        fd.append('image[]', new Blob([buf], { type: mimeOf(p) }), path.basename(p))
      }
      r = await fetch('https://api.openai.com/v1/images/edits', {
        method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
      })
    } else {

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

This finding duplicates the actual outbound upload to the OpenAI edit endpoint. Because the skill processes user photos for social-style image generation, external transmission of image content is contextually sensitive and should be treated as a genuine privacy exposure unless users explicitly approve it.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 153)May include surrounding context.

js
: await readFile(p)
        fd.append('image[]', new Blob([buf], { type: mimeOf(p) }), path.basename(p))
      }
      r = await fetch('https://api.openai.com/v1/images/edits', {
        method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
      })
    } else {

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This finding duplicates the outbound generation request to OpenAI. Even without attached images, sending prompts to a third-party model provider is an external data disclosure that should be controlled and disclosed.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 157)May include surrounding context.

js
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
      })
    } else {
      r = await fetch('https://api.openai.com/v1/images/generations', {
        method: 'POST',
        headers: { authorization: `Bearer ${key}`, 'content-type': 'application/json' },
        body: JSON.stringify({

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This finding duplicates the outbound generation request to OpenAI. Even without attached images, sending prompts to a third-party model provider is an external data disclosure that should be controlled and disclosed.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 157)May include surrounding context.

js
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
      })
    } else {
      r = await fetch('https://api.openai.com/v1/images/generations', {
        method: 'POST',
        headers: { authorization: `Bearer ${key}`, 'content-type': 'application/json' },
        body: JSON.stringify({

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 261)May include surrounding context.

js
model: (req) =>
    env.GEN_MODEL_REPLICATE ||
    (req?.images?.length ? 'black-forest-labs/flux-kontext-pro' : 'black-forest-labs/flux-dev'),
  describe(req) { return `POST https://api.replicate.com/v1/models/${replicate.model(req)}/predictions` },
  async run(req) {
    const input = { prompt: req.prompt, num_outputs: req.batch }
    if (req.images?.length) input.input_image = await asDataUri(req.images[0])

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The Replicate prediction request transmits user prompts and optionally base64-encoded input images to an external service. Given this skill's purpose of transforming clothing photos into social-post-style outputs, those uploads may include personal images and therefore represent a real privacy and data-handling risk if done without explicit consent and governance.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 266)May include surrounding context.

js
const input = { prompt: req.prompt, num_outputs: req.batch }
    if (req.images?.length) input.input_image = await asDataUri(req.images[0])
    const j = await postJson(
      `https://api.replicate.com/v1/models/${replicate.model(req)}/predictions`,
      { input },
      { authorization: `Bearer ${env.REPLICATE_API_TOKEN}`, prefer: 'wait' },
      req.timeoutMs,

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The skill gives detailed instructions for generating edited images and saving them to disk, but does not explicitly warn that user-provided images will be modified and new files will be written. In agent workflows this can surprise users, create unwanted derivative content, or overwrite/store sensitive images without informed consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This markdown file is primarily written in Chinese, but lines L06-L07 introduce a mandatory instruction in English ('CRITICAL INSTRUCTION FOR AGENT'). That creates a language-policy inconsistency without any user opt-in or documented reason for forcing a different language in part of the skill instructions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file's human-readable comments and user-visible error/help strings are written in Chinese, including setup and failure guidance. Under the language policy rule, forcing a specific language without opt-in can be a policy violation when no alternative locale or choice is offered.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The dlazy provider invokes an external executable via spawn, which is a safety-relevant operation under the rule criteria. This file contains no confirmation prompt or user-facing disclosure near execution, and the surrounding comments describe architecture rather than warning the user that a local CLI will be run.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The natural-language note on L02 is written only in Chinese and provides no indication that other languages are supported or that the file is intentionally limited to a Chinese-speaking context. Under the language/locale policy, forcing a specific language without opt-in can be a policy concern when no justification or alternative is provided.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/lib/providers.mjs:104

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/gen.mjs:118

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/lib/providers.mjs:21