Back to skill

Security audit

一键替换服装面料 Fabric on Body

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently replaces garment fabrics in images, with expected cloud image-generation behavior that is mostly disclosed.

Before installing, be comfortable sending prompts and garment or fabric images to the selected image-generation provider. Avoid confidential images unless the provider terms fit your use case, use `--dry-run` to preview requests, and pin or verify any optional external install commands rather than running unpinned network installs blindly.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (25)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 113)May include surrounding context.

md
node scripts/gen.mjs --task fabric-on-body \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 169)May include surrounding context.

md
node scripts/gen.mjs --task fabric-on-body \

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description is written entirely in Chinese and specifies trigger phrases only in Chinese, which implies the skill is intended to operate in that language by default. Under the policy, language constraints should either offer user choice or be clearly documented as justified for a region-specific use case.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill body is predominantly Chinese-language instructional content, but it does not explain that the locale is intentionally limited or provide an alternative language path. This can violate language/locale policy when a skill effectively forces one language without user opt-in.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

md
| --- | --- |
| 面料图拍太远 | 看不清织纹,只会当成一块纯色 |
| 面料图带强环境色 | 黄光下拍的白布会换成米黄色 |
| 版式图有复杂印花 | 原印花会和新面料打架,先用 [item-repair](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/item-repair/skill.md) 或换素图 |
| 面料与品类不匹配 | 硬挺牛仔布做不出吊带裙的垂坠,模型会硬凑 |

---

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The brand configuration hard-codes a model description as 'East Asian woman', which imposes a protected demographic attribute without any documented user choice, market-specific necessity, or compliance justification. In an image-generation pipeline used across many SKUs, this can systematically bias outputs, exclude representation options, and create discrimination, fairness, or policy-compliance risk at scale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

L136-L142 的自然语言指令全部以中文规定 Agent 应如何向用户反馈错误与后续操作,但文档中没有提供语言/locale 选择,也没有说明该技能仅面向中文用户或特定地区。根据规则,未获用户选择即强制单一语言属于自然语言层面的 locale policy 问题。

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The script instructs users to run npx skills add ... without pinning a specific package version. This can cause users to fetch whatever version is current at execution time, creating a supply-chain risk if a malicious or compromised release is published or if behavior changes unexpectedly.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 134)May include surrounding context.

js
model: () => env.GEN_MODEL_OPENAI || 'gpt-image-1',
  describe(req) {
    const ep = req.images?.length ? 'images/edits' : 'images/generations'
    return `POST https://api.openai.com/v1/${ep}  model=${openai.model()} size=${mapSize(req.size)} n=${req.batch}`
  },
  async run(req) {
    const key = env.OPENAI_API_KEY

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 153)May include surrounding context.

js
model: () => env.GEN_MODEL_OPENAI || 'gpt-image-1',
  describe(req) {
    const ep = req.images?.length ? 'images/edits' : 'images/generations'
    return `POST https://api.openai.com/v1/${ep}  model=${openai.model()} size=${mapSize(req.size)} n=${req.batch}`
  },
  async run(req) {
    const key = env.OPENAI_API_KEY

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 157)May include surrounding context.

js
model: () => env.GEN_MODEL_OPENAI || 'gpt-image-1',
  describe(req) {
    const ep = req.images?.length ? 'images/edits' : 'images/generations'
    return `POST https://api.openai.com/v1/${ep}  model=${openai.model()} size=${mapSize(req.size)} n=${req.batch}`
  },
  async run(req) {
    const key = env.OPENAI_API_KEY

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code sends req.prompt and, in several providers, req.images content to external APIs such as OpenAI, Gemini, fal, Replicate, and Ark. Although these network calls are core functionality, this file contains no user-facing log, confirmation, or explanatory comment warning that local files or referenced URLs may be uploaded to third-party services.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 153)May include surrounding context.

js
: await readFile(p)
        fd.append('image[]', new Blob([buf], { type: mimeOf(p) }), path.basename(p))
      }
      r = await fetch('https://api.openai.com/v1/images/edits', {
        method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
      })
    } else {

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 157)May include surrounding context.

js
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
      })
    } else {
      r = await fetch('https://api.openai.com/v1/images/generations', {
        method: 'POST',
        headers: { authorization: `Bearer ${key}`, 'content-type': 'application/json' },
        body: JSON.stringify({

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 261)May include surrounding context.

js
model: (req) =>
    env.GEN_MODEL_REPLICATE ||
    (req?.images?.length ? 'black-forest-labs/flux-kontext-pro' : 'black-forest-labs/flux-dev'),
  describe(req) { return `POST https://api.replicate.com/v1/models/${replicate.model(req)}/predictions` },
  async run(req) {
    const input = { prompt: req.prompt, num_outputs: req.batch }
    if (req.images?.length) input.input_image = await asDataUri(req.images[0])

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 266)May include surrounding context.

js
model: (req) =>
    env.GEN_MODEL_REPLICATE ||
    (req?.images?.length ? 'black-forest-labs/flux-kontext-pro' : 'black-forest-labs/flux-dev'),
  describe(req) { return `POST https://api.replicate.com/v1/models/${replicate.model(req)}/predictions` },
  async run(req) {
    const input = { prompt: req.prompt, num_outputs: req.batch }
    if (req.images?.length) input.input_image = await asDataUri(req.images[0])

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language note at L02 is written only in Chinese and provides no indication that users can opt into another language or locale. This can violate a language/locale policy when a skill or its configuration assumes a specific language without documenting that constraint or offering choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document is primarily written in Chinese, but the prominently labeled critical instruction is forced into English with no user opt-in or stated reason. This can violate a language/locale policy requiring consistent or user-selectable language presentation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file contains natural-language comments and user-facing CLI output in Chinese, including usage/help text and error messages elsewhere in the file, without offering a language choice. That can violate a language/locale policy when users are not explicitly opted into Chinese-only interaction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script emits error, usage, and warning text only in Chinese, such as the template-missing error and usage banner. Because there is no opt-in or locale selection, the file enforces a specific language for end users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code contains only Chinese natural-language comments and later emits Chinese error messages, which imposes a specific language/locale on maintainers and potentially users without any opt-in or documented regional scope. The policy explicitly calls for flagging language or locale constraints when they are forced rather than offered as a choice or justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The thrown error strings at these lines are natural-language outputs and are hard-coded in Chinese, which forces a specific language for anyone consuming parser errors. There is no visible opt-in, locale negotiation, or justification that this parser is region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The file's natural-language guidance and operational comments are written only in Chinese, including usage-critical instructions and error/help text. For an organizational language policy check, this can be a locale constraint without explicit user choice or documented justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The dlazy provider invokes an external binary via spawn, which is a safety-relevant operation under this rule. This file does not provide a user-facing warning, confirmation, or explanatory comment near execution to disclose that an external CLI will be run with prompt and image arguments.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/lib/providers.mjs:104

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/gen.mjs:118

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/lib/providers.mjs:21