Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md node scripts/gen.mjs --task fission-pattern \
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a coherent ecommerce image-generation helper that uploads prompts and product images to chosen cloud image providers as part of its stated purpose.
Install only if you are comfortable sending product photos, prompts, and generated outputs to the selected cloud image provider. Use --dry-run first for cost/request review, keep provider API keys scoped and revocable, and avoid uploading confidential unreleased products or personal images unless your organization approves that provider.
Referenced artifact was not completely inspected
node scripts/gen.mjs --task fission-pattern \
Referenced artifact was not completely inspected
node scripts/gen.mjs --task fission-pattern \
The skill contains explicit command examples invoking external tooling (dlazy, node scripts/gen.mjs) and remote resources, but the manifest does not declare any tool restrictions such as allowed tools or permissions. In a skill system that relies on manifest scoping, this creates an overbroad execution surface where the agent may use networked/code capabilities without an explicit least-privilege boundary.
The description says to use the skill when the user says phrases like “凑够详情页” or “出一套图,” which are generic requests that could arise in ordinary conversation about image editing or content planning. The file does not provide exclusion conditions or negative examples to clarify when these phrases should not trigger this specific skill.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
| ✅ 主视角 + 纯净背景 | 越干净,整套图的商品一致性越高 |
| ✅ 卖点写具体 | `防水防汗` 会带出运动场景,`法式复古` 会带出咖啡馆场景 |
| ✅ 商品结构完整可见 | 套图里的细节图要靠这张图推断结构 |
| ❌ 已经带营销文字的图 | 文字会被复制到每张套图里,先用 [remove-watermark](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/remove-watermark/skill.md) 洗干净 |
| ❌ 商品被手/道具遮挡 | 遮住的部分在每张套图里都会不一样 |
---
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
| ✅ 主视角 + 纯净背景 | 越干净,整套图的商品一致性越高 |
| ✅ 卖点写具体 | `防水防汗` 会带出运动场景,`法式复古` 会带出咖啡馆场景 |
| ✅ 商品结构完整可见 | 套图里的细节图要靠这张图推断结构 |
| ❌ 已经带营销文字的图 | 文字会被复制到每张套图里,先用 [remove-watermark](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/remove-watermark/skill.md) 洗干净 |
| ❌ 商品被手/道具遮挡 | 遮住的部分在每张套图里都会不一样 |
---
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
| 亲肤 / 婴童 | `soft nursery bedding, pastel palette, very soft diffused light` |
| 精密 / 工艺 | `dark navy blueprint paper with a brass ruler, cool directional side light` |
**姿势套图**用的是另一组:正面站姿 / 侧身转头 / 背面回头 / 自然行走 / 坐姿——每条只换姿势段,模特与穿搭段逐字不变(写法可直接复用 [creative-scene](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/creative-scene/skill.md) 的改姿势句式)。
---
The skill hard-codes a protected characteristic ('East Asian woman') for the model without any user choice, documented business necessity, or accessibility/compliance justification. This can systematically bias generated marketing assets toward a single ethnicity, creating discrimination, exclusion, and policy/compliance risk when the skill is reused across many SKUs.
The document states that prompts, local images, and generated outputs are sent to or hosted by cloud endpoints, but it does not require an explicit user-facing warning or consent step before use. In a skill that processes product images and prompts, this can lead to unintended disclosure of proprietary, personal, or otherwise sensitive data if users assume processing is local or do not understand third-party data handling.
The file's human-facing comments and usage/help text are written in Chinese, including operational guidance and error/help messaging. This imposes a specific language/locale on users without offering a choice or documenting that the skill is intentionally region-specific.
The CLI prints template-missing errors and usage instructions solely in Chinese. Because the skill does not offer language selection or justify a locale restriction, this is a natural-language policy issue under the language/locale rule.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The script sends the assembled request to a selected external provider via provider.run(req), which includes the user's prompt and image references. Although the file header describes the tool as a generation entrypoint, there is no confirmation prompt or explicit runtime disclosure that user-supplied content will be transmitted to third-party services.
This helper sends JSON bodies to external services, and multiple providers use it to transmit req.prompt and potentially image data to third-party APIs. The file lacks any user-facing warning, confirmation, or explicit inline disclosure that user content may be uploaded off-box to external providers.
The helper launches an external binary via spawn(), which is a safety-relevant operation for code files under this audit. While there are error messages for failures, there is no confirmation prompt, no user-facing log before execution, and no inline comment/docstring specifically warning that the skill will execute a local CLI command.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
model: () => env.GEN_MODEL_OPENAI || 'gpt-image-1',
describe(req) {
const ep = req.images?.length ? 'images/edits' : 'images/generations'
return `POST https://api.openai.com/v1/${ep} model=${openai.model()} size=${mapSize(req.size)} n=${req.batch}`
},
async run(req) {
const key = env.OPENAI_API_KEY
This is the concrete network transmission point for image edits to OpenAI, carrying uploaded image content and prompt text. In this skill context, that may include internal product photography and derivative asset inputs, making unauthorized or undisclosed third-party sharing potentially harmful.
: await readFile(p)
fd.append('image[]', new Blob([buf], { type: mimeOf(p) }), path.basename(p))
}
r = await fetch('https://api.openai.com/v1/images/edits', {
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
})
} else {
This is the concrete network transmission point for image edits to OpenAI, carrying uploaded image content and prompt text. In this skill context, that may include internal product photography and derivative asset inputs, making unauthorized or undisclosed third-party sharing potentially harmful.
: await readFile(p)
fd.append('image[]', new Blob([buf], { type: mimeOf(p) }), path.basename(p))
}
r = await fetch('https://api.openai.com/v1/images/edits', {
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
})
} else {
This is the actual POST that sends generation prompts to OpenAI. Because the skill is designed for commercial creative workflows, prompts may reveal confidential product claims or launch information, so external transmission is materially risky if not controlled.
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
})
} else {
r = await fetch('https://api.openai.com/v1/images/generations', {
method: 'POST',
headers: { authorization: `Bearer ${key}`, 'content-type': 'application/json' },
body: JSON.stringify({
This is the actual POST that sends generation prompts to OpenAI. Because the skill is designed for commercial creative workflows, prompts may reveal confidential product claims or launch information, so external transmission is materially risky if not controlled.
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
})
} else {
r = await fetch('https://api.openai.com/v1/images/generations', {
method: 'POST',
headers: { authorization: `Bearer ${key}`, 'content-type': 'application/json' },
body: JSON.stringify({
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
model: (req) =>
env.GEN_MODEL_REPLICATE ||
(req?.images?.length ? 'black-forest-labs/flux-kontext-pro' : 'black-forest-labs/flux-dev'),
describe(req) { return `POST https://api.replicate.com/v1/models/${replicate.model(req)}/predictions` },
async run(req) {
const input = { prompt: req.prompt, num_outputs: req.batch }
if (req.images?.length) input.input_image = await asDataUri(req.images[0])
This call sends prompts and possibly a base64-encoded input image to Replicate. In the context of a product-image fission skill, that can expose proprietary images and campaign content to a third-party service, which is a genuine data exfiltration/privacy risk even if functionally intended.
const input = { prompt: req.prompt, num_outputs: req.batch }
if (req.images?.length) input.input_image = await asDataUri(req.images[0])
const j = await postJson(
`https://api.replicate.com/v1/models/${replicate.model(req)}/predictions`,
{ input },
{ authorization: `Bearer ${env.REPLICATE_API_TOKEN}`, prefer: 'wait' },
req.timeoutMs,
The invocation guidance is written as fixed Chinese trigger phrases and the document does not indicate that users may interact in other languages or choose their preferred locale. Under the stated policy, forcing a specific language without opt-in can be a natural-language policy violation.
This file is primarily written in Chinese, but lines L06-L07 introduce a hardcoded English instruction directed at the agent. That creates a natural-language locale inconsistency without any opt-in or justification, which can violate language/locale policy expectations for user-facing skill materials.
The help text lists multiple credential environment variables, indicating the script accesses sensitive API keys to operate. The file does not include a user warning or explanatory comment near execution that credentials will be consumed for outbound provider requests, which reduces transparency for safety-critical credential handling.
Detected: suspicious.dangerous_exec, suspicious.env_credential_access