Back to skill

Security audit

一图裂变套图 Fission Pattern

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent ecommerce image-generation helper that uploads prompts and product images to chosen cloud image providers as part of its stated purpose.

Install only if you are comfortable sending product photos, prompts, and generated outputs to the selected cloud image provider. Use --dry-run first for cost/request review, keep provider API keys scoped and revocable, and avoid uploading confidential unreleased products or personal images unless your organization approves that provider.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (27)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 128)May include surrounding context.

md
node scripts/gen.mjs --task fission-pattern \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 188)May include surrounding context.

md
node scripts/gen.mjs --task fission-pattern \

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill contains explicit command examples invoking external tooling (dlazy, node scripts/gen.mjs) and remote resources, but the manifest does not declare any tool restrictions such as allowed tools or permissions. In a skill system that relies on manifest scoping, this creates an overbroad execution surface where the agent may use networked/code capabilities without an explicit least-privilege boundary.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The description says to use the skill when the user says phrases like “凑够详情页” or “出一套图,” which are generic requests that could arise in ordinary conversation about image editing or content planning. The file does not provide exclusion conditions or negative examples to clarify when these phrases should not trigger this specific skill.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
| ✅ 主视角 + 纯净背景 | 越干净,整套图的商品一致性越高 |
| ✅ 卖点写具体 | `防水防汗` 会带出运动场景,`法式复古` 会带出咖啡馆场景 |
| ✅ 商品结构完整可见 | 套图里的细节图要靠这张图推断结构 |
| ❌ 已经带营销文字的图 | 文字会被复制到每张套图里,先用 [remove-watermark](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/remove-watermark/skill.md) 洗干净 |
| ❌ 商品被手/道具遮挡 | 遮住的部分在每张套图里都会不一样 |

---

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 225)May include surrounding context.

md
| ✅ 主视角 + 纯净背景 | 越干净,整套图的商品一致性越高 |
| ✅ 卖点写具体 | `防水防汗` 会带出运动场景,`法式复古` 会带出咖啡馆场景 |
| ✅ 商品结构完整可见 | 套图里的细节图要靠这张图推断结构 |
| ❌ 已经带营销文字的图 | 文字会被复制到每张套图里,先用 [remove-watermark](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/remove-watermark/skill.md) 洗干净 |
| ❌ 商品被手/道具遮挡 | 遮住的部分在每张套图里都会不一样 |

---

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 114)May include surrounding context.

md
| 亲肤 / 婴童 | `soft nursery bedding, pastel palette, very soft diffused light` |
| 精密 / 工艺 | `dark navy blueprint paper with a brass ruler, cool directional side light` |

**姿势套图**用的是另一组:正面站姿 / 侧身转头 / 背面回头 / 自然行走 / 坐姿——每条只换姿势段,模特与穿搭段逐字不变(写法可直接复用 [creative-scene](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/creative-scene/skill.md) 的改姿势句式)。

---

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill hard-codes a protected characteristic ('East Asian woman') for the model without any user choice, documented business necessity, or accessibility/compliance justification. This can systematically bias generated marketing assets toward a single ethnicity, creating discrimination, exclusion, and policy/compliance risk when the skill is reused across many SKUs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document states that prompts, local images, and generated outputs are sent to or hosted by cloud endpoints, but it does not require an explicit user-facing warning or consent step before use. In a skill that processes product images and prompts, this can lead to unintended disclosure of proprietary, personal, or otherwise sensitive data if users assume processing is local or do not understand third-party data handling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file's human-facing comments and usage/help text are written in Chinese, including operational guidance and error/help messaging. This imposes a specific language/locale on users without offering a choice or documenting that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The CLI prints template-missing errors and usage instructions solely in Chinese. Because the skill does not offer language selection or justify a locale restriction, this is a natural-language policy issue under the language/locale rule.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script sends the assembled request to a selected external provider via provider.run(req), which includes the user's prompt and image references. Although the file header describes the tool as a generation entrypoint, there is no confirmation prompt or explicit runtime disclosure that user-supplied content will be transmitted to third-party services.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This helper sends JSON bodies to external services, and multiple providers use it to transmit req.prompt and potentially image data to third-party APIs. The file lacks any user-facing warning, confirmation, or explicit inline disclosure that user content may be uploaded off-box to external providers.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The helper launches an external binary via spawn(), which is a safety-relevant operation for code files under this audit. While there are error messages for failures, there is no confirmation prompt, no user-facing log before execution, and no inline comment/docstring specifically warning that the skill will execute a local CLI command.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 134)May include surrounding context.

js
model: () => env.GEN_MODEL_OPENAI || 'gpt-image-1',
  describe(req) {
    const ep = req.images?.length ? 'images/edits' : 'images/generations'
    return `POST https://api.openai.com/v1/${ep}  model=${openai.model()} size=${mapSize(req.size)} n=${req.batch}`
  },
  async run(req) {
    const key = env.OPENAI_API_KEY

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This is the concrete network transmission point for image edits to OpenAI, carrying uploaded image content and prompt text. In this skill context, that may include internal product photography and derivative asset inputs, making unauthorized or undisclosed third-party sharing potentially harmful.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 153)May include surrounding context.

js
: await readFile(p)
        fd.append('image[]', new Blob([buf], { type: mimeOf(p) }), path.basename(p))
      }
      r = await fetch('https://api.openai.com/v1/images/edits', {
        method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
      })
    } else {

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This is the concrete network transmission point for image edits to OpenAI, carrying uploaded image content and prompt text. In this skill context, that may include internal product photography and derivative asset inputs, making unauthorized or undisclosed third-party sharing potentially harmful.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 153)May include surrounding context.

js
: await readFile(p)
        fd.append('image[]', new Blob([buf], { type: mimeOf(p) }), path.basename(p))
      }
      r = await fetch('https://api.openai.com/v1/images/edits', {
        method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
      })
    } else {

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

This is the actual POST that sends generation prompts to OpenAI. Because the skill is designed for commercial creative workflows, prompts may reveal confidential product claims or launch information, so external transmission is materially risky if not controlled.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 157)May include surrounding context.

js
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
      })
    } else {
      r = await fetch('https://api.openai.com/v1/images/generations', {
        method: 'POST',
        headers: { authorization: `Bearer ${key}`, 'content-type': 'application/json' },
        body: JSON.stringify({

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

This is the actual POST that sends generation prompts to OpenAI. Because the skill is designed for commercial creative workflows, prompts may reveal confidential product claims or launch information, so external transmission is materially risky if not controlled.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 157)May include surrounding context.

js
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
      })
    } else {
      r = await fetch('https://api.openai.com/v1/images/generations', {
        method: 'POST',
        headers: { authorization: `Bearer ${key}`, 'content-type': 'application/json' },
        body: JSON.stringify({

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 261)May include surrounding context.

js
model: (req) =>
    env.GEN_MODEL_REPLICATE ||
    (req?.images?.length ? 'black-forest-labs/flux-kontext-pro' : 'black-forest-labs/flux-dev'),
  describe(req) { return `POST https://api.replicate.com/v1/models/${replicate.model(req)}/predictions` },
  async run(req) {
    const input = { prompt: req.prompt, num_outputs: req.batch }
    if (req.images?.length) input.input_image = await asDataUri(req.images[0])

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

This call sends prompts and possibly a base64-encoded input image to Replicate. In the context of a product-image fission skill, that can expose proprietary images and campaign content to a third-party service, which is a genuine data exfiltration/privacy risk even if functionally intended.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 266)May include surrounding context.

js
const input = { prompt: req.prompt, num_outputs: req.batch }
    if (req.images?.length) input.input_image = await asDataUri(req.images[0])
    const j = await postJson(
      `https://api.replicate.com/v1/models/${replicate.model(req)}/predictions`,
      { input },
      { authorization: `Bearer ${env.REPLICATE_API_TOKEN}`, prefer: 'wait' },
      req.timeoutMs,

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The invocation guidance is written as fixed Chinese trigger phrases and the document does not indicate that users may interact in other languages or choose their preferred locale. Under the stated policy, forcing a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This file is primarily written in Chinese, but lines L06-L07 introduce a hardcoded English instruction directed at the agent. That creates a natural-language locale inconsistency without any opt-in or justification, which can violate language/locale policy expectations for user-facing skill materials.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The help text lists multiple credential environment variables, indicating the script accesses sensitive API keys to operate. The file does not include a user warning or explanatory comment near execution that credentials will be consumed for outbound provider requests, which reduces transparency for safety-critical credential handling.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/lib/providers.mjs:104

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/gen.mjs:118

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/lib/providers.mjs:21