Back to skill

Security audit

服装图一键上身 Flat Lay

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed virtual try-on skill that uploads user-chosen images to image-generation providers and saves outputs locally, with no hidden persistence or destructive behavior found.

Install only if you are comfortable sending garment, reference, and optional face/model images to the selected image-generation provider. Use --dry-run to review the request, set --provider or PROVIDER to avoid surprising backend selection, and avoid uploading personal likenesses or proprietary product images unless you have the rights and consent to do so.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (28)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 116)May include surrounding context.

md
node scripts/gen.mjs --task flat-lay \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 162)May include surrounding context.

md
node scripts/gen.mjs --task flat-lay \

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
92% confidence
Finding

Importing and using child_process enables local subprocess execution, which is a powerful capability unrelated to a narrowly scoped try-on skill. In this file that capability is later used to invoke an external CLI, creating extra attack surface through PATH resolution, inherited local configuration, and execution of code outside the audited JS logic.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The default route executes a local 'dlazy' command, meaning the skill may run an external program even when no explicit provider is chosen. This is dangerous because the behavior depends on the local environment and CLI configuration, making data handling, execution semantics, and trust boundaries less transparent than direct calls to a narrowly scoped try-on backend.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill instructs use of external CLI and network-backed image generation services but does not declare tool scope such as allowed tools or permissions. That creates an authorization and transparency gap: an agent may invoke networked tooling and access environment-backed credentials without an explicit policy boundary, increasing the chance of unintended data exfiltration or overbroad execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill asks users to upload garment, reference, and optional model-face images and sends them to an external image-generation service, but it does not clearly warn users of that transfer. Because these images can contain personal data, likenesses, proprietary product designs, or sensitive commercial assets, users may unknowingly disclose data to a third party and trigger privacy, consent, or compliance issues.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill hard-codes a model as an 'East Asian woman' without indicating that this is user-selectable, required by a justified locale constraint, or limited to a narrowly scoped brand use case. In an image-generation workflow, this can systematically bias outputs, exclude other identities, and create fairness/compliance risks when the tool is used broadly for virtual try-on or commercial content generation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The document is primarily written in Chinese, but the emphasized agent instruction is only provided in English and is framed as a mandatory instruction. This creates a locale/language inconsistency that can force agent behavior in a specific language without documenting user choice or a justified regional constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

该参考文档标题与全文指令均以中文固定呈现,未说明这是区域性/特定受众限定,也未给出用户可选择语言的机制。按规则,强制特定语言而无用户 opt-in 属于自然语言策略违规。

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The provider abstraction is materially broader than the stated flat-lay virtual try-on purpose: the request schema and downstream providers support generic text generation and video/image generation. That mismatch increases the chance the skill can be repurposed for unintended data flows or higher-risk model operations beyond user expectations, even if the code does not itself exploit that capability.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The helper spawns an external CLI process via spawn(bin, args, ...), which is a safety-relevant operation under the code-file warning criteria. Although there is error handling, this file provides no confirmation prompt, user-visible logging, or comment/docstring specifically warning that an external command will be executed on the user's system.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 134)May include surrounding context.

js
model: () => env.GEN_MODEL_OPENAI || 'gpt-image-1',
  describe(req) {
    const ep = req.images?.length ? 'images/edits' : 'images/generations'
    return `POST https://api.openai.com/v1/${ep}  model=${openai.model()} size=${mapSize(req.size)} n=${req.batch}`
  },
  async run(req) {
    const key = env.OPENAI_API_KEY

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 153)May include surrounding context.

js
model: () => env.GEN_MODEL_OPENAI || 'gpt-image-1',
  describe(req) {
    const ep = req.images?.length ? 'images/edits' : 'images/generations'
    return `POST https://api.openai.com/v1/${ep}  model=${openai.model()} size=${mapSize(req.size)} n=${req.batch}`
  },
  async run(req) {
    const key = env.OPENAI_API_KEY

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 157)May include surrounding context.

js
model: () => env.GEN_MODEL_OPENAI || 'gpt-image-1',
  describe(req) {
    const ep = req.images?.length ? 'images/edits' : 'images/generations'
    return `POST https://api.openai.com/v1/${ep}  model=${openai.model()} size=${mapSize(req.size)} n=${req.batch}`
  },
  async run(req) {
    const key = env.OPENAI_API_KEY

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 153)May include surrounding context.

js
: await readFile(p)
        fd.append('image[]', new Blob([buf], { type: mimeOf(p) }), path.basename(p))
      }
      r = await fetch('https://api.openai.com/v1/images/edits', {
        method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
      })
    } else {

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Multiple providers transmit req.prompt and, in some branches, local or fetched image content to third-party APIs such as OpenAI, Gemini, fal, Replicate, and Ark. These outbound HTTP requests are safety-relevant because they may send user or system data off-machine, yet the file lacks user-facing warnings, prompts, or comments explicitly disclosing that behavior.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 157)May include surrounding context.

js
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
      })
    } else {
      r = await fetch('https://api.openai.com/v1/images/generations', {
        method: 'POST',
        headers: { authorization: `Bearer ${key}`, 'content-type': 'application/json' },
        body: JSON.stringify({

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 261)May include surrounding context.

js
model: (req) =>
    env.GEN_MODEL_REPLICATE ||
    (req?.images?.length ? 'black-forest-labs/flux-kontext-pro' : 'black-forest-labs/flux-dev'),
  describe(req) { return `POST https://api.replicate.com/v1/models/${replicate.model(req)}/predictions` },
  async run(req) {
    const input = { prompt: req.prompt, num_outputs: req.batch }
    if (req.images?.length) input.input_image = await asDataUri(req.images[0])

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 266)May include surrounding context.

js
model: (req) =>
    env.GEN_MODEL_REPLICATE ||
    (req?.images?.length ? 'black-forest-labs/flux-kontext-pro' : 'black-forest-labs/flux-dev'),
  describe(req) { return `POST https://api.replicate.com/v1/models/${replicate.model(req)}/predictions` },
  async run(req) {
    const input = { prompt: req.prompt, num_outputs: req.batch }
    if (req.images?.length) input.input_image = await asDataUri(req.images[0])

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language note in this JSON file is written only in Chinese and provides no indication that language selection is optional or context-specific. For an organizational language/locale policy check, this can constitute a forced locale choice in skill-facing configuration text without user opt-in or documented regional justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The text states that English prompts are more stable for garment fidelity, which steers usage toward a specific language without presenting it as an optional preference. Under the policy, language constraints should be opt-in or clearly justified with user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file's user-facing comments and usage instructions are written exclusively in Chinese, including the top-level description and examples. This creates a natural-language locale constraint without offering an alternative language or documenting why the restriction is necessary.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The console error and usage messages shown to users are emitted only in Chinese. Under the policy, forcing a specific language without opt-in or documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The --doctor flow calls credentialReport() to inspect availability of provider credentials referenced in environment variables. While it does not print secret values, the code handles sensitive credential presence and the help text lists the relevant variables, but there is no explicit warning or comment highlighting this sensitive access behavior.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/lib/providers.mjs:104

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/gen.mjs:118

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/lib/providers.mjs:21