Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md node scripts/gen.mjs --task flat-lay \
Security audit
Security checks for vulnerabilities and agentic risk
This is a disclosed virtual try-on skill that uploads user-chosen images to image-generation providers and saves outputs locally, with no hidden persistence or destructive behavior found.
Install only if you are comfortable sending garment, reference, and optional face/model images to the selected image-generation provider. Use --dry-run to review the request, set --provider or PROVIDER to avoid surprising backend selection, and avoid uploading personal likenesses or proprietary product images unless you have the rights and consent to do so.
Referenced artifact was not completely inspected
node scripts/gen.mjs --task flat-lay \
Referenced artifact was not completely inspected
node scripts/gen.mjs --task flat-lay \
Importing and using child_process enables local subprocess execution, which is a powerful capability unrelated to a narrowly scoped try-on skill. In this file that capability is later used to invoke an external CLI, creating extra attack surface through PATH resolution, inherited local configuration, and execution of code outside the audited JS logic.
The default route executes a local 'dlazy' command, meaning the skill may run an external program even when no explicit provider is chosen. This is dangerous because the behavior depends on the local environment and CLI configuration, making data handling, execution semantics, and trust boundaries less transparent than direct calls to a narrowly scoped try-on backend.
The skill instructs use of external CLI and network-backed image generation services but does not declare tool scope such as allowed tools or permissions. That creates an authorization and transparency gap: an agent may invoke networked tooling and access environment-backed credentials without an explicit policy boundary, increasing the chance of unintended data exfiltration or overbroad execution.
The skill asks users to upload garment, reference, and optional model-face images and sends them to an external image-generation service, but it does not clearly warn users of that transfer. Because these images can contain personal data, likenesses, proprietary product designs, or sensitive commercial assets, users may unknowingly disclose data to a third party and trigger privacy, consent, or compliance issues.
The skill hard-codes a model as an 'East Asian woman' without indicating that this is user-selectable, required by a justified locale constraint, or limited to a narrowly scoped brand use case. In an image-generation workflow, this can systematically bias outputs, exclude other identities, and create fairness/compliance risks when the tool is used broadly for virtual try-on or commercial content generation.
The document is primarily written in Chinese, but the emphasized agent instruction is only provided in English and is framed as a mandatory instruction. This creates a locale/language inconsistency that can force agent behavior in a specific language without documenting user choice or a justified regional constraint.
该参考文档标题与全文指令均以中文固定呈现,未说明这是区域性/特定受众限定,也未给出用户可选择语言的机制。按规则,强制特定语言而无用户 opt-in 属于自然语言策略违规。
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The provider abstraction is materially broader than the stated flat-lay virtual try-on purpose: the request schema and downstream providers support generic text generation and video/image generation. That mismatch increases the chance the skill can be repurposed for unintended data flows or higher-risk model operations beyond user expectations, even if the code does not itself exploit that capability.
The helper spawns an external CLI process via spawn(bin, args, ...), which is a safety-relevant operation under the code-file warning criteria. Although there is error handling, this file provides no confirmation prompt, user-visible logging, or comment/docstring specifically warning that an external command will be executed on the user's system.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
model: () => env.GEN_MODEL_OPENAI || 'gpt-image-1',
describe(req) {
const ep = req.images?.length ? 'images/edits' : 'images/generations'
return `POST https://api.openai.com/v1/${ep} model=${openai.model()} size=${mapSize(req.size)} n=${req.batch}`
},
async run(req) {
const key = env.OPENAI_API_KEY
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
model: () => env.GEN_MODEL_OPENAI || 'gpt-image-1',
describe(req) {
const ep = req.images?.length ? 'images/edits' : 'images/generations'
return `POST https://api.openai.com/v1/${ep} model=${openai.model()} size=${mapSize(req.size)} n=${req.batch}`
},
async run(req) {
const key = env.OPENAI_API_KEY
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
model: () => env.GEN_MODEL_OPENAI || 'gpt-image-1',
describe(req) {
const ep = req.images?.length ? 'images/edits' : 'images/generations'
return `POST https://api.openai.com/v1/${ep} model=${openai.model()} size=${mapSize(req.size)} n=${req.batch}`
},
async run(req) {
const key = env.OPENAI_API_KEY
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
: await readFile(p)
fd.append('image[]', new Blob([buf], { type: mimeOf(p) }), path.basename(p))
}
r = await fetch('https://api.openai.com/v1/images/edits', {
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
})
} else {
Multiple providers transmit req.prompt and, in some branches, local or fetched image content to third-party APIs such as OpenAI, Gemini, fal, Replicate, and Ark. These outbound HTTP requests are safety-relevant because they may send user or system data off-machine, yet the file lacks user-facing warnings, prompts, or comments explicitly disclosing that behavior.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
})
} else {
r = await fetch('https://api.openai.com/v1/images/generations', {
method: 'POST',
headers: { authorization: `Bearer ${key}`, 'content-type': 'application/json' },
body: JSON.stringify({
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
model: (req) =>
env.GEN_MODEL_REPLICATE ||
(req?.images?.length ? 'black-forest-labs/flux-kontext-pro' : 'black-forest-labs/flux-dev'),
describe(req) { return `POST https://api.replicate.com/v1/models/${replicate.model(req)}/predictions` },
async run(req) {
const input = { prompt: req.prompt, num_outputs: req.batch }
if (req.images?.length) input.input_image = await asDataUri(req.images[0])
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
model: (req) =>
env.GEN_MODEL_REPLICATE ||
(req?.images?.length ? 'black-forest-labs/flux-kontext-pro' : 'black-forest-labs/flux-dev'),
describe(req) { return `POST https://api.replicate.com/v1/models/${replicate.model(req)}/predictions` },
async run(req) {
const input = { prompt: req.prompt, num_outputs: req.batch }
if (req.images?.length) input.input_image = await asDataUri(req.images[0])
The natural-language note in this JSON file is written only in Chinese and provides no indication that language selection is optional or context-specific. For an organizational language/locale policy check, this can constitute a forced locale choice in skill-facing configuration text without user opt-in or documented regional justification.
The text states that English prompts are more stable for garment fidelity, which steers usage toward a specific language without presenting it as an optional preference. Under the policy, language constraints should be opt-in or clearly justified with user choice.
The file's user-facing comments and usage instructions are written exclusively in Chinese, including the top-level description and examples. This creates a natural-language locale constraint without offering an alternative language or documenting why the restriction is necessary.
The console error and usage messages shown to users are emitted only in Chinese. Under the policy, forcing a specific language without opt-in or documented justification is a natural-language policy violation.
The --doctor flow calls credentialReport() to inspect availability of provider credentials referenced in environment variables. While it does not print secret values, the code handles sensitive credential presence and the help text lists the relevant variables, but there is no explicit warning or comment highlighting this sensitive access behavior.
Detected: suspicious.dangerous_exec, suspicious.env_credential_access