Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md node scripts/gen.mjs --task item-change-background \
Security audit
Security checks for vulnerabilities and agentic risk
This skill coherently helps generate product-background images, with expected cloud image-generation uploads and no evidence of hidden persistence, broad local scanning, exfiltration, or destructive behavior.
Before installing, confirm you are comfortable sending selected product photos, prompts, and optional brand reference assets to the chosen image-generation provider. Avoid using unreleased or sensitive product images unless that provider's retention and privacy terms are acceptable, and prefer dry-run/doctor commands first when checking configuration.
Referenced artifact was not completely inspected
node scripts/gen.mjs --task item-change-background \
Referenced artifact was not completely inspected
node scripts/gen.mjs --task item-change-background \
The skill documents executable commands that invoke external tooling and networked image-generation services, but the manifest declares no explicit tool restrictions such as allowed-tools or permissions. In an agent environment, this ambiguity can let the runtime grant broader-than-necessary capabilities, increasing the chance of unintended network access or environment exposure beyond the skill’s narrow purpose.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
| ✅ 纯白/纯色底商品图 | 抠图边界最干净 |
| ✅ 商品完整、主视角 | 出画的部分放进场景后要靠编 |
| ✅ 光线均匀 | 原图有强方向光时,新场景的光向必须跟它一致 |
| ❌ 已在复杂场景里 | 先用 [clothing-extraction](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/clothing-extraction/skill.md) 或抠图洗成白底 |
| ❌ 半透明/反光商品无参照 | 玻璃瓶、镜面商品要靠环境反光才真实,白底图信息不足 |
---
The skill instructs users to upload product images to a third-party image-generation service but does not clearly disclose that those images will be transmitted off-platform. Product photos may contain proprietary designs, embargoed items, EXIF metadata, or other sensitive commercial information, so silent external transfer creates a real confidentiality and compliance risk.
The brand configuration hard-codes a specific ethnicity and gender presentation ('East Asian woman') as the default model identity for all skills, without any user choice, market-specific justification, or documented necessity. In a reusable generation pipeline, this can systematically bias outputs, exclude other identities, and create fairness/compliance issues across product imagery at scale.
This reference file presents all operational instructions in a single language and does not indicate that users may choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified.
This file contains user-facing natural language in Chinese in comments and usage/help text, while the script's stated purpose is to generate English prompt constraints. There is no indication that the skill is intentionally region-specific or that users can opt into the locale, which creates a language-policy issue for mixed-language or non-Chinese users.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The helpers read local files and convert them to base64 or data URIs, and later provider implementations send that content to external APIs. This file contains no user-facing log, confirmation, or warning comment disclosing that local image paths may be uploaded to third-party services.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
model: () => env.GEN_MODEL_OPENAI || 'gpt-image-1',
describe(req) {
const ep = req.images?.length ? 'images/edits' : 'images/generations'
return `POST https://api.openai.com/v1/${ep} model=${openai.model()} size=${mapSize(req.size)} n=${req.batch}`
},
async run(req) {
const key = env.OPENAI_API_KEY
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
model: () => env.GEN_MODEL_OPENAI || 'gpt-image-1',
describe(req) {
const ep = req.images?.length ? 'images/edits' : 'images/generations'
return `POST https://api.openai.com/v1/${ep} model=${openai.model()} size=${mapSize(req.size)} n=${req.batch}`
},
async run(req) {
const key = env.OPENAI_API_KEY
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
model: () => env.GEN_MODEL_OPENAI || 'gpt-image-1',
describe(req) {
const ep = req.images?.length ? 'images/edits' : 'images/generations'
return `POST https://api.openai.com/v1/${ep} model=${openai.model()} size=${mapSize(req.size)} n=${req.batch}`
},
async run(req) {
const key = env.OPENAI_API_KEY
This code sends the user's prompt and image content to the OpenAI API, including reading local files or fetching remote images and attaching them to the request. There is no confirmation prompt, visible log, or warning comment in this file disclosing that user-supplied content is transmitted to a third-party service.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
: await readFile(p)
fd.append('image[]', new Blob([buf], { type: mimeOf(p) }), path.basename(p))
}
r = await fetch('https://api.openai.com/v1/images/edits', {
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
})
} else {
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
})
} else {
r = await fetch('https://api.openai.com/v1/images/generations', {
method: 'POST',
headers: { authorization: `Bearer ${key}`, 'content-type': 'application/json' },
body: JSON.stringify({
The Gemini provider constructs request parts from the user's prompt and optional images, then sends them to Google's generative language endpoint. The file does not include a user-facing warning, confirmation, or explanatory note that this data is uploaded to an external provider.
The fal provider sends prompt data and optional image data, potentially including local images converted to data URIs, to fal.run. No confirmation, warning, or inline disclosure is present to inform users that their content is being transmitted off-system.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
model: (req) =>
env.GEN_MODEL_REPLICATE ||
(req?.images?.length ? 'black-forest-labs/flux-kontext-pro' : 'black-forest-labs/flux-dev'),
describe(req) { return `POST https://api.replicate.com/v1/models/${replicate.model(req)}/predictions` },
async run(req) {
const input = { prompt: req.prompt, num_outputs: req.batch }
if (req.images?.length) input.input_image = await asDataUri(req.images[0])
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
model: (req) =>
env.GEN_MODEL_REPLICATE ||
(req?.images?.length ? 'black-forest-labs/flux-kontext-pro' : 'black-forest-labs/flux-dev'),
describe(req) { return `POST https://api.replicate.com/v1/models/${replicate.model(req)}/predictions` },
async run(req) {
const input = { prompt: req.prompt, num_outputs: req.batch }
if (req.images?.length) input.input_image = await asDataUri(req.images[0])
The Replicate provider packages the user's prompt and optional image input and sends it to the Replicate API. This is a network operation involving potentially sensitive user content, but the file lacks any user-facing notice or warning about the upload.
The Ark provider sends prompts and optional images to a remote Volcengine endpoint, including converting local images to transmissible data URIs. There is no visible disclosure, confirmation, or warning in this file that user content is sent to an external provider.
The natural-language note on this line is written exclusively in Chinese, which can indicate a language-specific policy constraint in a shared configuration artifact. Because there is no accompanying opt-in, alternative locale, or justification that this file is only for a Chinese-language environment, it may violate the requirement not to force a specific language without user choice.
This file is primarily written in Chinese, but the key operational instruction for the agent is given in English as a mandatory directive. That creates a language-policy inconsistency and may force a specific language mode without any user opt-in or stated justification.
The dlazy provider invokes an external CLI via spawn/exec behavior, which is a safety-relevant operation for code files. While the code handles errors, it does not provide a user-facing warning, confirmation, or explanatory comment near execution that the skill will run a local command.
Detected: suspicious.dangerous_exec, suspicious.env_credential_access