Back to skill

Security audit

商品换背景 Item Change Background

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently helps generate product-background images, with expected cloud image-generation uploads and no evidence of hidden persistence, broad local scanning, exfiltration, or destructive behavior.

Before installing, confirm you are comfortable sending selected product photos, prompts, and optional brand reference assets to the chosen image-generation provider. Avoid using unreleased or sensitive product images unless that provider's retention and privacy terms are acceptable, and prefer dry-run/doctor commands first when checking configuration.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (25)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 110)May include surrounding context.

md
node scripts/gen.mjs --task item-change-background \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 172)May include surrounding context.

md
node scripts/gen.mjs --task item-change-background \

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill documents executable commands that invoke external tooling and networked image-generation services, but the manifest declares no explicit tool restrictions such as allowed-tools or permissions. In an agent environment, this ambiguity can let the runtime grant broader-than-necessary capabilities, increasing the chance of unintended network access or environment exposure beyond the skill’s narrow purpose.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

md
| ✅ 纯白/纯色底商品图 | 抠图边界最干净 |
| ✅ 商品完整、主视角 | 出画的部分放进场景后要靠编 |
| ✅ 光线均匀 | 原图有强方向光时,新场景的光向必须跟它一致 |
| ❌ 已在复杂场景里 | 先用 [clothing-extraction](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/clothing-extraction/skill.md) 或抠图洗成白底 |
| ❌ 半透明/反光商品无参照 | 玻璃瓶、镜面商品要靠环境反光才真实,白底图信息不足 |

---

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs users to upload product images to a third-party image-generation service but does not clearly disclose that those images will be transmitted off-platform. Product photos may contain proprietary designs, embargoed items, EXIF metadata, or other sensitive commercial information, so silent external transfer creates a real confidentiality and compliance risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The brand configuration hard-codes a specific ethnicity and gender presentation ('East Asian woman') as the default model identity for all skills, without any user choice, market-specific justification, or documented necessity. In a reusable generation pipeline, this can systematically bias outputs, exclude other identities, and create fairness/compliance issues across product imagery at scale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This reference file presents all operational instructions in a single language and does not indicate that users may choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This file contains user-facing natural language in Chinese in comments and usage/help text, while the script's stated purpose is to generate English prompt constraints. There is no indication that the skill is intentionally region-specific or that users can opt into the locale, which creates a language-policy issue for mixed-language or non-Chinese users.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The helpers read local files and convert them to base64 or data URIs, and later provider implementations send that content to external APIs. This file contains no user-facing log, confirmation, or warning comment disclosing that local image paths may be uploaded to third-party services.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 134)May include surrounding context.

js
model: () => env.GEN_MODEL_OPENAI || 'gpt-image-1',
  describe(req) {
    const ep = req.images?.length ? 'images/edits' : 'images/generations'
    return `POST https://api.openai.com/v1/${ep}  model=${openai.model()} size=${mapSize(req.size)} n=${req.batch}`
  },
  async run(req) {
    const key = env.OPENAI_API_KEY

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 153)May include surrounding context.

js
model: () => env.GEN_MODEL_OPENAI || 'gpt-image-1',
  describe(req) {
    const ep = req.images?.length ? 'images/edits' : 'images/generations'
    return `POST https://api.openai.com/v1/${ep}  model=${openai.model()} size=${mapSize(req.size)} n=${req.batch}`
  },
  async run(req) {
    const key = env.OPENAI_API_KEY

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 157)May include surrounding context.

js
model: () => env.GEN_MODEL_OPENAI || 'gpt-image-1',
  describe(req) {
    const ep = req.images?.length ? 'images/edits' : 'images/generations'
    return `POST https://api.openai.com/v1/${ep}  model=${openai.model()} size=${mapSize(req.size)} n=${req.batch}`
  },
  async run(req) {
    const key = env.OPENAI_API_KEY

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code sends the user's prompt and image content to the OpenAI API, including reading local files or fetching remote images and attaching them to the request. There is no confirmation prompt, visible log, or warning comment in this file disclosing that user-supplied content is transmitted to a third-party service.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 153)May include surrounding context.

js
: await readFile(p)
        fd.append('image[]', new Blob([buf], { type: mimeOf(p) }), path.basename(p))
      }
      r = await fetch('https://api.openai.com/v1/images/edits', {
        method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
      })
    } else {

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 157)May include surrounding context.

js
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
      })
    } else {
      r = await fetch('https://api.openai.com/v1/images/generations', {
        method: 'POST',
        headers: { authorization: `Bearer ${key}`, 'content-type': 'application/json' },
        body: JSON.stringify({

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The Gemini provider constructs request parts from the user's prompt and optional images, then sends them to Google's generative language endpoint. The file does not include a user-facing warning, confirmation, or explanatory note that this data is uploaded to an external provider.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The fal provider sends prompt data and optional image data, potentially including local images converted to data URIs, to fal.run. No confirmation, warning, or inline disclosure is present to inform users that their content is being transmitted off-system.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 261)May include surrounding context.

js
model: (req) =>
    env.GEN_MODEL_REPLICATE ||
    (req?.images?.length ? 'black-forest-labs/flux-kontext-pro' : 'black-forest-labs/flux-dev'),
  describe(req) { return `POST https://api.replicate.com/v1/models/${replicate.model(req)}/predictions` },
  async run(req) {
    const input = { prompt: req.prompt, num_outputs: req.batch }
    if (req.images?.length) input.input_image = await asDataUri(req.images[0])

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 266)May include surrounding context.

js
model: (req) =>
    env.GEN_MODEL_REPLICATE ||
    (req?.images?.length ? 'black-forest-labs/flux-kontext-pro' : 'black-forest-labs/flux-dev'),
  describe(req) { return `POST https://api.replicate.com/v1/models/${replicate.model(req)}/predictions` },
  async run(req) {
    const input = { prompt: req.prompt, num_outputs: req.batch }
    if (req.images?.length) input.input_image = await asDataUri(req.images[0])

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The Replicate provider packages the user's prompt and optional image input and sends it to the Replicate API. This is a network operation involving potentially sensitive user content, but the file lacks any user-facing notice or warning about the upload.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The Ark provider sends prompts and optional images to a remote Volcengine endpoint, including converting local images to transmissible data URIs. There is no visible disclosure, confirmation, or warning in this file that user content is sent to an external provider.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language note on this line is written exclusively in Chinese, which can indicate a language-specific policy constraint in a shared configuration artifact. Because there is no accompanying opt-in, alternative locale, or justification that this file is only for a Chinese-language environment, it may violate the requirement not to force a specific language without user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

This file is primarily written in Chinese, but the key operational instruction for the agent is given in English as a mandatory directive. That creates a language-policy inconsistency and may force a specific language mode without any user opt-in or stated justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The dlazy provider invokes an external CLI via spawn/exec behavior, which is a safety-relevant operation for code files. While the code handles errors, it does not provide a user-facing warning, confirmation, or explanatory comment near execution that the skill will run a local command.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/lib/providers.mjs:104

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/gen.mjs:118

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/lib/providers.mjs:21