Back to skill

Security audit

商品图精修 Item Repair

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent product-photo retouching skill, but its bundled runner has broader cloud-generation and URL-fetching authority than the narrow item-repair purpose needs.

Review before installing if you handle confidential product photos, unreleased catalog assets, or restricted customer data. Use it only when you intend to upload images/prompts to a selected cloud provider, prefer local file inputs over arbitrary URLs, use dry-run first, and limit API keys/provider configuration to the provider you actually want to use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (31)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

md
node scripts/gen.mjs --task item-repair \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 163)May include surrounding context.

md
node scripts/gen.mjs --task item-repair \

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill documents direct use of external tooling and network-reliant services (dlazy, remote image/model endpoints, linked references) but does not declare an explicit tool/permission scope. That creates an authorization and review gap: an agent may invoke networked/image-processing capabilities more broadly than intended, making accidental data exfiltration or unreviewed external calls harder to constrain.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger phrases are broad everyday terms like “修图”, “整理一下”, and “拍得不好看”, which can match many unrelated user intents. Over-broad activation can cause the wrong skill to run on unintended images or contexts, leading to unapproved editing, external model calls, and unnecessary transfer of user content to third-party tooling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

The natural-language description and invocation guidance are written entirely in Chinese and present fixed trigger wording without indicating that other languages are supported or that the user can choose a locale. This can constitute a locale policy issue when a skill implicitly requires one language without documenting a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 11)May include surrounding context.

md
把**随手拍的商品图**修成**可上架的精修图**:压平褶皱、摆正对称、匀光、提纯背景。

和 [material-enhancement](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/material-enhancement/skill.md) 的分工:material-enhancement 修**面料纹理**(在模特图上),本技能修**摆放与光照**(在商品图上)。两者可以串起来用。

---

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 200)May include surrounding context.

md
把**随手拍的商品图**修成**可上架的精修图**:压平褶皱、摆正对称、匀光、提纯背景。

和 [material-enhancement](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/material-enhancement/skill.md) 的分工:material-enhancement 修**面料纹理**(在模特图上),本技能修**摆放与光照**(在商品图上)。两者可以串起来用。

---

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The brand configuration hard-codes a specific ethnicity, gender, and age presentation ('East Asian woman, late twenties') as the default model profile for all downstream image-generation skills. In a commercial image-editing pipeline, this can systematically override user intent and produce exclusionary or biased outputs, especially when applied across many SKUs without an explicit business or compliance justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document states that local images and prompts are uploaded to cloud services, but it does not clearly warn users before operation about privacy, confidentiality, or compliance implications. In the context of an image-repair skill handling user-supplied product photos, users may unknowingly send sensitive images, metadata, or proprietary content to third-party providers, increasing the risk of unintended data exposure.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file presents itself as a unified entry point for all skills and accepts a generic --task that selects behavior from lib/tasks.json, rather than being limited to 商品精修/去褶皱. It also contains video/text task handling and provider/model selection logic, which exceeds the manifest's described single-purpose image-retouching scope.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The persist function will fetch any URL returned in f.url and write its contents to disk without validating scheme, host, size, or content type. If an untrusted or compromised provider can influence returned URLs, this can enable server-side request forgery to internal resources, unexpected outbound access, and writing attacker-controlled content to local files.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file's comments and several user-visible error strings are written only in Chinese, which imposes a specific language on users and operators without opt-in. The file does not indicate that the skill is region-specific or that alternate languages are available.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The provider abstraction explicitly supports general text, image, and video generation across multiple backends, which exceeds the stated skill purpose of product-photo retouching and wrinkle removal. In this skill context, that scope expansion matters because it enables off-manifest capabilities and broader outbound data handling that a user would not reasonably expect from a narrowly described repair tool.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill can invoke an external CLI backend via subprocess, expanding execution and supply-chain risk beyond simple image retouching. Although spawn is used without a shell, this still permits reliance on an externally installed binary whose behavior, configuration, network access, and updates are outside this code's control.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code fetches arbitrary URLs from req.images, creating server-side network access that can be abused for SSRF, internal metadata probing, or retrieval of sensitive internal resources. In a retouching skill, accepting remote image URLs may be convenient, but unrestricted fetches materially increase risk because the backend becomes a network proxy.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This module sends request bodies to external providers via fetch/postJson, including prompts and potentially local image contents converted to base64. In this file there is no confirmation prompt, visible user-facing log/print, or comment/docstring warning that user content may be transmitted to third-party APIs.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The OpenAI provider supports pure image generation when no input image is supplied, which is broader than repair/editing of existing product photos. In this skill's context, that mismatch is a real policy and capability issue because it allows the skill to generate unrelated synthetic content under the guise of a repair tool.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 134)May include surrounding context.

js
model: () => env.GEN_MODEL_OPENAI || 'gpt-image-1',
  describe(req) {
    const ep = req.images?.length ? 'images/edits' : 'images/generations'
    return `POST https://api.openai.com/v1/${ep}  model=${openai.model()} size=${mapSize(req.size)} n=${req.batch}`
  },
  async run(req) {
    const key = env.OPENAI_API_KEY

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 153)May include surrounding context.

js
model: () => env.GEN_MODEL_OPENAI || 'gpt-image-1',
  describe(req) {
    const ep = req.images?.length ? 'images/edits' : 'images/generations'
    return `POST https://api.openai.com/v1/${ep}  model=${openai.model()} size=${mapSize(req.size)} n=${req.batch}`
  },
  async run(req) {
    const key = env.OPENAI_API_KEY

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 153)May include surrounding context.

js
: await readFile(p)
        fd.append('image[]', new Blob([buf], { type: mimeOf(p) }), path.basename(p))
      }
      r = await fetch('https://api.openai.com/v1/images/edits', {
        method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
      })
    } else {

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This generation endpoint use permits off-scope synthetic image creation and third-party prompt transmission under a narrowly described repair skill. Because users would expect photo fixing rather than arbitrary generation, this mismatch increases the chance of misuse and undisclosed processing.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 157)May include surrounding context.

js
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
      })
    } else {
      r = await fetch('https://api.openai.com/v1/images/generations', {
        method: 'POST',
        headers: { authorization: `Bearer ${key}`, 'content-type': 'application/json' },
        body: JSON.stringify({

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This generation endpoint use permits off-scope synthetic image creation and third-party prompt transmission under a narrowly described repair skill. Because users would expect photo fixing rather than arbitrary generation, this mismatch increases the chance of misuse and undisclosed processing.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 157)May include surrounding context.

js
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
      })
    } else {
      r = await fetch('https://api.openai.com/v1/images/generations', {
        method: 'POST',
        headers: { authorization: `Bearer ${key}`, 'content-type': 'application/json' },
        body: JSON.stringify({

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 261)May include surrounding context.

js
model: (req) =>
    env.GEN_MODEL_REPLICATE ||
    (req?.images?.length ? 'black-forest-labs/flux-kontext-pro' : 'black-forest-labs/flux-dev'),
  describe(req) { return `POST https://api.replicate.com/v1/models/${replicate.model(req)}/predictions` },
  async run(req) {
    const input = { prompt: req.prompt, num_outputs: req.batch }
    if (req.images?.length) input.input_image = await asDataUri(req.images[0])

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The Replicate integration transmits prompts and optionally image data to a third-party model endpoint that can operate in generation mode, which exceeds the declared photo-repair scope. In this skill context, the main risk is unexpected external processing paired with broader-than-advertised capability.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 266)May include surrounding context.

js
const input = { prompt: req.prompt, num_outputs: req.batch }
    if (req.images?.length) input.input_image = await asDataUri(req.images[0])
    const j = await postJson(
      `https://api.replicate.com/v1/models/${replicate.model(req)}/predictions`,
      { input },
      { authorization: `Bearer ${env.REPLICATE_API_TOKEN}`, prefer: 'wait' },
      req.timeoutMs,

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/lib/providers.mjs:104

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/gen.mjs:118

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/lib/providers.mjs:21