Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md node scripts/gen.mjs --task material-enhancement \
Security audit
Security checks for vulnerabilities and agentic risk
This appears to be a real image-enhancement skill, but it ships a broader cloud-generation helper that can send images to third parties and run unrelated tasks beyond material enhancement.
Review this skill before installing if you work with proprietary product photos. Use it only with images you are allowed to send to the selected provider, prefer --dry-run first, avoid remote image URLs from untrusted sources, and restrict provider credentials/environment variables to the service you intend to use. The material-enhancement workflow itself is coherent, but the bundled generator is broader than the advertised task.
Referenced artifact was not completely inspected
node scripts/gen.mjs --task material-enhancement \
Referenced artifact was not completely inspected
node scripts/gen.mjs --task material-enhancement \
The skill invokes external CLI tooling and references network-accessible resources, but it does not declare any explicit tool or permission scope. In an agent environment, this weakens least-privilege guarantees and can allow unintended access to environment variables or networked backends if the skill is auto-enabled or executed with broader runtime privileges than necessary.
The trigger phrases are broad enough to match common image-editing requests, which can cause the agent to invoke this skill in situations the user did not intend. Misrouting is primarily a safety and reliability issue here, but it can also lead to unnecessary external tool calls, unintended data transfer, or cost-incurring image processing.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
| --- | --- |
| 面料表面纹理、微观细节、褶皱阴影层次、纤维光泽 | 构图、模特(脸/发/手/姿势)、其他服饰、背景、色调、服装轮廓与颜色 |
**不做**:不改服装轮廓与颜色;不改模特与背景;不把一种面料换成另一种(换面料请用 [fabric-on-body](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/fabric-on-body/skill.md))。
---
The skill hard-codes a model description including ethnicity, age range, and body type without indicating that these are user-selectable or required by a justified business or locale constraint. In an image-generation pipeline used across many SKUs, this can systematically enforce exclusionary representation and produce biased outputs at scale.
该文件的标题与全文说明均以中文固定呈现,且未见任何允许用户选择语言或说明仅面向特定中文使用场景的文字。按照语言/地区策略,若技能或参考文档强制单一语言而无用户选择或合理限定,属于自然语言层面的策略问题。
Several user-facing CLI messages are hard-coded in Chinese, including error text and usage/help output. This creates a language/locale policy concern because the skill does not provide user opt-in, fallback, or documentation that the tool is intended only for Chinese-speaking users or a region-specific environment.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The script persists provider output to disk and, when a file buffer is absent, fetches arbitrary remote URLs and writes the resulting bytes locally. This creates implicit network egress and filesystem modification behavior that may surprise users, and if a compromised or untrusted provider returns attacker-controlled URLs, the script could download unintended content or very large files into the local environment.
The module imports child_process.spawn and uses it to invoke an external 'dlazy' CLI as a provider backend. Launching arbitrary external binaries is a stronger capability than is ordinarily justified by a skill whose stated purpose is image material enhancement, especially when network-backed providers already exist for the same function.
The code fetches arbitrary user-supplied URLs and converts them to base64 for downstream processing. This creates a server-side request forgery and data exfiltration risk, because an attacker can make the service reach internal hosts, cloud metadata endpoints, or other sensitive network resources under the guise of loading an image.
This provider layer materially exceeds the stated purpose of a texture-enhancement skill. It supports generic image generation, video-oriented outputs, and text outputs across multiple backends, which broadens the skill’s capability surface and can enable unintended data flows or misuse outside the manifest-declared scope.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
model: () => env.GEN_MODEL_OPENAI || 'gpt-image-1',
describe(req) {
const ep = req.images?.length ? 'images/edits' : 'images/generations'
return `POST https://api.openai.com/v1/${ep} model=${openai.model()} size=${mapSize(req.size)} n=${req.batch}`
},
async run(req) {
const key = env.OPENAI_API_KEY
The HTTP providers send user prompts and referenced images to third-party services, but this file contains no guardrails, disclosure hooks, or consent checks. In a media-enhancement skill, input images may contain proprietary product photos or sensitive data, so silent external transmission increases privacy and compliance risk.
This is an actual network POST to a third-party API carrying user content, so it represents a real external transmission boundary. In the context of an image-enhancement skill, this matters because the code may forward user-provided images without any in-file privacy gating.
: await readFile(p)
fd.append('image[]', new Blob([buf], { type: mimeOf(p) }), path.basename(p))
}
r = await fetch('https://api.openai.com/v1/images/edits', {
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
})
} else {
This is an actual network POST to a third-party API carrying user content, so it represents a real external transmission boundary. In the context of an image-enhancement skill, this matters because the code may forward user-provided images without any in-file privacy gating.
: await readFile(p)
fd.append('image[]', new Blob([buf], { type: mimeOf(p) }), path.basename(p))
}
r = await fetch('https://api.openai.com/v1/images/edits', {
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
})
} else {
This network request sends user prompt data to OpenAI for image generation, which is a genuine external data flow. The risk is contextual rather than exploit-specific: sensitive prompts may leave the trust boundary without user awareness.
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
})
} else {
r = await fetch('https://api.openai.com/v1/images/generations', {
method: 'POST',
headers: { authorization: `Bearer ${key}`, 'content-type': 'application/json' },
body: JSON.stringify({
This network request sends user prompt data to OpenAI for image generation, which is a genuine external data flow. The risk is contextual rather than exploit-specific: sensitive prompts may leave the trust boundary without user awareness.
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
})
} else {
r = await fetch('https://api.openai.com/v1/images/generations', {
method: 'POST',
headers: { authorization: `Bearer ${key}`, 'content-type': 'application/json' },
body: JSON.stringify({
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
model: (req) =>
env.GEN_MODEL_REPLICATE ||
(req?.images?.length ? 'black-forest-labs/flux-kontext-pro' : 'black-forest-labs/flux-dev'),
describe(req) { return `POST https://api.replicate.com/v1/models/${replicate.model(req)}/predictions` },
async run(req) {
const input = { prompt: req.prompt, num_outputs: req.batch }
if (req.images?.length) input.input_image = await asDataUri(req.images[0])
This postJson invocation sends prompt and possibly image data to Replicate, crossing the local trust boundary to a third-party service. In this skill’s context, that raises real confidentiality and compliance concerns for proprietary or user-sensitive media.
const input = { prompt: req.prompt, num_outputs: req.batch }
if (req.images?.length) input.input_image = await asDataUri(req.images[0])
const j = await postJson(
`https://api.replicate.com/v1/models/${replicate.model(req)}/predictions`,
{ input },
{ authorization: `Bearer ${env.REPLICATE_API_TOKEN}`, prefer: 'wait' },
req.timeoutMs,
The task list explicitly exposes a capability named "remove-watermark" without any indication of authorization checks, ownership verification, or rights constraints. In an image-editing skill set, this strongly enables misuse to strip provenance or copyright markings from third-party content, which can facilitate IP infringement, fraud, and policy evasion.
The description and operating instructions are predominantly in Chinese, which effectively imposes a language expectation on users and operators. The file does not state that Chinese is optional, nor does it document a region-specific justification for the language constraint.
Lines L06-L07 introduce a critical instruction in English inside an otherwise Chinese-language document. This can violate language/locale expectations by forcing a specific language for operational instructions without offering a user choice or documenting the reason for the language constraint.
The module documentation states providers expose a common interface and that run() returns '{ files:[{buffer|url, ext}], raw }'. In practice, multiple providers return additional 'texts' fields and the request/response path also includes video-oriented behavior, so the documentation understates and partially contradicts actual behavior.
Detected: suspicious.dangerous_exec, suspicious.env_credential_access