Back to skill

Security audit

材质质感增强 Material Enhancement

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real image-enhancement skill, but it ships a broader cloud-generation helper that can send images to third parties and run unrelated tasks beyond material enhancement.

Review this skill before installing if you work with proprietary product photos. Use it only with images you are allowed to send to the selected provider, prefer --dry-run first, avoid remote image URLs from untrusted sources, and restrict provider credentials/environment variables to the service you intend to use. The material-enhancement workflow itself is coherent, but the bundled generator is broader than the advertised task.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (26)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 116)May include surrounding context.

md
node scripts/gen.mjs --task material-enhancement \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 167)May include surrounding context.

md
node scripts/gen.mjs --task material-enhancement \

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill invokes external CLI tooling and references network-accessible resources, but it does not declare any explicit tool or permission scope. In an agent environment, this weakens least-privilege guarantees and can allow unintended access to environment variables or networked backends if the skill is auto-enabled or executed with broader runtime privileges than necessary.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger phrases are broad enough to match common image-editing requests, which can cause the agent to invoke this skill in situations the user did not intend. Misrouting is primarily a safety and reliability issue here, but it can also lead to unnecessary external tool calls, unintended data transfer, or cost-incurring image processing.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

md
| --- | --- |
| 面料表面纹理、微观细节、褶皱阴影层次、纤维光泽 | 构图、模特(脸/发/手/姿势)、其他服饰、背景、色调、服装轮廓与颜色 |

**不做**:不改服装轮廓与颜色;不改模特与背景;不把一种面料换成另一种(换面料请用 [fabric-on-body](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/fabric-on-body/skill.md))。

---

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill hard-codes a model description including ethnicity, age range, and body type without indicating that these are user-selectable or required by a justified business or locale constraint. In an image-generation pipeline used across many SKUs, this can systematically enforce exclusionary representation and produce biased outputs at scale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

该文件的标题与全文说明均以中文固定呈现,且未见任何允许用户选择语言或说明仅面向特定中文使用场景的文字。按照语言/地区策略,若技能或参考文档强制单一语言而无用户选择或合理限定,属于自然语言层面的策略问题。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Several user-facing CLI messages are hard-coded in Chinese, including error text and usage/help output. This creates a language/locale policy concern because the skill does not provide user opt-in, fallback, or documentation that the tool is intended only for Chinese-speaking users or a region-specific environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script persists provider output to disk and, when a file buffer is absent, fetches arbitrary remote URLs and writes the resulting bytes locally. This creates implicit network egress and filesystem modification behavior that may surprise users, and if a compromised or untrusted provider returns attacker-controlled URLs, the script could download unintended content or very large files into the local environment.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The module imports child_process.spawn and uses it to invoke an external 'dlazy' CLI as a provider backend. Launching arbitrary external binaries is a stronger capability than is ordinarily justified by a skill whose stated purpose is image material enhancement, especially when network-backed providers already exist for the same function.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code fetches arbitrary user-supplied URLs and converts them to base64 for downstream processing. This creates a server-side request forgery and data exfiltration risk, because an attacker can make the service reach internal hosts, cloud metadata endpoints, or other sensitive network resources under the guise of loading an image.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This provider layer materially exceeds the stated purpose of a texture-enhancement skill. It supports generic image generation, video-oriented outputs, and text outputs across multiple backends, which broadens the skill’s capability surface and can enable unintended data flows or misuse outside the manifest-declared scope.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 134)May include surrounding context.

js
model: () => env.GEN_MODEL_OPENAI || 'gpt-image-1',
  describe(req) {
    const ep = req.images?.length ? 'images/edits' : 'images/generations'
    return `POST https://api.openai.com/v1/${ep}  model=${openai.model()} size=${mapSize(req.size)} n=${req.batch}`
  },
  async run(req) {
    const key = env.OPENAI_API_KEY

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The HTTP providers send user prompts and referenced images to third-party services, but this file contains no guardrails, disclosure hooks, or consent checks. In a media-enhancement skill, input images may contain proprietary product photos or sensitive data, so silent external transmission increases privacy and compliance risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This is an actual network POST to a third-party API carrying user content, so it represents a real external transmission boundary. In the context of an image-enhancement skill, this matters because the code may forward user-provided images without any in-file privacy gating.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 153)May include surrounding context.

js
: await readFile(p)
        fd.append('image[]', new Blob([buf], { type: mimeOf(p) }), path.basename(p))
      }
      r = await fetch('https://api.openai.com/v1/images/edits', {
        method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
      })
    } else {

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This is an actual network POST to a third-party API carrying user content, so it represents a real external transmission boundary. In the context of an image-enhancement skill, this matters because the code may forward user-provided images without any in-file privacy gating.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 153)May include surrounding context.

js
: await readFile(p)
        fd.append('image[]', new Blob([buf], { type: mimeOf(p) }), path.basename(p))
      }
      r = await fetch('https://api.openai.com/v1/images/edits', {
        method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
      })
    } else {

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This network request sends user prompt data to OpenAI for image generation, which is a genuine external data flow. The risk is contextual rather than exploit-specific: sensitive prompts may leave the trust boundary without user awareness.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 157)May include surrounding context.

js
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
      })
    } else {
      r = await fetch('https://api.openai.com/v1/images/generations', {
        method: 'POST',
        headers: { authorization: `Bearer ${key}`, 'content-type': 'application/json' },
        body: JSON.stringify({

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This network request sends user prompt data to OpenAI for image generation, which is a genuine external data flow. The risk is contextual rather than exploit-specific: sensitive prompts may leave the trust boundary without user awareness.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 157)May include surrounding context.

js
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
      })
    } else {
      r = await fetch('https://api.openai.com/v1/images/generations', {
        method: 'POST',
        headers: { authorization: `Bearer ${key}`, 'content-type': 'application/json' },
        body: JSON.stringify({

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 261)May include surrounding context.

js
model: (req) =>
    env.GEN_MODEL_REPLICATE ||
    (req?.images?.length ? 'black-forest-labs/flux-kontext-pro' : 'black-forest-labs/flux-dev'),
  describe(req) { return `POST https://api.replicate.com/v1/models/${replicate.model(req)}/predictions` },
  async run(req) {
    const input = { prompt: req.prompt, num_outputs: req.batch }
    if (req.images?.length) input.input_image = await asDataUri(req.images[0])

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This postJson invocation sends prompt and possibly image data to Replicate, crossing the local trust boundary to a third-party service. In this skill’s context, that raises real confidentiality and compliance concerns for proprietary or user-sensitive media.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 266)May include surrounding context.

js
const input = { prompt: req.prompt, num_outputs: req.batch }
    if (req.images?.length) input.input_image = await asDataUri(req.images[0])
    const j = await postJson(
      `https://api.replicate.com/v1/models/${replicate.model(req)}/predictions`,
      { input },
      { authorization: `Bearer ${env.REPLICATE_API_TOKEN}`, prefer: 'wait' },
      req.timeoutMs,

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The task list explicitly exposes a capability named "remove-watermark" without any indication of authorization checks, ownership verification, or rights constraints. In an image-editing skill set, this strongly enables misuse to strip provenance or copyright markings from third-party content, which can facilitate IP infringement, fraud, and policy evasion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The description and operating instructions are predominantly in Chinese, which effectively imposes a language expectation on users and operators. The file does not state that Chinese is optional, nor does it document a region-specific justification for the language constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

Lines L06-L07 introduce a critical instruction in English inside an otherwise Chinese-language document. This can violate language/locale expectations by forcing a specific language for operational instructions without offering a user choice or documenting the reason for the language constraint.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The module documentation states providers expose a common interface and that run() returns '{ files:[{buffer|url, ext}], raw }'. In practice, multiple providers return additional 'texts' fields and the request/response path also includes video-oriented behavior, so the documentation understates and partially contradicts actual behavior.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/lib/providers.mjs:104

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/gen.mjs:118

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/lib/providers.mjs:21