Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md node scripts/gen.mjs --task one-shot \
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a coherent e-commerce image editing helper, but users should understand that it uploads prompts and images to cloud generation providers.
Install only if you are comfortable sending product photos, model photos, prompts, and optional face or pose references to the selected cloud provider. Use licensed or consented images, avoid personal or third-party portraits unless you have permission, and choose provider credentials deliberately.
Referenced artifact was not completely inspected
node scripts/gen.mjs --task one-shot \
Referenced artifact was not completely inspected
node scripts/gen.mjs --task one-shot \
The skill instructs use of external tooling that can access networked backends and likely relies on environment-based credentials, but it does not declare any explicit tool scope or permissions boundary. This increases the risk of over-broad execution context, accidental credential exposure, or unauthorized outbound access if the agent platform infers or grants capabilities implicitly.
The trigger phrases are broad and can match generic user requests like changing people, backgrounds, or ethnicity, which may cause the skill to activate in unintended contexts. Mis-triggering is especially risky here because the skill uploads user images to an external editing service and can perform sensitive identity-related edits.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
拿一张**已经拍好的模特图或人台图**,在**商品完全不动**的前提下换掉人、换掉背景,或两者都换。
和 [flat-lay](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/flat-lay/skill.md) 的区别:flat-lay 从平铺图**造**一张模特图;本技能是把**已有**的模特图**裂变**成多个人群 / 场景版本——一次拍摄,覆盖国内海外、不同年龄段、不同肤色的投放需求。
---
The skill asks users to provide model photos, pose references, and even a target model face image, then sends them to an external image-editing service, but it gives no privacy warning or consent guidance. Because these inputs may contain biometric or personally identifiable information, users may unknowingly upload sensitive images to a third party.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
| 手指崩坏 | 换人时手部重绘 | 加修手句 + `--batch 4` 挑图 |
| 只换背景却把人也换了 | 模式句不完整 | 补 `Keep the model identical — same face, hair, body and pose.` |
| 新背景光线和人对不上 | 未约束光向 | 追加 `Match the new background lighting to the light direction on the model in image 1.` |
| 面料纹理被抹平 | `--quality medium` | 改 `--quality high`,或换图后接 [material-enhancement](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/material-enhancement/skill.md) |
| 人台图转真人后脖子/手很怪 | 缺少补全指令 | 用第五节人台图专用句,明确要求补出头颈与手臂 |
---
The configuration hard-codes a protected demographic attribute ('East Asian woman') as the default model identity for generated outputs without indicating that this is user-selected, optional, or required for a documented business purpose. In an image-generation skill that explicitly supports changing models, backgrounds, and ethnicity, embedding a fixed race/gender default can create biased or exclusionary outputs at scale and may lead to discriminatory treatment or inappropriate demographic targeting.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
At L178 the script invokes provider.run(req), which transmits the assembled prompt and referenced images to a remote backend. Although the help text documents provider selection and dry-run behavior, there is no confirmation prompt or explicit user disclosure near execution that user-supplied content will be sent off-machine.
The file's user-visible natural-language strings, including comments and thrown error messages, are written in Chinese only. Under the stated policy, forcing a specific language without user opt-in is a locale/language policy concern unless the constraint is explicitly documented and justified.
The module interface explicitly supports video:boolean and text:boolean, and several providers return texts or videos, making this a general multimodal generation/router layer rather than one limited to '已有模特图换模特、换背景' image variation. That exceeds the manifest's narrowly described purpose of producing alternate people/background versions of a single model image while keeping the product unchanged.
The OpenAI provider switches to images/generations when no input images are supplied, and other providers similarly choose pure generation models when req.images is absent. The manifest describes transforming one existing model image into alternate versions, which implies an image-conditioned workflow rather than standalone generation from prompt only.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
model: () => env.GEN_MODEL_OPENAI || 'gpt-image-1',
describe(req) {
const ep = req.images?.length ? 'images/edits' : 'images/generations'
return `POST https://api.openai.com/v1/${ep} model=${openai.model()} size=${mapSize(req.size)} n=${req.batch}`
},
async run(req) {
const key = env.OPENAI_API_KEY
The code uploads user-supplied images and prompts to OpenAI's external API, which is a real data egress path. In the context of a skill handling locally referenced images, this is dangerous if users or calling code are not clearly informed that content will leave the local environment and be processed by a third party.
: await readFile(p)
fd.append('image[]', new Blob([buf], { type: mimeOf(p) }), path.basename(p))
}
r = await fetch('https://api.openai.com/v1/images/edits', {
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
})
} else {
The code uploads user-supplied images and prompts to OpenAI's external API, which is a real data egress path. In the context of a skill handling locally referenced images, this is dangerous if users or calling code are not clearly informed that content will leave the local environment and be processed by a third party.
: await readFile(p)
fd.append('image[]', new Blob([buf], { type: mimeOf(p) }), path.basename(p))
}
r = await fetch('https://api.openai.com/v1/images/edits', {
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
})
} else {
This request sends prompts and generation parameters to an external provider even when no image is present, creating third-party data disclosure and potentially violating the skill's expected one-image transformation scope. The risk is contextual rather than exploit-specific, but it is still a genuine external transmission channel.
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
})
} else {
r = await fetch('https://api.openai.com/v1/images/generations', {
method: 'POST',
headers: { authorization: `Bearer ${key}`, 'content-type': 'application/json' },
body: JSON.stringify({
This request sends prompts and generation parameters to an external provider even when no image is present, creating third-party data disclosure and potentially violating the skill's expected one-image transformation scope. The risk is contextual rather than exploit-specific, but it is still a genuine external transmission channel.
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
})
} else {
r = await fetch('https://api.openai.com/v1/images/generations', {
method: 'POST',
headers: { authorization: `Bearer ${key}`, 'content-type': 'application/json' },
body: JSON.stringify({
This code accepts local file paths or remote URLs in req.images and forwards their contents to third-party providers, which can expose sensitive local data or internal resources if upstream input is attacker-controlled. Because it also fetches remote URLs server-side before re-uploading them, it increases risk of unintended data disclosure and SSRF-style access to reachable endpoints.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
model: (req) =>
env.GEN_MODEL_REPLICATE ||
(req?.images?.length ? 'black-forest-labs/flux-kontext-pro' : 'black-forest-labs/flux-dev'),
describe(req) { return `POST https://api.replicate.com/v1/models/${replicate.model(req)}/predictions` },
async run(req) {
const input = { prompt: req.prompt, num_outputs: req.batch }
if (req.images?.length) input.input_image = await asDataUri(req.images[0])
The Replicate provider sends prompts and possibly image data to an external API, creating a real outbound data flow to a third party. In this skill context, where local file paths can be accepted as inputs, that raises meaningful privacy and data-handling risk if upstream controls do not constrain what may be sent.
const input = { prompt: req.prompt, num_outputs: req.batch }
if (req.images?.length) input.input_image = await asDataUri(req.images[0])
const j = await postJson(
`https://api.replicate.com/v1/models/${replicate.model(req)}/predictions`,
{ input },
{ authorization: `Bearer ${env.REPLICATE_API_TOKEN}`, prefer: 'wait' },
req.timeoutMs,
The document is primarily written in Chinese, but lines L06-L07 contain a directive addressed to the agent entirely in English. This creates a language/locale inconsistency and effectively forces a specific language for operational instructions without offering user choice or documenting a justified locale constraint.
该文件的标题、说明和面向 Agent 的硬性要求均仅以中文给出,没有提供用户可选择语言/locale 的说明,也未说明这是仅面向中文环境的受限文档。根据规则,强制单一语言而无用户选择或明确、合理的地域限制,属于自然语言层面的语言/locale 策略风险。
The file’s natural-language comments and user-facing usage/help strings are written in Chinese, including operational messages shown to users. This imposes a specific language/locale without any opt-in or indication that the skill is intentionally region-specific, which matches the language-policy violation criteria.
The warning string for missing model reference images is emitted in Chinese, and similar Chinese-only CLI output appears elsewhere. Because these are user-visible messages with no language selection or documented locale restriction, they violate the natural-language locale policy.
Detected: suspicious.dangerous_exec, suspicious.env_credential_access