Back to skill

Security audit

换模特换背景 One Shot

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent e-commerce image editing helper, but users should understand that it uploads prompts and images to cloud generation providers.

Install only if you are comfortable sending product photos, model photos, prompts, and optional face or pose references to the selected cloud provider. Use licensed or consented images, avoid personal or third-party portraits unless you have permission, and choose provider credentials deliberately.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (29)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 115)May include surrounding context.

md
node scripts/gen.mjs --task one-shot \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 161)May include surrounding context.

md
node scripts/gen.mjs --task one-shot \

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill instructs use of external tooling that can access networked backends and likely relies on environment-based credentials, but it does not declare any explicit tool scope or permissions boundary. This increases the risk of over-broad execution context, accidental credential exposure, or unauthorized outbound access if the agent platform infers or grants capabilities implicitly.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger phrases are broad and can match generic user requests like changing people, backgrounds, or ethnicity, which may cause the skill to activate in unintended contexts. Mis-triggering is especially risky here because the skill uploads user images to an external editing service and can perform sensitive identity-related edits.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 11)May include surrounding context.

md
拿一张**已经拍好的模特图或人台图**,在**商品完全不动**的前提下换掉人、换掉背景,或两者都换。

和 [flat-lay](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/flat-lay/skill.md) 的区别:flat-lay 从平铺图**造**一张模特图;本技能是把**已有**的模特图**裂变**成多个人群 / 场景版本——一次拍摄,覆盖国内海外、不同年龄段、不同肤色的投放需求。

---

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill asks users to provide model photos, pose references, and even a target model face image, then sends them to an external image-editing service, but it gives no privacy warning or consent guidance. Because these inputs may contain biometric or personally identifiable information, users may unknowingly upload sensitive images to a third party.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 214)May include surrounding context.

md
| 手指崩坏 | 换人时手部重绘 | 加修手句 + `--batch 4` 挑图 |
| 只换背景却把人也换了 | 模式句不完整 | 补 `Keep the model identical — same face, hair, body and pose.` |
| 新背景光线和人对不上 | 未约束光向 | 追加 `Match the new background lighting to the light direction on the model in image 1.` |
| 面料纹理被抹平 | `--quality medium` | 改 `--quality high`,或换图后接 [material-enhancement](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/material-enhancement/skill.md) |
| 人台图转真人后脖子/手很怪 | 缺少补全指令 | 用第五节人台图专用句,明确要求补出头颈与手臂 |

---

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The configuration hard-codes a protected demographic attribute ('East Asian woman') as the default model identity for generated outputs without indicating that this is user-selected, optional, or required for a documented business purpose. In an image-generation skill that explicitly supports changing models, backgrounds, and ethnicity, embedding a fixed race/gender default can create biased or exclusionary outputs at scale and may lead to discriminatory treatment or inappropriate demographic targeting.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

At L178 the script invokes provider.run(req), which transmits the assembled prompt and referenced images to a remote backend. Although the help text documents provider selection and dry-run behavior, there is no confirmation prompt or explicit user disclosure near execution that user-supplied content will be sent off-machine.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file's user-visible natural-language strings, including comments and thrown error messages, are written in Chinese only. Under the stated policy, forcing a specific language without user opt-in is a locale/language policy concern unless the constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module interface explicitly supports video:boolean and text:boolean, and several providers return texts or videos, making this a general multimodal generation/router layer rather than one limited to '已有模特图换模特、换背景' image variation. That exceeds the manifest's narrowly described purpose of producing alternate people/background versions of a single model image while keeping the product unchanged.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The OpenAI provider switches to images/generations when no input images are supplied, and other providers similarly choose pure generation models when req.images is absent. The manifest describes transforming one existing model image into alternate versions, which implies an image-conditioned workflow rather than standalone generation from prompt only.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 134)May include surrounding context.

js
model: () => env.GEN_MODEL_OPENAI || 'gpt-image-1',
  describe(req) {
    const ep = req.images?.length ? 'images/edits' : 'images/generations'
    return `POST https://api.openai.com/v1/${ep}  model=${openai.model()} size=${mapSize(req.size)} n=${req.batch}`
  },
  async run(req) {
    const key = env.OPENAI_API_KEY

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The code uploads user-supplied images and prompts to OpenAI's external API, which is a real data egress path. In the context of a skill handling locally referenced images, this is dangerous if users or calling code are not clearly informed that content will leave the local environment and be processed by a third party.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 153)May include surrounding context.

js
: await readFile(p)
        fd.append('image[]', new Blob([buf], { type: mimeOf(p) }), path.basename(p))
      }
      r = await fetch('https://api.openai.com/v1/images/edits', {
        method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
      })
    } else {

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The code uploads user-supplied images and prompts to OpenAI's external API, which is a real data egress path. In the context of a skill handling locally referenced images, this is dangerous if users or calling code are not clearly informed that content will leave the local environment and be processed by a third party.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 153)May include surrounding context.

js
: await readFile(p)
        fd.append('image[]', new Blob([buf], { type: mimeOf(p) }), path.basename(p))
      }
      r = await fetch('https://api.openai.com/v1/images/edits', {
        method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
      })
    } else {

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

This request sends prompts and generation parameters to an external provider even when no image is present, creating third-party data disclosure and potentially violating the skill's expected one-image transformation scope. The risk is contextual rather than exploit-specific, but it is still a genuine external transmission channel.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 157)May include surrounding context.

js
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
      })
    } else {
      r = await fetch('https://api.openai.com/v1/images/generations', {
        method: 'POST',
        headers: { authorization: `Bearer ${key}`, 'content-type': 'application/json' },
        body: JSON.stringify({

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

This request sends prompts and generation parameters to an external provider even when no image is present, creating third-party data disclosure and potentially violating the skill's expected one-image transformation scope. The risk is contextual rather than exploit-specific, but it is still a genuine external transmission channel.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 157)May include surrounding context.

js
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
      })
    } else {
      r = await fetch('https://api.openai.com/v1/images/generations', {
        method: 'POST',
        headers: { authorization: `Bearer ${key}`, 'content-type': 'application/json' },
        body: JSON.stringify({

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code accepts local file paths or remote URLs in req.images and forwards their contents to third-party providers, which can expose sensitive local data or internal resources if upstream input is attacker-controlled. Because it also fetches remote URLs server-side before re-uploading them, it increases risk of unintended data disclosure and SSRF-style access to reachable endpoints.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 261)May include surrounding context.

js
model: (req) =>
    env.GEN_MODEL_REPLICATE ||
    (req?.images?.length ? 'black-forest-labs/flux-kontext-pro' : 'black-forest-labs/flux-dev'),
  describe(req) { return `POST https://api.replicate.com/v1/models/${replicate.model(req)}/predictions` },
  async run(req) {
    const input = { prompt: req.prompt, num_outputs: req.batch }
    if (req.images?.length) input.input_image = await asDataUri(req.images[0])

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The Replicate provider sends prompts and possibly image data to an external API, creating a real outbound data flow to a third party. In this skill context, where local file paths can be accepted as inputs, that raises meaningful privacy and data-handling risk if upstream controls do not constrain what may be sent.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 266)May include surrounding context.

js
const input = { prompt: req.prompt, num_outputs: req.batch }
    if (req.images?.length) input.input_image = await asDataUri(req.images[0])
    const j = await postJson(
      `https://api.replicate.com/v1/models/${replicate.model(req)}/predictions`,
      { input },
      { authorization: `Bearer ${env.REPLICATE_API_TOKEN}`, prefer: 'wait' },
      req.timeoutMs,

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document is primarily written in Chinese, but lines L06-L07 contain a directive addressed to the agent entirely in English. This creates a language/locale inconsistency and effectively forces a specific language for operational instructions without offering user choice or documenting a justified locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

该文件的标题、说明和面向 Agent 的硬性要求均仅以中文给出,没有提供用户可选择语言/locale 的说明,也未说明这是仅面向中文环境的受限文档。根据规则,强制单一语言而无用户选择或明确、合理的地域限制,属于自然语言层面的语言/locale 策略风险。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s natural-language comments and user-facing usage/help strings are written in Chinese, including operational messages shown to users. This imposes a specific language/locale without any opt-in or indication that the skill is intentionally region-specific, which matches the language-policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The warning string for missing model reference images is emitted in Chinese, and similar Chinese-only CLI output appears elsewhere. Because these are user-visible messages with no language selection or documented locale restriction, they violate the natural-language locale policy.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/lib/providers.mjs:104

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/gen.mjs:118

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/lib/providers.mjs:21