Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md node scripts/gen.mjs --task to-3d \
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed ecommerce image-generation helper that uploads user-selected prompts/images to image providers and saves generated outputs locally.
Install only if you are comfortable sending selected product images and prompts to the configured image provider. Use --dry-run to inspect requests first, choose the provider explicitly when needed, and avoid passing confidential images unless that provider is approved for your use.
Referenced artifact was not completely inspected
node scripts/gen.mjs --task to-3d \
Referenced artifact was not completely inspected
node scripts/gen.mjs --task to-3d \
The skill documents executable CLI commands that access external services and may rely on environment-based credentials, but it does not declare any explicit tool scope or allowed-tools policy. This creates a least-privilege gap: an agent integrating the skill could permit broader network or environment access than necessary, increasing the chance of unauthorized outbound requests or secret exposure during execution.
The manifest description and nearly all instructional content are in Chinese, and the skill does not indicate that users may interact in other languages or opt into this locale. Under the policy rule, forcing or assuming a specific language without user choice can be a natural-language policy violation.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
| --- | --- |
| 折叠摆放 | 袖子折在身上,模型算不出袖子长度 |
| 大面积褶皱 | 褶皱会被当成结构撑成怪形状 |
| 已带人体 | 真人上身图请用 [one-shot](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/one-shot/skill.md) |
| 套装同框 | 拆成单件分别跑 |
---
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
| 版型被撑胖 | 只说了加体积没说保比例 | 追加保比例句:`Add volume, not size.` |
| 领口是平的黑洞 | 未描述内里 | 追加领口内里句 |
| 袖子直挺挺贴身侧 | 未描述袖姿 | 追加 `hanging slightly forward and away from the body` |
| 织法糊了 | `--quality medium` | 改 `high`;或接 [material-enhancement](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/material-enhancement/skill.md) |
| 折叠摆放的图效果很差 | 输入违规 | 重拍成完全摊平的平铺图 |
---
The skill hard-codes a model ethnicity ('East Asian woman') into shared brand configuration without any user opt-in, business necessity, or documented justification. In an image-generation pipeline used across many SKUs, this can systematically enforce demographic bias in outputs, create discrimination/compliance risk, and prevent user or merchant control over representation.
The entire skill reference is written in Chinese and includes agent-facing requirements only in Chinese, with no indication that users may choose another language or locale. Under the policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified.
This code contains natural-language comments and user-facing CLI messages in Chinese, indicating the skill is designed around a single language. Under the policy, forcing a specific language without user opt-in or a documented region-specific justification is a natural-language policy violation.
The error and usage text shown to users is exclusively Chinese, and the file does not offer an alternative language or note that the tool is limited to a Chinese-speaking context. This violates the language/locale policy criteria for all file types.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The script sends req, which includes the user's prompt and image references, to a selected external provider via provider.run(req). Although the file header and help text describe generation behavior, they do not clearly disclose that user-supplied content is transmitted to third-party services when the command actually runs.
The helper sends JSON bodies to external provider endpoints, and elsewhere this file passes prompts and image data into those requests. There is no confirmation prompt, print/log statement, or explanatory comment warning that user-provided text or images may be transmitted to third-party services.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
model: () => env.GEN_MODEL_OPENAI || 'gpt-image-1',
describe(req) {
const ep = req.images?.length ? 'images/edits' : 'images/generations'
return `POST https://api.openai.com/v1/${ep} model=${openai.model()} size=${mapSize(req.size)} n=${req.batch}`
},
async run(req) {
const key = env.OPENAI_API_KEY
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
model: () => env.GEN_MODEL_OPENAI || 'gpt-image-1',
describe(req) {
const ep = req.images?.length ? 'images/edits' : 'images/generations'
return `POST https://api.openai.com/v1/${ep} model=${openai.model()} size=${mapSize(req.size)} n=${req.batch}`
},
async run(req) {
const key = env.OPENAI_API_KEY
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
model: () => env.GEN_MODEL_OPENAI || 'gpt-image-1',
describe(req) {
const ep = req.images?.length ? 'images/edits' : 'images/generations'
return `POST https://api.openai.com/v1/${ep} model=${openai.model()} size=${mapSize(req.size)} n=${req.batch}`
},
async run(req) {
const key = env.OPENAI_API_KEY
This branch reads local files or fetches remote images, then attaches that content to a multipart request sent to the OpenAI API. The code lacks any visible confirmation, log message, or warning comment informing users that image contents will leave the local system.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
: await readFile(p)
fd.append('image[]', new Blob([buf], { type: mimeOf(p) }), path.basename(p))
}
r = await fetch('https://api.openai.com/v1/images/edits', {
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
})
} else {
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
})
} else {
r = await fetch('https://api.openai.com/v1/images/generations', {
method: 'POST',
headers: { authorization: `Bearer ${key}`, 'content-type': 'application/json' },
body: JSON.stringify({
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
model: (req) =>
env.GEN_MODEL_REPLICATE ||
(req?.images?.length ? 'black-forest-labs/flux-kontext-pro' : 'black-forest-labs/flux-dev'),
describe(req) { return `POST https://api.replicate.com/v1/models/${replicate.model(req)}/predictions` },
async run(req) {
const input = { prompt: req.prompt, num_outputs: req.batch }
if (req.images?.length) input.input_image = await asDataUri(req.images[0])
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
model: (req) =>
env.GEN_MODEL_REPLICATE ||
(req?.images?.length ? 'black-forest-labs/flux-kontext-pro' : 'black-forest-labs/flux-dev'),
describe(req) { return `POST https://api.replicate.com/v1/models/${replicate.model(req)}/predictions` },
async run(req) {
const input = { prompt: req.prompt, num_outputs: req.batch }
if (req.images?.length) input.input_image = await asDataUri(req.images[0])
The task list explicitly exposes a capability named "remove-watermark" without any visible authorization, rights-verification, or policy guardrails. Watermark removal is commonly used to strip ownership or licensing indicators from protected images, so shipping it as a standard task materially increases the risk of copyright abuse and provenance evasion.
The document is primarily written in Chinese, but the highlighted instruction switches to English and presents it as a critical requirement for the agent. This can be a language/locale policy concern because it imposes a specific language form without user opt-in or an explicit rationale.
The help text lists sensitive credential environment variables such as OPENAI_API_KEY, GEMINI_API_KEY, and others, and the script later selects providers based on available credentials. While this is expected functionality, the file does not include an explicit warning or comment about accessing these sensitive values.
The persist function creates directories and writes output files to disk, either at a user-specified path or under output/. The behavior is inferable from --save and the script purpose, but there is no explicit warning that running the command will modify the local filesystem when not using --dry-run.
Detected: suspicious.dangerous_exec, suspicious.env_credential_access