Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md node scripts/gen.mjs --task wear-everything \
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a coherent ecommerce image-generation helper that sends user-selected prompts and images to configured cloud generation providers and saves the returned outputs locally.
Install only if you are comfortable sending product photos, model/reference images, prompts, and related brand constraints to dLazy or whichever configured provider is selected. Use dry-run first, choose approved providers for sensitive assets, keep API keys scoped and revocable, and prefer pinned trusted CLI packages.
Referenced artifact was not completely inspected
node scripts/gen.mjs --task wear-everything \
Referenced artifact was not completely inspected
node scripts/gen.mjs --task wear-everything \
The skill documents executable CLI usage with networked image-generation backends and references provider configuration, but it does not declare any explicit tool scope such as allowed tools or permissions. In an agent environment, this can lead to overly broad access to network or environment-backed capabilities, making accidental misuse, data exfiltration, or invocation of unintended tools more likely.
The manifest description and main heading/content are presented entirely in Chinese, and the trigger phrases are explicitly Chinese-only. This creates a language/locale constraint without any opt-in, alternative language support, or justification that the skill is intended only for a Chinese-speaking or region-specific context.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
把一张**鞋 / 包 / 手表 / 眼镜 / 帽子 / 围巾 / 项链 / 耳饰**的商品图,变成**真人正确佩戴**的商拍图。
和 [flat-lay](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/flat-lay/skill.md) 的区别:flat-lay 处理「穿在身上的衣服」,本技能处理「戴在身上的东西」——商品只占画面的一小块区域,因此**选区(商品出现在参考图的哪个位置)**是成败关键。
---
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
把一张**鞋 / 包 / 手表 / 眼镜 / 帽子 / 围巾 / 项链 / 耳饰**的商品图,变成**真人正确佩戴**的商拍图。
和 [flat-lay](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/flat-lay/skill.md) 的区别:flat-lay 处理「穿在身上的衣服」,本技能处理「戴在身上的东西」——商品只占画面的一小块区域,因此**选区(商品出现在参考图的哪个位置)**是成败关键。
---
The configuration hard-codes a model as an 'East Asian woman' for all generated outputs, removing user choice and embedding protected demographic attributes directly into the skill's default behavior. In a commercial image-generation workflow, this can create fairness, representation, and discrimination risks, especially if applied across many SKUs or storefronts without an explicit business justification or opt-in.
The document is primarily written in Chinese, but lines L06-L07 introduce a mandatory English instruction directed at the agent. This creates a natural-language policy concern because the skill appears to impose a specific language context for execution without any user opt-in or documented justification.
This file presents all operational instructions, warnings, and required agent behavior exclusively in Chinese. Under the natural-language policy rule, forcing a specific language without user opt-in or a documented region-specific justification is a policy violation.
This file contains multiple natural-language CLI messages in Chinese, including error and usage output. Because the skill does not offer language selection or explain that it is intentionally Chinese-only, it violates the language/locale policy for natural-language content.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
This script sends the user-supplied prompt and image references to a third-party generation provider during normal execution, but the regular execution path does not present an explicit runtime warning or confirmation that potentially sensitive inputs will leave the local environment. In this skill context, prompts and images may include product assets, model references, or proprietary brand materials, so accidental disclosure to external services is a realistic privacy and compliance risk.
The file's user-facing strings and instructional comments are written exclusively in Chinese, including operational error messages later in the file, with no indication that this skill is intentionally region-specific or that users can opt into another language. This can violate language/locale policy when a skill imposes a specific language without user choice.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
model: () => env.GEN_MODEL_OPENAI || 'gpt-image-1',
describe(req) {
const ep = req.images?.length ? 'images/edits' : 'images/generations'
return `POST https://api.openai.com/v1/${ep} model=${openai.model()} size=${mapSize(req.size)} n=${req.batch}`
},
async run(req) {
const key = env.OPENAI_API_KEY
This finding overlaps the actual external POST call to OpenAI and represents real third-party transmission of user image data. Because the skill processes wearable try-on imagery, the data sent can be personally sensitive and should not be forwarded silently.
: await readFile(p)
fd.append('image[]', new Blob([buf], { type: mimeOf(p) }), path.basename(p))
}
r = await fetch('https://api.openai.com/v1/images/edits', {
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
})
} else {
This finding overlaps the actual external POST call to OpenAI and represents real third-party transmission of user image data. Because the skill processes wearable try-on imagery, the data sent can be personally sensitive and should not be forwarded silently.
: await readFile(p)
fd.append('image[]', new Blob([buf], { type: mimeOf(p) }), path.basename(p))
}
r = await fetch('https://api.openai.com/v1/images/edits', {
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
})
} else {
This finding overlaps the actual external POST call to OpenAI for generation and represents real outbound transmission of user prompt data. In a commerce/try-on workflow, prompt contents can still be sensitive or proprietary and should be treated as externally shared data.
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
})
} else {
r = await fetch('https://api.openai.com/v1/images/generations', {
method: 'POST',
headers: { authorization: `Bearer ${key}`, 'content-type': 'application/json' },
body: JSON.stringify({
This finding overlaps the actual external POST call to OpenAI for generation and represents real outbound transmission of user prompt data. In a commerce/try-on workflow, prompt contents can still be sensitive or proprietary and should be treated as externally shared data.
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
})
} else {
r = await fetch('https://api.openai.com/v1/images/generations', {
method: 'POST',
headers: { authorization: `Bearer ${key}`, 'content-type': 'application/json' },
body: JSON.stringify({
The code sends user prompts and user-supplied images, including local files converted to base64 and remote image content fetched first, to third-party model providers without any disclosure, consent, or policy enforcement in this layer. In a skill that generates wearable try-on images from user assets, those inputs are likely to contain personal photos or proprietary product images, so silent transfer to external APIs creates a real privacy and data-handling risk.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
model: (req) =>
env.GEN_MODEL_REPLICATE ||
(req?.images?.length ? 'black-forest-labs/flux-kontext-pro' : 'black-forest-labs/flux-dev'),
describe(req) { return `POST https://api.replicate.com/v1/models/${replicate.model(req)}/predictions` },
async run(req) {
const input = { prompt: req.prompt, num_outputs: req.batch }
if (req.images?.length) input.input_image = await asDataUri(req.images[0])
The Replicate prediction request sends prompt data and, when present, a base64/data-URI encoded input image to an external provider. In this skill, the input image may be a user's body photo or product asset, making this a meaningful privacy and data-transfer risk if not clearly disclosed and controlled.
const input = { prompt: req.prompt, num_outputs: req.batch }
if (req.images?.length) input.input_image = await asDataUri(req.images[0])
const j = await postJson(
`https://api.replicate.com/v1/models/${replicate.model(req)}/predictions`,
{ input },
{ authorization: `Bearer ${env.REPLICATE_API_TOKEN}`, prefer: 'wait' },
req.timeoutMs,
The persist path writes provider-returned content directly to disk, and if only a URL is returned it fetches remote content and saves it without an explicit user-facing warning in that path. While this is expected functionality for an asset-generation tool, it can still surprise users by storing untrusted external data locally, creating risks around inadvertent retention of sensitive/generated content or handling malformed files.
This file's natural-language content is entirely in Chinese, including maintenance instructions and parser behavior notes, and later user-visible error strings are also Chinese. The policy calls for flagging language/locale constraints when a skill forces a specific language without user choice or clear justification.
The thrown Error messages at these lines are natural-language strings in Chinese and would surface to developers/users when parsing fails. Because the file provides no locale selection or explicit justification for Chinese-only output, this is a natural-language policy concern.
The code spawns an external executable using spawn() based on environment configuration, but there is no confirmation prompt, visible log/print, or warning comment explaining that an external command will be executed. Because subprocess execution is safety-relevant, some form of disclosure is expected unless it is clearly surfaced elsewhere in the skill documentation.
Detected: suspicious.dangerous_exec, suspicious.env_credential_access