Back to skill

Security audit

鞋包配饰真人穿戴 Wear Everything

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent ecommerce image-generation helper that sends user-selected prompts and images to configured cloud generation providers and saves the returned outputs locally.

Install only if you are comfortable sending product photos, model/reference images, prompts, and related brand constraints to dLazy or whichever configured provider is selected. Use dry-run first, choose approved providers for sensitive assets, keep API keys scoped and revocable, and prefer pinned trusted CLI packages.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (26)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 129)May include surrounding context.

md
node scripts/gen.mjs --task wear-everything \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 175)May include surrounding context.

md
node scripts/gen.mjs --task wear-everything \

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill documents executable CLI usage with networked image-generation backends and references provider configuration, but it does not declare any explicit tool scope such as allowed tools or permissions. In an agent environment, this can lead to overly broad access to network or environment-backed capabilities, making accidental misuse, data exfiltration, or invocation of unintended tools more likely.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description and main heading/content are presented entirely in Chinese, and the trigger phrases are explicitly Chinese-only. This creates a language/locale constraint without any opt-in, alternative language support, or justification that the skill is intended only for a Chinese-speaking or region-specific context.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 11)May include surrounding context.

md
把一张**鞋 / 包 / 手表 / 眼镜 / 帽子 / 围巾 / 项链 / 耳饰**的商品图,变成**真人正确佩戴**的商拍图。

和 [flat-lay](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/flat-lay/skill.md) 的区别:flat-lay 处理「穿在身上的衣服」,本技能处理「戴在身上的东西」——商品只占画面的一小块区域,因此**选区(商品出现在参考图的哪个位置)**是成败关键。

---

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

md
把一张**鞋 / 包 / 手表 / 眼镜 / 帽子 / 围巾 / 项链 / 耳饰**的商品图,变成**真人正确佩戴**的商拍图。

和 [flat-lay](https://github.com/dlazy-ai/ecommerce-skills/blob/main/skills/flat-lay/skill.md) 的区别:flat-lay 处理「穿在身上的衣服」,本技能处理「戴在身上的东西」——商品只占画面的一小块区域,因此**选区(商品出现在参考图的哪个位置)**是成败关键。

---

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The configuration hard-codes a model as an 'East Asian woman' for all generated outputs, removing user choice and embedding protected demographic attributes directly into the skill's default behavior. In a commercial image-generation workflow, this can create fairness, representation, and discrimination risks, especially if applied across many SKUs or storefronts without an explicit business justification or opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The document is primarily written in Chinese, but lines L06-L07 introduce a mandatory English instruction directed at the agent. This creates a natural-language policy concern because the skill appears to impose a specific language context for execution without any user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This file presents all operational instructions, warnings, and required agent behavior exclusively in Chinese. Under the natural-language policy rule, forcing a specific language without user opt-in or a documented region-specific justification is a policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This file contains multiple natural-language CLI messages in Chinese, including error and usage output. Because the skill does not offer language selection or explain that it is intentionally Chinese-only, it violates the language/locale policy for natural-language content.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This script sends the user-supplied prompt and image references to a third-party generation provider during normal execution, but the regular execution path does not present an explicit runtime warning or confirmation that potentially sensitive inputs will leave the local environment. In this skill context, prompts and images may include product assets, model references, or proprietary brand materials, so accidental disclosure to external services is a realistic privacy and compliance risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file's user-facing strings and instructional comments are written exclusively in Chinese, including operational error messages later in the file, with no indication that this skill is intentionally region-specific or that users can opt into another language. This can violate language/locale policy when a skill imposes a specific language without user choice.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 134)May include surrounding context.

js
model: () => env.GEN_MODEL_OPENAI || 'gpt-image-1',
  describe(req) {
    const ep = req.images?.length ? 'images/edits' : 'images/generations'
    return `POST https://api.openai.com/v1/${ep}  model=${openai.model()} size=${mapSize(req.size)} n=${req.batch}`
  },
  async run(req) {
    const key = env.OPENAI_API_KEY

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This finding overlaps the actual external POST call to OpenAI and represents real third-party transmission of user image data. Because the skill processes wearable try-on imagery, the data sent can be personally sensitive and should not be forwarded silently.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 153)May include surrounding context.

js
: await readFile(p)
        fd.append('image[]', new Blob([buf], { type: mimeOf(p) }), path.basename(p))
      }
      r = await fetch('https://api.openai.com/v1/images/edits', {
        method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
      })
    } else {

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This finding overlaps the actual external POST call to OpenAI and represents real third-party transmission of user image data. Because the skill processes wearable try-on imagery, the data sent can be personally sensitive and should not be forwarded silently.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 153)May include surrounding context.

js
: await readFile(p)
        fd.append('image[]', new Blob([buf], { type: mimeOf(p) }), path.basename(p))
      }
      r = await fetch('https://api.openai.com/v1/images/edits', {
        method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
      })
    } else {

External Transmission

Medium
Category
Data Exfiltration
Confidence
82% confidence
Finding

This finding overlaps the actual external POST call to OpenAI for generation and represents real outbound transmission of user prompt data. In a commerce/try-on workflow, prompt contents can still be sensitive or proprietary and should be treated as externally shared data.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 157)May include surrounding context.

js
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
      })
    } else {
      r = await fetch('https://api.openai.com/v1/images/generations', {
        method: 'POST',
        headers: { authorization: `Bearer ${key}`, 'content-type': 'application/json' },
        body: JSON.stringify({

External Transmission

Medium
Category
Data Exfiltration
Confidence
82% confidence
Finding

This finding overlaps the actual external POST call to OpenAI for generation and represents real outbound transmission of user prompt data. In a commerce/try-on workflow, prompt contents can still be sensitive or proprietary and should be treated as externally shared data.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 157)May include surrounding context.

js
method: 'POST', headers: { authorization: `Bearer ${key}` }, body: fd,
      })
    } else {
      r = await fetch('https://api.openai.com/v1/images/generations', {
        method: 'POST',
        headers: { authorization: `Bearer ${key}`, 'content-type': 'application/json' },
        body: JSON.stringify({

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code sends user prompts and user-supplied images, including local files converted to base64 and remote image content fetched first, to third-party model providers without any disclosure, consent, or policy enforcement in this layer. In a skill that generates wearable try-on images from user assets, those inputs are likely to contain personal photos or proprietary product images, so silent transfer to external APIs creates a real privacy and data-handling risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 261)May include surrounding context.

js
model: (req) =>
    env.GEN_MODEL_REPLICATE ||
    (req?.images?.length ? 'black-forest-labs/flux-kontext-pro' : 'black-forest-labs/flux-dev'),
  describe(req) { return `POST https://api.replicate.com/v1/models/${replicate.model(req)}/predictions` },
  async run(req) {
    const input = { prompt: req.prompt, num_outputs: req.batch }
    if (req.images?.length) input.input_image = await asDataUri(req.images[0])

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The Replicate prediction request sends prompt data and, when present, a base64/data-URI encoded input image to an external provider. In this skill, the input image may be a user's body photo or product asset, making this a meaningful privacy and data-transfer risk if not clearly disclosed and controlled.

Content

Scanner excerpt · scripts/lib/providers.mjs (reported line 266)May include surrounding context.

js
const input = { prompt: req.prompt, num_outputs: req.batch }
    if (req.images?.length) input.input_image = await asDataUri(req.images[0])
    const j = await postJson(
      `https://api.replicate.com/v1/models/${replicate.model(req)}/predictions`,
      { input },
      { authorization: `Bearer ${env.REPLICATE_API_TOKEN}`, prefer: 'wait' },
      req.timeoutMs,

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The persist path writes provider-returned content directly to disk, and if only a URL is returned it fetches remote content and saves it without an explicit user-facing warning in that path. While this is expected functionality for an asset-generation tool, it can still surprise users by storing untrusted external data locally, creating risks around inadvertent retention of sensitive/generated content or handling malformed files.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This file's natural-language content is entirely in Chinese, including maintenance instructions and parser behavior notes, and later user-visible error strings are also Chinese. The policy calls for flagging language/locale constraints when a skill forces a specific language without user choice or clear justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The thrown Error messages at these lines are natural-language strings in Chinese and would surface to developers/users when parsing fails. Because the file provides no locale selection or explicit justification for Chinese-only output, this is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The code spawns an external executable using spawn() based on environment configuration, but there is no confirmation prompt, visible log/print, or warning comment explaining that an external command will be executed. Because subprocess execution is safety-relevant, some form of disclosure is expected unless it is clearly surfaced elsewhere in the skill documentation.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/lib/providers.mjs:104

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/gen.mjs:118

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/lib/providers.mjs:21