Back to skill

Security audit

Prompt Artist

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches an AI prompt-optimization tool, but its billing command can charge a SkillPay account by default without an explicit confirmation step.

Review this skill carefully before installing. The prompt and style features are local and low impact, but the billing command uses SKILLPAY_API_KEY and can send charge requests to SkillPay.me. Do not let an agent run the billing command automatically; require an explicit user approval for each charge and verify the expected amount and user id first.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A second substantial description-to-behavior mismatch indicates the skill claims billing integration, multilingual prompt generation, and platform-specific optimization that are reportedly not implemented, while actual behavior is largely static style browsing. Security-wise, this creates a trust and transparency failure that can mislead users into sharing data or expecting payment-related protections and controls that do not exist.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A second substantial description-to-behavior mismatch indicates the skill claims billing integration, multilingual prompt generation, and platform-specific optimization that are reportedly not implemented, while actual behavior is largely static style browsing. Security-wise, this creates a trust and transparency failure that can mislead users into sharing data or expecting payment-related protections and controls that do not exist.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill advertises executable scripts and requires an API key, but it does not declare any explicit tool scope or permissions despite detected capabilities for environment access, file writes, and network use. In an agent ecosystem, missing capability declarations undermine least-privilege controls and can cause the skill to be invoked with broader access than users or orchestrators expect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation presents billing and payment-related commands as normal operations without any warning that they may charge a user account or modify financial state. In an agent-driven environment, users may trigger these actions indirectly, so lack of clear confirmation expectations raises the risk of unintended charges and disputed transactions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow explicitly includes a charge command as step 1, but it does not indicate that this changes payment/account state or should only occur after informed user consent. This is particularly risky for autonomous agents because a workflow example can normalize auto-charging behavior before the user has reviewed cost or approved payment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code sends a user ID, skill ID, and billing/payment amounts to a remote API via HTTP requests, but there is no confirmation prompt, user-facing log message, or explanatory comment/docstring warning that billing data will be transmitted. For a code file, these are safety-relevant network operations affecting user billing and privacy, and the file provides no visible disclosure beyond implementation details.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code emits user-facing titles and status text exclusively in Chinese, such as 收藏提示词, 提示词历史, 风格, and 空列表. For a general-purpose history utility, forcing a specific language without opt-in or documented regional restriction is a natural-language policy violation under the locale-choice requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script emits all human-readable labels in Chinese, such as the title and field names, with no opt-in, fallback, or indication that the skill is intended only for Chinese-speaking users. This can violate language/locale policy expectations when skills should not force a specific language without user choice or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The user-facing output strings in format_output are hardcoded in Chinese, even when the selected platform is English (midjourney or nano_banana) and there is no option to choose output language. This is a natural-language locale policy issue because the skill imposes a specific language without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This Python file contains user-facing natural-language strings such as category names, style descriptions, and usage text entirely in Chinese. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The specification states 'English preferred' for Midjourney, which is a natural-language locale preference presented as default guidance rather than an explicit user choice. Under the policy, forcing or steering toward a specific language without opt-in can be a language-policy concern unless it is clearly justified as platform-required.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The specification states 'English preferred' for Nano Banana, which nudges output toward a specific language without indicating that the user can choose another language. The policy allows locale constraints when they are justified or opt-in, but neither is stated here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The helper reads the sensitive environment variable SKILLPAY_API_KEY, but the file contains no comment, docstring detail, or user-facing notice explaining that a credential is required and will be used for authenticated billing requests. Under the code-file criteria, sensitive credential access should not be silent when there is no other disclosure present.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.