Back to skill

Security audit

autoGenImageSkill

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent image-generation tool, but it can send prompts, images, and credentials to configurable services with weak endpoint safeguards that users should review before installing.

Install only if you trust the image backend you configure. Prefer official mode without overriding OPENAI_BASE_URL, avoid passing secrets as command-line arguments, use environment or secret-manager injection instead, and treat proxy or reserved relay modes as third-party data sharing for prompts and source images.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/gpt_image_cli.js:448
Finding

Official API credentials can be transmitted to an arbitrary or cleartext endpoint

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/gpt_image_cli.js:143
Finding

Relay-controlled image URL enables server-side request forgery

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:44
Finding

Sensitive credentials are passed through process command-line arguments

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (13)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 18)May include surrounding context.

md
The main script is [scripts/gpt_image_cli.js](scripts/gpt_image_cli.js). Run it with Node 18+. In OpenClaw, reference it as `{baseDir}/scripts/gpt_image_cli.js`

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
88% confidence
Finding

The output rules instruct the agent to always return the absolute output path plus decisive metadata including endpoint/relay job ID and any revised prompt. Exposing internal filesystem paths and service metadata can leak environmental details useful for reconnaissance, and returning revised prompts may reveal provider-side transformations or sensitive prompt content that the user did not explicitly request back.

Content

Scanner excerpt · SKILL.md (reported line 126)May include surrounding context.

md
- Read [references/access-modes.md](references/access-modes.md) when choosing among official, proxy, and reserved entries or when a user asks how to configure them.
- Read [references/runtime.md](references/runtime.md) when debugging generation, SSE parsing, relay quota, OpenClaw/Hermes packaging, or the relationship to the original `gpt_image` project.

## Output Rules

Always return the absolute output image path and the decisive metadata: access mode, endpoint or relay job ID, provider name when available, byte size, and any revised prompt returned by the model. Keep credentials redacted.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill invokes a Node CLI that uses environment variables and makes outbound network requests, but the manifest does not declare any tool scope such as permissions or allowed-tools. This creates a trust and sandboxing gap: agents or platforms may allow broader execution than users expect, increasing the risk of unintended secret access or arbitrary external calls.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill enables implicit invocation but provides no explicit gating conditions, scope limits, or user-confirmation requirements. Because this skill can trigger image generation through official keys, custom proxies, or reserved-capacity relays, over-broad automatic activation could cause unintended external API usage, quota consumption, or routing of user prompts to third-party infrastructure without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The reserved mode documentation instructs users to send a user ID, optional profile name, purchase key, and potentially a local image (converted to a data URL) to a relay service, but it does not clearly warn that this is third-party data transmission. In a skill handling image generation, this matters because prompts and images may contain sensitive personal or business information, and users may assume behavior similar to direct official API usage.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script allows prompts and optional input images to be sent to a user-supplied proxy or relay endpoint, not just the official OpenAI API. In this skill context, prompts and images may contain sensitive user data, and the CLI does not provide an explicit warning, trust check, or endpoint allowlist before transmitting them to arbitrary services.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/access-modes.md (reported line 31)May include surrounding context.

md
const baseUrl =
    mode === 'official'
      ? stringValue(args['base-url'], process.env.OPENAI_BASE_URL) || 'https://api.openai.com/v1'
      : requireValue('base-url or GPT_IMAGE_BASE_URL', stringValue(args['base-url'], process.env.GPT_IMAGE_BASE_URL));

  const inputImage = readImageDataUrl(stringValue(args.image, process.env.GPT_IMAGE_INPUT_IMAGE));

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/gpt_image_cli.js (reported line 455)May include surrounding context.

js
const baseUrl =
    mode === 'official'
      ? stringValue(args['base-url'], process.env.OPENAI_BASE_URL) || 'https://api.openai.com/v1'
      : requireValue('base-url or GPT_IMAGE_BASE_URL', stringValue(args['base-url'], process.env.GPT_IMAGE_BASE_URL));

  const inputImage = readImageDataUrl(stringValue(args.image, process.env.GPT_IMAGE_INPUT_IMAGE));

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill README switches from English to Chinese for the sponsorship section and several example prompts, but does not state that Chinese is optional or offer a language preference. Under the stated policy, forcing or assuming a specific language without user opt-in can be a natural-language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The skill description is presented in Chinese on one line and English on another, but there is no indication that language selection is based on user preference or opt-in. This may create an inconsistent language experience and can violate a language/locale policy if users are expected to receive content in their chosen language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The example command includes a Chinese prompt as the presented usage pattern, and another example later does the same. In the absence of any note that prompt language is optional or user-selected, this can be read as imposing a specific language preference, which falls under the language/locale policy check.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

This example again presents Chinese as the default prompt language with no surrounding text offering language choice. Repeated single-locale examples can create an implicit language constraint in documentation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The session command can persist serviceUrl, userId, and profile-related state to a predictable file in the user's home directory without prominently disclosing that persistence behavior. While it does not store high-value secrets here, writing identifiers and service metadata to disk can create privacy and operational leakage, especially on shared systems.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/gpt_image_cli.js:76