T08 · Insecure Dependencies
- Location
scripts/deploy-worker.sh:24- Finding
Unpinned Package Execution During Cloudflare Deployment
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This image-generation skill mostly matches its purpose, but it needs Review because it can silently route prompts to a paid third-party service and includes an ambiguous Cloudflare deployment script.
Install only if you are comfortable sending prompts to Cloudflare and possibly EvoLink, storing prompt history locally, and manually reviewing the deployment script before running it. Avoid sensitive prompts unless you accept the provider and channel data flows, and do not run scripts/deploy-worker.sh without first pinning Wrangler and confirming the sage-image-gen target is intentional.
scripts/deploy-worker.sh:24Unpinned Package Execution During Cloudflare Deployment
nexpix.js:166Unrestricted Provider-Controlled URL Download Enables SSRF and Resource Exhaustion
The skill is presented primarily as an image-generation utility, but the documented file layout and behavior include deployment automation for a Cloudflare Worker via a shell script. That mismatch can mislead operators into approving or invoking the skill in contexts where they did not intend to permit infrastructure changes, creating risk of unauthorized deployment actions and broader cloud-side impact.
Referenced artifact was not completely inspected
| `nexpix.js` | Core module (routing, generation, tracking) |
The skill advertises behavior that relies on environment-backed secrets such as Cloudflare and optional EvoLink API keys, but it does not declare an explicit tool scope or permissions boundary. In an agent ecosystem, this increases the chance that the skill can access sensitive environment data or be invoked with broader capabilities than reviewers and users expect.
The trigger list includes broad activation language such as generic image-generation requests, which can cause the skill to activate in many ordinary conversations. Overbroad triggering is dangerous because it can unexpectedly route prompts to external services, consume quota or paid fallback credits, and handle user content in contexts where the user did not clearly consent to using this specific skill.
The skill logs prompts and generation metadata, including the full prompt text and local file path, into a persistent tracking file without any user-facing notice or opt-in. Prompts for image generation can contain sensitive business ideas, personal data, or confidential creative material, so silent retention creates a privacy and data exposure risk if the workstation, workspace, or backups are accessed by others.
When Workers AI fails or quota conditions change, the code can automatically send the user's prompt to EvoLink, a separate paid third-party service, without explicit notice or confirmation at the time of use. This is dangerous because users may assume prompts stay on the free/default provider, while sensitive or proprietary text is instead transmitted externally and may incur cost and different data handling terms.
The integration examples send user prompts and generated images to third-party services including Discord, Telegram, and image-generation backends, but the documentation does not clearly warn users about that external data transmission. This creates a privacy and consent risk, especially because prompts may contain sensitive business data, personal information, or confidential content that is then relayed across multiple external platforms.
Using npx wrangler deploy without pinning an exact Wrangler version allows whatever version is resolved at runtime to be executed. In a deployment script, this creates supply-chain and reproducibility risk: a compromised, unexpected, or newly breaking package version could alter deployment behavior or run attacker-controlled install hooks in the operator's environment.
The file is presented as deploying the NexPix worker, but both the comments and actual target directory/URL refer to a different worker name, sage-image-gen. This creates an intent/documentation contradiction that could cause operators to deploy or inspect the wrong service.
No suspicious patterns detected.