Back to skill

Security audit

NexPix — Cloudflare Image Generation

Security checks for vulnerabilities and agentic risk

Overview

This image-generation skill mostly matches its purpose, but it needs Review because it can silently route prompts to a paid third-party service and includes an ambiguous Cloudflare deployment script.

Install only if you are comfortable sending prompts to Cloudflare and possibly EvoLink, storing prompt history locally, and manually reviewing the deployment script before running it. Avoid sensitive prompts unless you accept the provider and channel data flows, and do not run scripts/deploy-worker.sh without first pinning Wrangler and confirming the sage-image-gen target is intentional.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
scripts/deploy-worker.sh:24
Finding

Unpinned Package Execution During Cloudflare Deployment

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
nexpix.js:166
Finding

Unrestricted Provider-Controlled URL Download Enables SSRF and Resource Exhaustion

Content
View full analysis
{ const client = url.startsWith('https') ? https : require('http'); client.get(url, (res) => { if (res.statusCode >= 300 && res.statusCode < 400 && res.headers.location) { return downloadFile(res.headers.location, filepath).then(resolve).catch(reject); } const ws = fs.createWriteStream(filepath); res.pipe(ws); ws.on('finish', () => { ws.close(); resolve(); }); ws.on('error', reject); }).on('error', reject); }); } ``` The URL is obtained from the EvoLink task response and passed directly to the downloader: ```javascript if (status.status === 'completed' && status.results?.[0]) { const imageUrl = status.results[0].url || status.results[0]; const elapsed = ((Date.now() - startTime) / 1000).toFixed(1); fs.mkdirSync(MEDIA_DIR_PAID, { recursive: true }); const ext = imageUrl.includes('.png') ? 'png' : imageUrl.includes('.webp') ? 'webp' : 'jpg'; const filename = `nexpix-${Date.now()}.${ext}`; const filepath = path.join(MEDIA_DIR_PAID, filename); await downloadFile(imageUrl, filepath); ``` ### Technical Analysis The downloader trusts a URL supplied by the remote EvoLink task response. It does not validate the URL scheme, destination hostname, resolved IP address, response status, content type, or response size. The protocol selection permits plaintext HTTP for any URL that does not begin with the exact string `https`. Redirects are recursively followed without a redirect limit and without revalidating whether each destination is an approved public image host. This can allow requests to loopback, private-network, link-local, o ...[truncated 2454 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill is presented primarily as an image-generation utility, but the documented file layout and behavior include deployment automation for a Cloudflare Worker via a shell script. That mismatch can mislead operators into approving or invoking the skill in contexts where they did not intend to permit infrastructure changes, creating risk of unauthorized deployment actions and broader cloud-side impact.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 96)May include surrounding context.

md
| `nexpix.js` | Core module (routing, generation, tracking) |

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill advertises behavior that relies on environment-backed secrets such as Cloudflare and optional EvoLink API keys, but it does not declare an explicit tool scope or permissions boundary. In an agent ecosystem, this increases the chance that the skill can access sensitive environment data or be invoked with broader capabilities than reviewers and users expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list includes broad activation language such as generic image-generation requests, which can cause the skill to activate in many ordinary conversations. Overbroad triggering is dangerous because it can unexpectedly route prompts to external services, consume quota or paid fallback credits, and handle user content in contexts where the user did not clearly consent to using this specific skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill logs prompts and generation metadata, including the full prompt text and local file path, into a persistent tracking file without any user-facing notice or opt-in. Prompts for image generation can contain sensitive business ideas, personal data, or confidential creative material, so silent retention creates a privacy and data exposure risk if the workstation, workspace, or backups are accessed by others.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

When Workers AI fails or quota conditions change, the code can automatically send the user's prompt to EvoLink, a separate paid third-party service, without explicit notice or confirmation at the time of use. This is dangerous because users may assume prompts stay on the free/default provider, while sensitive or proprietary text is instead transmitted externally and may incur cost and different data handling terms.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The integration examples send user prompts and generated images to third-party services including Discord, Telegram, and image-generation backends, but the documentation does not clearly warn users about that external data transmission. This creates a privacy and consent risk, especially because prompts may contain sensitive business data, personal information, or confidential content that is then relayed across multiple external platforms.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

Using npx wrangler deploy without pinning an exact Wrangler version allows whatever version is resolved at runtime to be executed. In a deployment script, this creates supply-chain and reproducibility risk: a compromised, unexpected, or newly breaking package version could alter deployment behavior or run attacker-controlled install hooks in the operator's environment.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file is presented as deploying the NexPix worker, but both the comments and actual target directory/URL refer to a different worker name, sage-image-gen. This creates an intent/documentation contradiction that could cause operators to deploy or inspect the wrong service.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.