Back to skill

Security audit

generate-poster

Security checks for vulnerabilities and agentic risk

Overview

This skill is for a real poster-generation API, but it should be reviewed because it can upload local images to permanent public links and its examples handle API keys unsafely.

Install only if users understand that product images and API keys are sent to Flyelep and that local uploads may become permanent public URLs. Avoid confidential, regulated, personal, or unreleased assets; provide keys through safer header/secret handling where possible; and avoid examples that put the key in request bodies, shell history, or plaintext temporary files.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:276
Finding

Local images are uploaded to permanent, unsigned public URLs without an explicit consent or deletion workflow

Content
View full analysis
" \ --max-time 120 \ -F "file=@./product.png" ``` The documented response demonstrates that the uploaded file receives a public cloud-storage URL: ```json { "code": 200, "data": { "relativePath": "cos_ai_agent/2026-08-11/3f2a9c1b7d84e6f5a012.png", "fullPath": "https://agent-1404002717.cos.ap-guangzhou.myqcloud.com/cos_ai_agent/2026-08-11/3f2a9c1b7d84e6f5a012.png" } } ``` ### Technical Analysis The skill instructs the agent to upload local user images to third-party Flyelep infrastructure whenever a public image URL is required. The returned object URL is explicitly described as public, permanently valid, and unsigned. An unsigned public URL is a bearer capability: anyone who obtains the URL can retrieve the image without authentication. Because the URL does not expire, exposure persists after the image-generation operation has finished. The skill provides no deletion endpoint, retention limit, post-processing cleanup, access-control mechanism, or explicit informed-consent checkpoint before upload. Although the URL contains a likely high-entropy object identifier and may not be practically enumerable, confidentiality still depends entirely on keepi ...[truncated 1457 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:317
Finding

API keys are exposed through command-line arguments and predictable plaintext temporary files

Content
View full analysis
","generateType":100,"posterType":5,"platformType":"Amazon","languageType":"English","detailPictureNumber":1,"modelEdition":9,"channel":"promotion","needText":true,"secretKey":""}', [System.Text.UTF8Encoding]::new($false) ) ``` The file is subsequently supplied to `curl` and removed only after the request: ```bash curl.exe --% -X POST \ "https://www.flyelep.cn/prod-api/poster-design/api/v1/poster/generateAsync" \ -H "Content-Type: application/json; charset=utf-8" \ --max-time 120 \ --data-binary @payload_temp.json rm payload_temp.json ``` The macOS/Linux examples place the key directly in the command-line JSON body: ```bash curl -X POST \ "https://www.flyelep.cn/prod-api/poster-design/api/v1/poster/generateAsync" \ -H "Content-Type: application/json; charset=utf-8" \ --max-time 120 \ --data-binary '{"query":"","generateType":100,"secretKey":""}' ``` Other examples place the same key in both the request header and body: ```bash curl -X POST \ "https://www.flyelep.cn/prod-api/poster-design/api/v1/poster/generate" \ -H "Content-Type: application/json; charset=utf-8" \ -H "secretKey: " \ --max-time 960 \ --data-binary '{"query":"","generateType":100,"secretKey":""}' ``` ### Technical Analysis The examples encourage several unsaf ...[truncated 3345 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill activation language is very broad and overlaps with generic image-generation requests, increasing the chance the agent routes users into a third-party API workflow when they only asked for ordinary image creation help. In context, that matters because this skill collects API keys and may upload user-supplied images to external infrastructure, so overbroad triggering can cause unintended external transmission and surprise third-party processing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file-upload section instructs the agent to send local files to Flyelep/Tencent Cloud-backed storage and notes the resulting URLs are permanent, but it does not clearly warn users that their files and generated assets are being transmitted to and stored by third-party infrastructure. This creates a meaningful privacy and data-governance risk, especially if users provide sensitive product images, unreleased creative assets, or proprietary materials without informed consent.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

This skill explicitly directs transmission of user-provided local files and secrets to an external service, which is expected for the feature but still constitutes a real security/privacy exposure surface. The risk is heightened by the same section's statement that uploaded files become available at permanent URLs, so accidental upload of sensitive content could result in durable third-party exposure beyond the immediate generation task.

Content

Scanner excerpt · SKILL.md (reported line 304)May include surrounding context.

判断成功只看 code,业务失败时 HTTP 状态码仍是 200,code 为 500 或 9999,原因在 msg 里。

bash
# Windows/PowerShell(用 curl.exe,PowerShell 里的 curl 是 Invoke-WebRequest 的别名)
curl.exe -X POST "https://www.flyelep.cn/prod-api/poster-design/api/v1/file/upload" -H "secretKey: 你的密钥" --max-time 120 -F "file=@C:/path/to/product.png"

# macOS/Linux

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

该 PowerShell 示例位于“生成产品主图(跨境电商,Amazon)”章节,但 query 文本写成了“生成一张白底产品主图”,而代码参数却使用 generateType:100,不是白底主图的 101。这会让调用者误以为该示例在演示白底图能力,属于文档意图与实际请求参数相矛盾。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

这一行对应的示例仍处于“生成产品主图(跨境电商,Amazon)”流程中,但内联 JSON 的 query 写的是“白底产品主图”,同时 generateType 仍是 100。文档文字与请求语义不一致,容易让使用者错误理解该接口用途。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.