Back to skill

Security audit

product-color-change

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Flyelep API helper for changing product image colors, with expected use of a user-provided API key and optional image upload.

Before installing, users should understand that their API key is used at runtime and any local images sent through the upload path may become permanently accessible via a public provider URL; use it only with images and credentials appropriate for Flyelep.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.