Back to skill

Security audit

Flux Image

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Flux image API guide, with expected external API use and an optional unpinned MCP package install users should review.

Install only if you are comfortable sending prompts, parameters, and referenced image URLs to AceDataCloud for processing. Do not include secrets, regulated data, private images, or signed URLs unless your organization approves that provider. If using the optional MCP server, install it in an isolated environment and verify the package source/version first.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:80
Finding

Unpinned Third-Party Python Package Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 80
Vulnerability Type: Unpinned third-party dependency
Risk Level: Medium

Vulnerable Code Snippet:

bash
pip install mcp-flux

Technical Analysis

The skill instructs users to install mcp-flux from pip's configured package index without specifying a version, cryptographic hash, trusted source repository, or integrity verification procedure. Consequently, the installed artifact can change independently of the reviewed skill content.

This creates a supply-chain risk: compromise of the package, its publisher account, its dependencies, or the configured package index could cause users to install attacker-controlled code. The audit did not establish that mcp-flux is currently malicious; the confirmed weakness is the absence of dependency pinning and artifact verification.

Attack Path

  1. An attacker compromises the mcp-flux distribution channel, publisher account, package release process, or one of its unresolved dependencies.
  2. The attacker publishes a malicious release under the package name expected by the documented command.
  3. A user follows the skill instructions and runs pip install mcp-flux.
  4. Pip resolves the current package and dependency versions from its configured index without checking project-provided hashes.
  5. Attacker-controlled code may execute during installation or later when the installed package is imported or launched.

Impact Assessment

Malicious dependency code could execute with the privileges of the user who installs or runs the package. Depending on those privileges and the local environment, the compromise could affect accessible files, environment variables, API credentials, network resources, and subsequent MCP operations. System-wide or privileged installation would increase the potential scope.

The project contains only SKILL.md; no embedded scripts, persistence mechanisms, instruction hij ...[truncated 61 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the dependency to a reviewed, exact version, such as mcp-flux==<reviewed-version>.
  • Publish and verify cryptographic hashes using a requirements file and pip install --require-hashes.
  • Document the package's verified official repository, publisher identity, and release provenance.
  • Review and pin transitive dependencies through a lockfile or hash-locked requirements file.
  • Prefer signed releases or attestations where supported, and verify them before installation.
  • Recommend installation in a dedicated virtual environment or isolated container using a non-privileged account.
  • Establish a periodic dependency-review process before updating the pinned version.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill documents authentication and API usage but does not clearly disclose that prompts and any referenced content are sent to AceDataCloud, a third-party service. This creates a privacy and data-handling risk because users may submit sensitive prompts, proprietary descriptions, or internal asset references without informed consent.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The example performs an authenticated POST to an external API endpoint, which means prompt contents and request metadata leave the local environment. In the context of an agent skill, this is expected functionality, but it still constitutes a real data egress path that can expose sensitive user inputs if not clearly disclosed and constrained.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

Quick Start

bash
curl -X POST https://api.acedata.cloud/flux/images \
  -H "Authorization: Bearer $ACEDATACLOUD_API_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"prompt": "a cat wearing a space helmet, photorealistic", "model": "flux-dev", "wait": true}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The example performs an authenticated POST to an external API endpoint, which means prompt contents and request metadata leave the local environment. In the context of an agent skill, this is expected functionality, but it still constitutes a real data egress path that can expose sensitive user inputs if not clearly disclosed and constrained.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

Quick Start

bash
curl -X POST https://api.acedata.cloud/flux/images \
  -H "Authorization: Bearer $ACEDATACLOUD_API_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"prompt": "a cat wearing a space helmet, photorealistic", "model": "flux-dev", "wait": true}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The image editing section shows use of image_url and editing prompts without warning that the referenced image and associated instructions are sent to an external service. This is dangerous because users may unknowingly expose private images, signed URLs, or confidential visual material to a third party.

Content

No source excerpt is available for this finding.

Rp1

Low
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The documentation instructs users to install an MCP dependency without pinning a specific version, which can lead to non-reproducible installs and unexpected behavior if a later package version is compromised or introduces breaking changes. In a security-sensitive agent/tooling context, unpinned dependencies increase supply-chain risk, even though this is documentation rather than executable code in the skill itself.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.