Back to skill

Security audit

Seedream Image

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward guide for using a hosted image-generation API, with expected external API use and an optional MCP install that users should treat carefully.

Before installing, understand that prompts, source image URLs, mask URLs, and generated-image requests go to AceDataCloud/Seedream. Do not send secrets, private internal URLs, regulated data, or confidential images unless that provider is approved for your use. If using the optional MCP package, install it in a dedicated virtual environment and consider pinning or verifying the package version first.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:89
Finding

Unpinned Third-Party MCP Package Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 89
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

Vulnerable Code

bash
pip install mcp-seedream

Technical Analysis

The documented installation command retrieves and installs the latest available version of mcp-seedream without an exact version constraint or cryptographic hash verification. Consequently, the effective dependency code can change after this skill has been reviewed.

The project does not include the package source, a lock file, integrity hashes, or other provenance controls. If a future package release or its distribution account is compromised, users following this instruction could install attacker-controlled code. Python package installation may execute build-system hooks during installation, while the installed MCP server can execute code later when invoked.

Attack Path

  1. An attacker compromises the package publisher account, distribution process, or another relevant software-supply-chain component.
  2. The attacker publishes a malicious release under the expected mcp-seedream package name.
  3. A user follows the instruction in SKILL.md and runs pip install mcp-seedream.
  4. Because no version or hash is pinned, pip resolves and downloads the attacker-controlled release.
  5. Malicious code executes during package installation or when the installed MCP server is subsequently invoked.
  6. The code operates with the privileges of the installing or invoking user and may access data available in that environment, potentially including ACEDATACLOUD_API_TOKEN.

Impact Assessment

Successful exploitation could provide arbitrary code execution with the privileges of the user who installs or runs the package. The accessible scope may include the user's files, environment variables, application credentials, and network access. In the documented environment, the configured AceDataCloud API token could be exposed or mis ...[truncated 184 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the dependency to an exact, reviewed version, for example:
    bash
    python -m pip install "mcp-seedream==<reviewed-version>"
    
  • Distribute a lock file or requirements file containing cryptographic hashes, and install with --require-hashes.
  • Verify the package publisher, source repository, release signatures, and package provenance before recommending it.
  • Review the pinned package source and repeat the review before updating the pinned version.
  • Recommend installation in a dedicated virtual environment with minimal filesystem and credential access.
  • Avoid installing or running the package with administrative or root privileges.
  • Provide the verified source location and expected package hash so users can independently validate the downloaded artifact.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs users to send prompts and, for editing, image URLs/mask URLs to AceDataCloud's third-party API without clearly warning that user-provided content leaves the local environment. This can lead to unintended disclosure of sensitive prompts, private image locations, or confidential data embedded in supplied URLs, especially in agentic contexts where users may assume processing is local.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

This skill explicitly sends user input to https://api.acedata.cloud/seedream/images, which is expected for a hosted image-generation service but still constitutes external data transmission. In the context of prompts and possible future user-supplied content, this is dangerous if the skill does not clearly disclose that potentially sensitive data will be transmitted to a third party.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

Quick Start

bash
curl -X POST https://api.acedata.cloud/seedream/images \
  -H "Authorization: Bearer $ACEDATACLOUD_API_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"prompt": "a cyberpunk cat wearing VR goggles in a neon city", "model": "seedream-3.0"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

This skill explicitly sends user input to https://api.acedata.cloud/seedream/images, which is expected for a hosted image-generation service but still constitutes external data transmission. In the context of prompts and possible future user-supplied content, this is dangerous if the skill does not clearly disclose that potentially sensitive data will be transmitted to a third party.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

Quick Start

bash
curl -X POST https://api.acedata.cloud/seedream/images \
  -H "Authorization: Bearer $ACEDATACLOUD_API_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"prompt": "a cyberpunk cat wearing VR goggles in a neon city", "model": "seedream-3.0"}'

Rp1

Low
Category
MCP Rug Pull
Confidence
60% confidence
Finding

pip install without ==version installs the latest release, which could include malicious changes.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.