T09 · Insecure Skill Coding Practices
- Location
scripts/lib/gpt-image-2.mjs:150- Finding
HiAPI bearer token can be transmitted to an arbitrary or plaintext endpoint
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill matches its image-generation purpose, but its installer, update checks, and configurable API host create avoidable risks around local command execution and API-key exposure.
Review before installing. Prefer a pinned commit or signed release instead of the documented npx github command, do not use untrusted custom target paths or AGENT_SKILLS_DIR values, keep HIAPI_BASE_URL at the default https://api.hiapi.ai unless you fully control the endpoint, and treat printed update commands as untrusted until independently verified.
scripts/lib/gpt-image-2.mjs:150HiAPI bearer token can be transmitted to an arbitrary or plaintext endpoint
scripts/install.mjs:101Installer command injection through an attacker-controlled target path
scripts/lib/gpt-image-2.mjs:350Unsigned remote update policy can inject mandatory instructions and block Skill execution
scripts/install.mjs:101Installation and update workflow executes code from an unpinned mutable Git source
Referenced artifact was not completely inspected
node scripts/check-config.mjs
The README instructs users to execute npx -y github:HiAPIAI/hiapi-gpt-image-2-skill directly from a GitHub repository without pinning to a specific commit, tag, or release digest. This creates a supply-chain risk: if the upstream repo is compromised or changes unexpectedly, users may execute attacker-controlled installation code on their local machine.
This command uses npx -y github:... without a pinned version, so installation behavior depends on the current state of the remote repository at execution time. An attacker who gains control of the repository or its dependency chain could deliver arbitrary code during install.
The README recommends a direct npx install from GitHub for the --codex path without version pinning. Because npx executes package install scripts, this exposes users to remote code execution if the referenced repository changes or is compromised.
The --claude installation example still relies on an unpinned GitHub source via npx. That means users are encouraged to trust mutable remote code during installation, which is a classic software supply-chain weakness.
This custom target installation command executes code fetched from GitHub without locking the source to a specific immutable version. If the repo or an upstream dependency is tampered with, the installer can perform arbitrary actions in the user's environment.
The 'Agent Auto-Install Prompt' tells agents to run an unpinned npx -y github:... command, which is especially risky because an automated agent may execute it with little user scrutiny. This increases the chance of silent supply-chain compromise leading to arbitrary code execution.
The upgrade command in the FAQ again directs users to execute an unpinned GitHub package via npx. A compromised upstream could turn the update path into a remote code execution vector across existing installations.
The Codex compatibility install command uses a mutable GitHub reference with npx, carrying the same supply-chain and arbitrary code execution risk as the other examples. Repetition across the README increases the likelihood that users will copy an unsafe pattern.
The Claude Code compatibility example repeats the unpinned npx github: install pattern, exposing users to mutable upstream code execution. This is dangerous because installation happens in the local user context and may affect agent skill directories and environment configuration.
The OpenCode install command uses AGENT_SKILLS_DIR=... npx -y github:... -y with no version pinning. If exploited, a malicious installer could write into skill directories, alter agent behavior, or run arbitrary code under the user's account.
The generic custom-directory install command executes mutable remote code from GitHub using npx, which is a real supply-chain vulnerability pattern. In this skill context, compromise could be especially impactful because the installer places code into agent skill directories, potentially affecting future agent actions.
The README instructs users to execute code directly from a GitHub repository via npx -y github:HiAPIAI/hiapi-gpt-image-2-skill without pinning a commit, tag, or package version. This creates a supply-chain risk: if the upstream repository is changed or compromised, users may run attacker-controlled installation code that can modify local agent skill directories and access environment data.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
安装脚本会自动检测 Codex(~/.codex/skills)和 Claude Code(~/.claude/skills)。如果两个都存在,-y 会同时装到两个目录。指定 Agent 或自定义目录:
npx -y github:HiAPIAI/hiapi-gpt-image-2-skill --codex # 只装到 ~/.codex/skills
npx -y github:HiAPIAI/hiapi-gpt-image-2-skill --claude # 只装到 ~/.claude/skills
npx -y github:HiAPIAI/hiapi-gpt-image-2-skill --target=/path # 自定义目录
AGENT_SKILLS_DIR=/path npx -y github:HiAPIAI/hiapi-gpt-image-2-skill -y
This command again tells users to run an unpinned GitHub-hosted installer with npx, which fetches and executes remote code at install time. Because the script auto-detects agent skill locations, a compromised upstream could write persistence into multiple local agent environments.
The --codex variant still executes unpinned remote code from GitHub, so the flag limiting target location does not reduce the core supply-chain risk. An attacker controlling the fetched code could still perform arbitrary actions during installation on the host system.
The --claude installation example also relies on unpinned remote execution via npx, exposing users to repository compromise or silent upstream changes. Because this is presented as a normal install path, users are encouraged to trust and execute mutable code without review.
Using --target=/path does not mitigate that the installer itself is unpinned remote code. A malicious update could write outside the intended directory, exfiltrate secrets, or tamper with the target skill content before placement.
The 'copy for your Agent' section encourages delegated execution of an unpinned GitHub installer, amplifying the supply-chain risk because an agent may run it with minimal human scrutiny. This increases the chance of automatic trust in mutable remote code that can persist in agent skill directories.
The FAQ's required update command again directs users to execute mutable code from GitHub through npx. This turns updates into a recurring supply-chain execution point, so any future compromise of the repository could propagate malicious code to existing users.
The Codex compatibility example repeats the unpinned GitHub npx install pattern. In the context of agent skills, this is more dangerous because installation commonly places executable instructions into a directory the agent will later trust and use.
The Claude Code compatibility example also executes unversioned remote installer code, preserving the same supply-chain risk. Because skill directories affect future agent behavior, compromise can have lasting impact beyond the initial install session.
The OpenCode example still uses unpinned GitHub execution via npx, merely changing the destination directory. This can enable arbitrary code execution during install and subsequent trusted placement of malicious skill artifacts.
The generic 'other agents' command extends the same unpinned installer pattern to any environment, broadening exposure. Since users may run this on diverse systems, the attack surface from a compromised upstream installer is significant.
The skill explicitly instructs users to run Node.js scripts that call external HiAPI endpoints, but the manifest does not declare any tool scope such as allowed network access. This creates an authorization and review gap: consumers or policy engines cannot easily tell that the skill performs outbound network operations, increasing the risk of unintended data egress or misuse of environment-provided secrets like HIAPI_API_KEY.
Detected: suspicious.dangerous_exec