Back to skill

Security audit

HiAPI GPT Image 2

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its image-generation purpose, but its installer, update checks, and configurable API host create avoidable risks around local command execution and API-key exposure.

Review before installing. Prefer a pinned commit or signed release instead of the documented npx github command, do not use untrusted custom target paths or AGENT_SKILLS_DIR values, keep HIAPI_BASE_URL at the default https://api.hiapi.ai unless you fully control the endpoint, and treat printed update commands as untrusted until independently verified.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/lib/gpt-image-2.mjs:150
Finding

HiAPI bearer token can be transmitted to an arbitrary or plaintext endpoint

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/install.mjs:101
Finding

Installer command injection through an attacker-controlled target path

Content
View full analysis
a.startsWith(prefix)); return hit ? hit.slice(prefix.length).replace(/^~(?=$|\/)/, homedir()) : null; } const explicitTarget = flagValue('target') ?? flagValue('skills-dir') ?? null; ``` The resulting path is interpolated into a command executed through a shell: ```js function installTo(target) { mkdirSync(target.dir, { recursive: true }); const destination = join(target.dir, SKILL_FOLDER); if (existsSync(destination)) { console.log(`[${DISPLAY_NAME}] ${destination} exists — replacing.`); rmSync(destination, { recursive: true, force: true }); } console.log(`[${DISPLAY_NAME}] Cloning into ${destination} …`); execSync(`git clone --depth 1 ${REPO_URL} "${destination}"`, { stdio: 'inherit' }); } ``` ### Technical Analysis `execSync()` receives a single command string, causing Node.js to invoke a shell. The `destination` value includes the user-controlled `--target`, `--skills-dir`, or `AGENT_SKILLS_DIR` value and is directly interpolated into that shell command. Wrapping the path in double quotes does not make it safe. Shell command substitution such as `$(command)` and backticks remains active inside double quotes. Embedded quotation marks may also terminate the quoted argument and introduce additional shell operators. The installer only needs to invoke Git with fixed arguments and a path. Shell interpretation is unnecessary and creates an avoidable code-execution boundary. ### Attack Path 1. An attacker persuades a user or Agent to run the documented installer with a crafted target value, or controls `AGENT_SKILLS_DIR`. 2. The crafted path contains shell syntax, for example command substi ...[truncated 1101 chars]
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
scripts/lib/gpt-image-2.mjs:350
Finding

Unsigned remote update policy can inject mandatory instructions and block Skill execution

Content
View full analysis
controller.abort(), timeoutMs) : null; try { response = await fetchImpl(manifestUrl, { headers: { Accept: "application/json" }, signal: controller?.signal, }); } catch { return { status: "skipped" }; } finally { if (timer) clearTimeout(timer); } if (!response?.ok) return { status: "skipped" }; let manifest; try { manifest = await response.json(); } catch { return { status: "skipped" }; } const skill = Array.isArray(manifest.skills) ? manifest.skills.find((entry) => entry?.id === skillId) : null; const policy = skill?.updatePolicy; if (!policy) return { status: "current" }; const minimumVersion = policy.minimumVersion || skill.version || currentVersion; const latestVersion = policy.latestVersion || skill.version || minimumVersion; const updateCommand = policy.updateCommand || `npx -y github:HiAPIAI/hiapi-gpt-image-2-skill -y`; if (compareVersions(currentVersion, minimumVersion) < 0) { return { status: "required", message: [ policy.requiredNotice || "This HiAPI skill version is no longer compatible with the curre ...[truncated 3813 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/install.mjs:101
Finding

Installation and update workflow executes code from an unpinned mutable Git source

Content
View full analysis
Remediation
View remediation
' -y ``` 3. Prefer signed release tags and verify the signature before installation. 4. Publish integrity hashes for release artifacts and verify them before execution. 5. Clone without executing fetched code first, verify the commit or artifact, and only then install it. 6. Avoid presenting `npx -y` against a mutable source as the primary trusted installation method. 7. Ensure update instructions use the same immutable and verified release mechanism. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (42)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 131)May include surrounding context.

md
node scripts/check-config.mjs

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The README instructs users to execute npx -y github:HiAPIAI/hiapi-gpt-image-2-skill directly from a GitHub repository without pinning to a specific commit, tag, or release digest. This creates a supply-chain risk: if the upstream repo is compromised or changes unexpectedly, users may execute attacker-controlled installation code on their local machine.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This command uses npx -y github:... without a pinned version, so installation behavior depends on the current state of the remote repository at execution time. An attacker who gains control of the repository or its dependency chain could deliver arbitrary code during install.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The README recommends a direct npx install from GitHub for the --codex path without version pinning. Because npx executes package install scripts, this exposes users to remote code execution if the referenced repository changes or is compromised.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The --claude installation example still relies on an unpinned GitHub source via npx. That means users are encouraged to trust mutable remote code during installation, which is a classic software supply-chain weakness.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This custom target installation command executes code fetched from GitHub without locking the source to a specific immutable version. If the repo or an upstream dependency is tampered with, the installer can perform arbitrary actions in the user's environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The 'Agent Auto-Install Prompt' tells agents to run an unpinned npx -y github:... command, which is especially risky because an automated agent may execute it with little user scrutiny. This increases the chance of silent supply-chain compromise leading to arbitrary code execution.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The upgrade command in the FAQ again directs users to execute an unpinned GitHub package via npx. A compromised upstream could turn the update path into a remote code execution vector across existing installations.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The Codex compatibility install command uses a mutable GitHub reference with npx, carrying the same supply-chain and arbitrary code execution risk as the other examples. Repetition across the README increases the likelihood that users will copy an unsafe pattern.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The Claude Code compatibility example repeats the unpinned npx github: install pattern, exposing users to mutable upstream code execution. This is dangerous because installation happens in the local user context and may affect agent skill directories and environment configuration.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The OpenCode install command uses AGENT_SKILLS_DIR=... npx -y github:... -y with no version pinning. If exploited, a malicious installer could write into skill directories, alter agent behavior, or run arbitrary code under the user's account.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The generic custom-directory install command executes mutable remote code from GitHub using npx, which is a real supply-chain vulnerability pattern. In this skill context, compromise could be especially impactful because the installer places code into agent skill directories, potentially affecting future agent actions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The README instructs users to execute code directly from a GitHub repository via npx -y github:HiAPIAI/hiapi-gpt-image-2-skill without pinning a commit, tag, or package version. This creates a supply-chain risk: if the upstream repository is changed or compromised, users may run attacker-controlled installation code that can modify local agent skill directories and access environment data.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.zh-CN.md (reported line 52)May include surrounding context.

安装脚本会自动检测 Codex(~/.codex/skills)和 Claude Code(~/.claude/skills)。如果两个都存在,-y 会同时装到两个目录。指定 Agent 或自定义目录:

bash
npx -y github:HiAPIAI/hiapi-gpt-image-2-skill --codex          # 只装到 ~/.codex/skills
npx -y github:HiAPIAI/hiapi-gpt-image-2-skill --claude         # 只装到 ~/.claude/skills
npx -y github:HiAPIAI/hiapi-gpt-image-2-skill --target=/path   # 自定义目录
AGENT_SKILLS_DIR=/path npx -y github:HiAPIAI/hiapi-gpt-image-2-skill -y

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

This command again tells users to run an unpinned GitHub-hosted installer with npx, which fetches and executes remote code at install time. Because the script auto-detects agent skill locations, a compromised upstream could write persistence into multiple local agent environments.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The --codex variant still executes unpinned remote code from GitHub, so the flag limiting target location does not reduce the core supply-chain risk. An attacker controlling the fetched code could still perform arbitrary actions during installation on the host system.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The --claude installation example also relies on unpinned remote execution via npx, exposing users to repository compromise or silent upstream changes. Because this is presented as a normal install path, users are encouraged to trust and execute mutable code without review.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

Using --target=/path does not mitigate that the installer itself is unpinned remote code. A malicious update could write outside the intended directory, exfiltrate secrets, or tamper with the target skill content before placement.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The 'copy for your Agent' section encourages delegated execution of an unpinned GitHub installer, amplifying the supply-chain risk because an agent may run it with minimal human scrutiny. This increases the chance of automatic trust in mutable remote code that can persist in agent skill directories.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The FAQ's required update command again directs users to execute mutable code from GitHub through npx. This turns updates into a recurring supply-chain execution point, so any future compromise of the repository could propagate malicious code to existing users.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The Codex compatibility example repeats the unpinned GitHub npx install pattern. In the context of agent skills, this is more dangerous because installation commonly places executable instructions into a directory the agent will later trust and use.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The Claude Code compatibility example also executes unversioned remote installer code, preserving the same supply-chain risk. Because skill directories affect future agent behavior, compromise can have lasting impact beyond the initial install session.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The OpenCode example still uses unpinned GitHub execution via npx, merely changing the destination directory. This can enable arbitrary code execution during install and subsequent trusted placement of malicious skill artifacts.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The generic 'other agents' command extends the same unpinned installer pattern to any environment, broadening exposure. Since users may run this on diverse systems, the attack surface from a compromised upstream installer is significant.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill explicitly instructs users to run Node.js scripts that call external HiAPI endpoints, but the manifest does not declare any tool scope such as allowed network access. This creates an authorization and review gap: consumers or policy engines cannot easily tell that the skill performs outbound network operations, increasing the risk of unintended data egress or misuse of environment-provided secrets like HIAPI_API_KEY.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/install.mjs:94