Back to skill

Security audit

Seede Design Agent Skills

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Seede AI design CLI integration, with expected but privacy-sensitive uploads and token use that users should handle deliberately.

Install only if you are comfortable using Seede AI as an external service. Avoid uploading confidential logos, documents, or customer materials unless you have permission, keep SEEDE_API_TOKEN out of chat logs and shell history, and prefer pinned package versions or a restricted environment for npm/npx installation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:25
Finding

Unpinned Third-Party Packages and Mutable Sources Are Executed During Installation

Content
View full analysis
Remediation
View remediation
add seedeai/seede-skill@ npm install -g seede-cli@ ``` 2. If repository syntax does not support release versions, pin the skill to a reviewed immutable commit hash rather than a branch or mutable tag. 3. Publish and verify expected integrity hashes or signed release artifacts before installation. 4. Use a lockfile for local or CI installation so transitive dependency versions remain reproducible. Prefer a project-local installation over a global installation where practical. 5. Run package installation in a restricted environment with minimal filesystem access, no unnecessary credentials, and limited network access. 6. Disable npm lifecycle scripts during initial acquisition where supported: ```bash npm install --ignore-scripts seede-cli@ ``` Lifecycle scripts should only be enabled after reviewing whether they are required and inspecting their implementation. 7. Document the expected npm registry and trusted repository source to reduce registry substitution and dependency-confusion risks. 8. Add automated dependency auditing, provenance verification, and periodic review of pinned versions before upgrades. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README explicitly promotes asset uploads, design retrieval, and token management against an external Seede AI service, but it does not warn users that files, prompts, branding assets, and API credentials may be transmitted to a third party. In an agent context this is more dangerous because autonomous systems may upload sensitive user materials or create/manage tokens without the operator fully realizing the data leaves the local environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

md
**Key Options:**

- `--no-interactive`: disable prompts; **MANDATORY** for agents.
- `-p, --prompt <string>`: description of the design (required in non-interactive).
- `-s, --scene <string>`: `socialMedia | poster | scrollytelling`.
- `-f, --format <string>`: `webp | png | jpg` (default: `webp`).

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs agents to upload local files to an external service without an explicit warning that local assets will leave the host environment. In an agent setting, this can cause unintended exfiltration of sensitive local files if a user request or downstream prompt references confidential images or documents.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest describes a design CLI for generating UI, graphics, and posters, but this section instructs agents to create and list API tokens. Credential lifecycle management is not an obvious or necessary part of producing designs, and it grants an account-management capability beyond the core design function.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The token creation guidance tells users to create and use API credentials but does not include handling precautions for secrets that are only shown once. In agent and CI contexts, this raises the risk of credential leakage through shell history, logs, transcripts, or insecure environment-variable management.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documented commands include registering accounts, logging in, checking identity, and logging out. For a skill whose stated purpose is generating designs, these account-management actions are ancillary and not clearly justified as part of the intended agent capability set.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The line Or via CLI flags(单一参考图): injects Chinese text into otherwise English documentation without offering any language choice or contextual justification. This can violate language/locale policy by imposing a specific language unexpectedly.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.