T09 · Insecure Skill Coding Practices
- Location
scripts/generate.js:72- Finding
Unrestricted Local File Upload Through the Reference Image Parameter
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
Picnow is a coherent image-generation skill, but its reference-image path can upload any readable local file to a third-party API without validation or confirmation.
Review this skill before installing. Use it only with prompts and images you are willing to send to api.letmego.top, avoid passing arbitrary local paths to --ref, and prefer pinned install sources plus a secret manager or temporary environment variable for the API key.
scripts/generate.js:72Unrestricted Local File Upload Through the Reference Image Parameter
README.md:12Unpinned npx Installers Permit Mutable Supply-Chain Code Execution
The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
The skill uses 'network' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
The README instructs users to run npx skillpm install @jxai/picnow without pinning a specific version. This creates a supply-chain risk because future package updates or a compromised publisher account could cause users to fetch and execute different code than expected. In the context of an agent skill, install commands are especially sensitive because they often run with the user's local privileges.
The command npx skills install jeekchen/picnow-skill references an unpinned installer and an unpinned repository target. This means users may retrieve whatever code is current at execution time, increasing exposure to repository compromise, malicious force-pushes, or unexpected breaking changes. Because this is an install path for executable skill content, the resulting risk is a real supply-chain issue.
The README explains how to obtain and set an API token but does not clearly warn users that prompts and reference images are sent to api.letmego.top, an external service. This omission can lead users to unknowingly upload sensitive business materials, personal photos, or confidential prompts. In an image-editing skill, reference images are especially privacy-sensitive, so the missing disclosure is a meaningful security and privacy issue.
The README recommends persisting LETMEGO_API_KEY in shell startup files or permanent user environment settings. This increases the lifetime and exposure surface of the credential: other local processes, accidental dotfile sharing, backups, or debugging output may reveal it. This is a weaker issue than direct exfiltration, but persistent credentials do raise risk if the endpoint or local environment is later compromised.
Sign up at https://api.letmego.top and copy your token, then:
# macOS / Linux — add to ~/.zshrc or ~/.bashrc to persist
export LETMEGO_API_KEY=your_token
# Windows PowerShell (permanent)
The README says the skill 'activates automatically' for broad requests like creating, generating, drawing, or editing images, but it does not define tight trigger boundaries or require explicit user confirmation. In agent environments, overly broad activation can cause unintended invocation, accidental transmission of prompts or image references to a third-party service, and surprise costs or privacy leaks. The skill context makes this more dangerous because image requests are common and often include sensitive attached files.
Referencing npx skillpm again in the supported-clients section reinforces the same unsafe installation pattern without version pinning. Repetition in documentation increases the chance that users adopt the insecure install flow, so this is not merely informational. While not an exploit by itself, it materially contributes to supply-chain exposure.
The skill’s activation criteria are broad enough to match many ordinary image-related requests, increasing the chance the agent invokes this skill when a narrower or safer capability would be more appropriate. Because the skill performs external API calls and may process local image references, overbroad triggering can cause unintended data transfer, unnecessary token use, and user confusion about where content is being sent.
The trigger list contains many ambiguous everyday phrases in both English and Chinese that can match casual requests lacking clear consent to use an external image-generation service. In context, this is more dangerous because the skill is configured to call a third-party endpoint and can accept local file paths for image-to-image operations, so accidental activation could expose user data or consume paid API quota.
When --ref is provided, the script reads the local file and uploads its contents to a remote third-party API without any explicit warning or confirmation at the point of use. This can cause unintentional disclosure of sensitive local images or embedded metadata, especially in an agent context where users may not realize a local file is being transmitted off-device.
The error message tells users to 'Get your 令牌' and uses 'your_令牌', forcing mixed-language output without user opt-in. This can violate language/locale expectations because the script does not offer an English-only or selectable alternative.
Detected: suspicious.env_credential_access