Back to skill

Security audit

Picnow — Image Generation

Security checks for vulnerabilities and agentic risk

Overview

Picnow is a coherent image-generation skill, but its reference-image path can upload any readable local file to a third-party API without validation or confirmation.

Review this skill before installing. Use it only with prompts and images you are willing to send to api.letmego.top, avoid passing arbitrary local paths to --ref, and prefer pinned install sources plus a secret manager or temporary environment variable for the API key.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate.js:72
Finding

Unrestricted Local File Upload Through the Reference Image Parameter

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:12
Finding

Unpinned npx Installers Permit Mutable Supply-Chain Code Execution

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (12)

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'network' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

The README instructs users to run npx skillpm install @jxai/picnow without pinning a specific version. This creates a supply-chain risk because future package updates or a compromised publisher account could cause users to fetch and execute different code than expected. In the context of an agent skill, install commands are especially sensitive because they often run with the user's local privileges.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
86% confidence
Finding

The command npx skills install jeekchen/picnow-skill references an unpinned installer and an unpinned repository target. This means users may retrieve whatever code is current at execution time, increasing exposure to repository compromise, malicious force-pushes, or unexpected breaking changes. Because this is an install path for executable skill content, the resulting risk is a real supply-chain issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explains how to obtain and set an API token but does not clearly warn users that prompts and reference images are sent to api.letmego.top, an external service. This omission can lead users to unknowingly upload sensitive business materials, personal photos, or confidential prompts. In an image-editing skill, reference images are especially privacy-sensitive, so the missing disclosure is a meaningful security and privacy issue.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The README recommends persisting LETMEGO_API_KEY in shell startup files or permanent user environment settings. This increases the lifetime and exposure surface of the credential: other local processes, accidental dotfile sharing, backups, or debugging output may reveal it. This is a weaker issue than direct exfiltration, but persistent credentials do raise risk if the endpoint or local environment is later compromised.

Content

Scanner excerpt · README.md (reported line 36)May include surrounding context.

Sign up at https://api.letmego.top and copy your token, then:

bash
# macOS / Linux — add to ~/.zshrc or ~/.bashrc to persist
export LETMEGO_API_KEY=your_token

# Windows PowerShell (permanent)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README says the skill 'activates automatically' for broad requests like creating, generating, drawing, or editing images, but it does not define tight trigger boundaries or require explicit user confirmation. In agent environments, overly broad activation can cause unintended invocation, accidental transmission of prompts or image references to a third-party service, and surprise costs or privacy leaks. The skill context makes this more dangerous because image requests are common and often include sensitive attached files.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
83% confidence
Finding

Referencing npx skillpm again in the supported-clients section reinforces the same unsafe installation pattern without version pinning. Repetition in documentation increases the chance that users adopt the insecure install flow, so this is not merely informational. While not an exploit by itself, it materially contributes to supply-chain exposure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill’s activation criteria are broad enough to match many ordinary image-related requests, increasing the chance the agent invokes this skill when a narrower or safer capability would be more appropriate. Because the skill performs external API calls and may process local image references, overbroad triggering can cause unintended data transfer, unnecessary token use, and user confusion about where content is being sent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger list contains many ambiguous everyday phrases in both English and Chinese that can match casual requests lacking clear consent to use an external image-generation service. In context, this is more dangerous because the skill is configured to call a third-party endpoint and can accept local file paths for image-to-image operations, so accidental activation could expose user data or consume paid API quota.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

When --ref is provided, the script reads the local file and uploads its contents to a remote third-party API without any explicit warning or confirmation at the point of use. This can cause unintentional disclosure of sensitive local images or embedded metadata, especially in an agent context where users may not realize a local file is being transmitted off-device.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The error message tells users to 'Get your 令牌' and uses 'your_令牌', forcing mixed-language output without user opt-in. This can violate language/locale expectations because the script does not offer an English-only or selectable alternative.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/generate.js:201