Back to skill

Security audit

img2-generate-only

Security checks for vulnerabilities and agentic risk

Overview

The skill’s stated image-generation purpose is clear, but it tells users to run an unbundled absolute-path script and pass an API key through command-line inputs.

Review this before installing. Use it only if you can verify or bundle the referenced Python script, and avoid putting real API keys in commands or example files; prefer a secret store, protected environment variable, or stdin-style secret input. Restrict the endpoint and output directory to locations you trust.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T07 · Tool Hijacking and Spoofing

Error
Location
SKILL.md:41
Finding

Execution Is Delegated to an Unbundled Absolute-Path Script

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:176
Finding

API Key Is Exposed Through Command-Line Arguments

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation explicitly instructs users to pass the API key via a command-line argument, which can expose the secret through shell history, process listings, terminal logging, CI job output, and orchestration traces. In this skill's context, the risk is real because the skill requires a live provider key and is designed for routine manual or workflow invocation, making accidental credential disclosure more likely.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JSON file contains natural-language content entirely in Chinese in the prompt field, which imposes a specific language/locale choice without indicating that the user selected it or that the skill is region-specific. The policy requires either user choice/opt-in or a clear documented justification for locale constraints.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language instructions and parameter explanations are presented entirely in Chinese, with no indication that users may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a reportable natural-language policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.