T07 · Tool Hijacking and Spoofing
- Location
SKILL.md:41- Finding
Execution Is Delegated to an Unbundled Absolute-Path Script
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill’s stated image-generation purpose is clear, but it tells users to run an unbundled absolute-path script and pass an API key through command-line inputs.
Review this before installing. Use it only if you can verify or bundle the referenced Python script, and avoid putting real API keys in commands or example files; prefer a secret store, protected environment variable, or stdin-style secret input. Restrict the endpoint and output directory to locations you trust.
SKILL.md:41Execution Is Delegated to an Unbundled Absolute-Path Script
SKILL.md:176API Key Is Exposed Through Command-Line Arguments
The documentation explicitly instructs users to pass the API key via a command-line argument, which can expose the secret through shell history, process listings, terminal logging, CI job output, and orchestration traces. In this skill's context, the risk is real because the skill requires a live provider key and is designed for routine manual or workflow invocation, making accidental credential disclosure more likely.
This JSON file contains natural-language content entirely in Chinese in the prompt field, which imposes a specific language/locale choice without indicating that the user selected it or that the skill is region-specific. The policy requires either user choice/opt-in or a clear documented justification for locale constraints.
The natural-language instructions and parameter explanations are presented entirely in Chinese, with no indication that users may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a reportable natural-language policy issue.
No suspicious patterns detected.