Back to skill

Security audit

Baoyu Comic

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it claims, but it includes fallback paths that can download or execute untrusted local tooling during normal use.

Install only if you are comfortable with a comic skill that writes project files, may save reusable preferences under your home directory, sends prompts and reference images to image-generation backends, and can invoke local tooling. Prefer installing trusted Bun yourself, avoid the `npx -y bun` fallback, do not set BAOYU_CODEX_IMAGEGEN_BIN unless you trust the exact executable, and review presets before using defaults that may include third-party characters.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:149
Finding

Unpinned Bun Package Download and Execution Through npx

Content
View full analysis
.ts` 3. Replace all `{baseDir}` in this document with the actual path 4. Resolve `${BUN_X}` runtime: if `bun` installed → `bun`; if `npx` available → `npx -y bun`; else suggest installing bun ``` From `references/codex-imagegen.md:41`: ```markdown If `bun` is missing, `npx -y bun /main.ts ...` works as a fallback. ``` ### Technical Analysis The Skill instructs the Agent to use `npx -y bun` when a locally installed Bun executable is unavailable. This command retrieves and executes the version of the `bun` package currently resolved by the configured npm registry. No package version, lockfile, integrity hash, registry restriction, or provenance verification is specified. The `-y` option suppresses the normal installation confirmation, so remotely retrieved package code may execute automatically during ordinary image-generation or PDF-merging operations. The effective code can change after this Skill has been reviewed. This creates a supply-chain boundary in which the safety of local execution depends on the npm registry, package ownership, registry configuration, DNS and network integrity, and the absence of dependency substitution or account compromise. ### Attack Path 1. The user requests comic generation or PDF merging. 2. The runtime does not have a trusted `bun` executable installed. 3. The Agent follows the documented fallback and invokes `npx -y bun`. 4. npm resolves the unpinned package using the runtime's configured registry. 5. A compromised, substituted, or unexpectedly modified package version is downloaded. 6. Package-controlled code execut ...[truncated 1059 chars]
Remediation
View remediation

T07 · Tool Hijacking and Spoofing

Warning
Location
references/codex-imagegen.md:24
Finding

Environment Variable Can Redirect Image Generation to an Arbitrary Local Executable

Content
View full analysis
`) or `.sh`/binary (spawn directly). 2. **Search the plugin root**: walk up from this skill's directory looking for `packages/baoyu-codex-imagegen/src/main.ts`. If found, that is the wrapper. Spawn it with `bun`. 3. **Last resort**: tell the user that `codex-imagegen` is not available in this runtime and ask whether to install the `baoyu-skills` plugin (or set `BAOYU_CODEX_IMAGEGEN_BIN`) or pick another backend. ``` ### Technical Analysis The wrapper-discovery procedure treats the path in `BAOYU_CODEX_IMAGEGEN_BIN` as trusted whenever it points to an existing file. The documented validation is limited to file existence. It does not require: - A trusted installation directory. - Canonical-path validation. - Trusted ownership or restrictive file permissions. - A cryptographic signature or known digest. - User confirmation of the resolved executable. - Rejection of writable scripts or symbolic-link redirection. The file may be a TypeScript file, shell script, or native binary. Shell scripts and binaries are executed directly, while TypeScript files are passed to Bun. Consequently, a process launcher, compromised environment configuration, or another actor able to influence inherited environment variables can replace the expected wrapper with attacker-controlled local code. ### Attack Path 1. An attacker or compromised launcher sets `BAOYU_CODEX_IMAGEGEN_BIN` to an attacker-controlled script or bi ...[truncated 1412 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Rogue AgentSelf-Modification, Session Persistence
Findings (38)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a comic creation skill focused on generating original educational comics with layout and image-generation capabilities. The supplied code does none of that. It only parses CLI arguments, locates pre-existing comic page image files in a directory, orders them by filename, embeds them into a PDF, and writes the resulting PDF to disk. While this may be part of a comic production pipeline, the code chunk itself is specifically a merge-to-PDF tool, which is a materially different primary purpose from the declared comic creator functionality.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 250)May include surrounding context.

md
at the top. If the backend is a repo skill (e.g., `baoyu-image-gen`), read its `SKILL.md` and use its documented interface rather than its scripts.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · references/workflow.md (reported line 382)May include surrounding context.

md
**Purpose**: User reviews and confirms prompts before image generation.

**Display prompt summary table**:

| Page | Title | Key Elements |
|------|-------|--------------|

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 120)May include surrounding context.

md
| Option | Description |
|--------|-------------|
| `--storyboard-only` | Generate storyboard only, skip prompts and images |
| `--prompts-only` | Generate storyboard + prompts, skip images |
| `--images-only` | Generate images from existing prompts directory |
| `--regenerate N` | Regenerate specific page(s) only (e.g., `3` or `2,5,8`) |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/workflow.md (reported line 241)May include surrounding context.

md
| Option | Description |
|--------|-------------|
| `--storyboard-only` | Generate storyboard only, skip prompts and images |
| `--prompts-only` | Generate storyboard + prompts, skip images |
| `--images-only` | Generate images from existing prompts directory |
| `--regenerate N` | Regenerate specific page(s) only (e.g., `3` or `2,5,8`) |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/workflow.md (reported line 378)May include surrounding context.

md
| Option | Description |
|--------|-------------|
| `--storyboard-only` | Generate storyboard only, skip prompts and images |
| `--prompts-only` | Generate storyboard + prompts, skip images |
| `--images-only` | Generate images from existing prompts directory |
| `--regenerate N` | Regenerate specific page(s) only (e.g., `3` or `2,5,8`) |

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The skill instructs the agent to resolve the runtime using npx -y bun when bun is not installed, which fetches and executes a package at runtime without a pinned version. This creates a supply-chain risk because behavior can change over time or a compromised upstream package/version could execute unexpected code in the agent environment.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 325)May include surrounding context.

md
Text correction policy:

- If dialogue, sound effects, panel labels, or any other rendered text is misspelled, garbled, hard to read, or visually weak, do not patch the bitmap with code.
- For text-correction regenerations, write a new prompt file and a new output path so the flawed candidate is preserved for comparison.
- Post-processing is limited to crop, resize, compression, or format conversion that does not alter text or the main composition.

## Notes

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file defines many natural-language 'Triggers' such as 'technical', 'educational', 'motivation', and 'short insight' without negative examples or boundary rules for when a preset should not activate. Because this is a markdown file and these phrases overlap with common content categories, the activation scope is ambiguous and may lead to incorrect preset selection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Lines L93-L94 require all text to be in Chinese unless the source material is already in another language, which imposes a specific language/locale by default. This is a natural-language policy concern because the file does not provide user opt-in, alternative locale options, or a clear region-specific justification.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The fallback command npx -y bun executes a package manager-resolved runtime without pinning a specific version or integrity, which can lead to non-reproducible behavior and potential supply-chain exposure if a malicious or unexpected package/version is served. In this skill, the command is presented as an execution path for image generation tooling, so an agent following it could fetch and run untrusted code on the host.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/config/first-time-setup.md (reported line 33)May include surrounding context.

md
│
        ▼
┌─────────────────────┐
│ Create EXTEND.md    │
└─────────────────────┘
        │
        ▼

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The setup explicitly offers writing preferences to a user-scoped path under ~/.baoyu-skills/, creating persistent cross-project state beyond the immediate comic-generation task. While preferences storage is a legitimate feature, storing them at user scope can surprise users, broaden the blast radius of any tampering, and create privacy or integrity issues if later runs implicitly trust that file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file distinguishes 'Project' versus 'User' save locations, but the question text does not clearly warn that the User option stores preferences globally across all projects. That weak disclosure can mislead users into granting broader persistence than intended, which is especially risky in an agent context where stored settings may affect future behavior automatically.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The preset hard-codes Chinese as the default panel language unless the source language matches something else, which can override or disregard the user's preferred language. In a content-generation skill, this creates a policy/compliance issue around user choice and can lead to unexpected outputs, though it is not a direct code-execution or data-security risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The prompt template reinforces the same issue by explicitly requiring dialogue text in Chinese, increasing the chance that downstream generations ignore user language preference. In this comic-creation context, the main danger is systematic policy violation or poor user experience rather than traditional security compromise.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The preset hard-codes Doraemon characters as the default, which conflicts with the skill’s stated purpose of generating original educational comics and introduces likely unauthorized use of copyrighted characters. Because this behavior is automatic unless the user overrides it, the skill can systematically produce infringing derivative content without informed user opt-in, increasing legal and policy risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The preset forces a specific set of characters and cultural/language context by default without explicit user consent, reducing user control and causing outputs that may unexpectedly include copyrighted or unsuitable defaults. In this skill’s context, that is more dangerous because the skill markets itself broadly as a comic creator, so users may reasonably expect neutral, original defaults rather than franchise-bound behavior.

Content

No source excerpt is available for this finding.

YARA rule 'network_reconnaissance': Network reconnaissance and scanning patterns [hacktools]

Medium
Category
YARA Match
Confidence
65% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · references/presets/wuxia.md (reported line 36)May include surrounding context.

md
Type | Visual Treatment |
|-------------|-----------------|
| Internal qi | Glowing aura around character |
| External qi | Visible energy projection |
| Qi clash | Radiating impact waves |
| Qi absorption | Flowing particles toward character |
| Hidden power | Subtle glow in eyes/fists |

### Energy Colors

| Qi Type | Color |
|---------|-------|
| Righteous | Blue (#4299E1), Gold (#FFD700) |
| Fierce | Red (#DC2626), Orange (#EA580C) |
| Evil | Purple (#7C3AED), Green (#16A34A) |
| Pure | White, Silver |
| Ancient | Gold with particles |

### Combat Visual Language

**Impact moments** must include:

1. Speed lines radiating from impact point
2. Flying debris (stone, wood, cloth)
3. Shockwave rings
4. Dust/energy clouds
5. Hair and clothing blown back

### Movement Depiction

| Speed Level | Visual Treatment |
|-------------|-----------------|
| Normal | Standard pose |
| Fast | Motion blur, speed lines |
| Lightning | Afterimages, multiple positions |
| Teleport | Fade effect, parti

YARA rule 'network_reconnaissance': Network reconnaissance and scanning patterns [hacktools]

Medium
Category
YARA Match
Confidence
65% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · references/tones/action.md (reported line 72)May include surrounding context.

md
Type | Visual Treatment |
|-------------|-----------------|
| Internal qi | Glowing aura around character |
| External qi | Visible energy projection |
| Qi clash | Radiating impact waves |
| Qi absorption | Flowing particles toward character |
| Hidden power | Subtle glow in eyes/fists |

### Energy Colors

| Qi Type | Color |
|---------|-------|
| Righteous | Blue (#4299E1), Gold (#FFD700) |
| Fierce | Red (#DC2626), Orange (#EA580C) |
| Evil | Purple (#7C3AED), Green (#16A34A) |
| Pure | White, Silver |
| Ancient | Gold with particles |

### Combat Visual Language

**Impact moments** must include:

1. Speed lines radiating from impact point
2. Flying debris (stone, wood, cloth)
3. Shockwave rings
4. Dust/energy clouds
5. Hair and clothing blown back

### Movement Depiction

| Speed Level | Visual Treatment |
|-------------|-----------------|
| Normal | Standard pose |
| Fast | Motion blur, speed lines |
| Lightning | Afterimages, multiple positions |
| Teleport | Fade effect, parti

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Line L003 mixes the title with Chinese text ("动作基调") while the rest of the file is in English, indicating a fixed language/localization choice in the skill content. The file does not offer any user opt-in or alternative locale guidance, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The manifest presents this skill as a knowledge comic creator, but the workflow directs Bash/PowerShell usage and later invokes external tooling for filesystem checks, image compression, and PDF merging. While some local file handling is expected, explicit subprocess-style command execution and script invocation are broader operational capabilities not stated in the manifest.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

These lines prescribe fixed character names in Chinese/Japanese script and state they must be used unless explicitly overridden. That imposes a specific locale/language choice inside the generated content, even though the workflow elsewhere says outputs should be written in the user's preferred language.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest describes comic creation with batch-capable image generation, but this workflow explicitly tells the agent to read another image generation skill's SKILL.md, determine feature support, and invoke that external skill. Cross-skill capability inspection and orchestration is a broader system-integration behavior not justified by the manifest alone.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

Line L03 begins with Japanese text as the primary label for the style without offering a language or locale choice. This can conflict with a language/locale policy requiring user opt-in or documented justification for non-default language usage.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.