Back to skill

Security audit

Baoyu Image Gen

Security checks for vulnerabilities and agentic risk

Overview

This image-generation skill is mostly coherent, but it deserves Review because one optional path can run a full-access Codex subprocess and project-local config can redirect sensitive execution settings.

Install only if you are comfortable with this skill sending prompts and reference images to chosen image providers. Avoid the `codex-cli` provider unless you trust the prompt source and accept full local Codex execution authority. Do not run it from untrusted repositories with `.baoyu-skills/.env` files, avoid storing provider keys in project-local config, and prefer a pinned trusted Bun install over the `npx -y bun` fallback.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T07 · Tool Hijacking and Spoofing

Error
Location
scripts/main.ts:363
Finding

Project-Local Environment Configuration Can Redirect Credentials or Replace the Codex Wrapper

Content
View full analysis
> { try { const content = await readFile(p, "utf8"); const env: Record = {}; for (const line of content.split("\n")) { const trimmed = line.trim(); if (!trimmed || trimmed.startsWith("#")) continue; const idx = trimmed.indexOf("="); if (idx === -1) continue; const key = trimmed.slice(0, idx).trim(); let val = trimmed.slice(idx + 1).trim(); if ((val.startsWith('"') && val.endsWith('"')) || (val.startsWith("'") && val.endsWith("'"))) { val = val.slice(1, -1); } env[key] = val; } return env; } catch { return {}; } } async function loadEnv(): Promise { const home = homedir(); const cwd = process.cwd(); const homeEnv = await loadEnvFile( path.join(home, ".baoyu-skills", ".env") ); const cwdEnv = await loadEnvFile( path.join(cwd, ".baoyu-skills", ".env") ); for (const [k, v] of Object.entries(homeEnv)) { if (!process.env[k]) process.env[k] = v; } for (const [k, v] of Object.entries(cwdEnv)) { if (!process.env[k]) process.env[k] = v; } } ``` The loader is invoked before provider selection and generation: ```ts await loadEnv(); ``` Provider base URLs and credentials are then taken from the resulting process environment: ```ts export async function generateImage( prompt: string, model: string, args: CliArgs ): Promise { const baseURL = process.env.OPENAI_BASE_URL || "https://api.openai.com/v1"; const apiKey = process.env.OPENAI_API_KEY; if (!apiKey) { throw ...[truncated 4207 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/codex-imagegen/spawn.ts:14
Finding

Untrusted Prompt Content Is Passed to a Codex Agent with Danger-Full-Access Permissions

Content
View full analysis
0 ? `\nREFERENCE IMAGES (attached above): ${opts.refImages.length} image(s) provided for style/composition guidance.\n` : ""; return `You have an internal tool called image_gen for image generation. Use it. TASK: Generate an image with the spec below, then save to disk. PROMPT: ${prompt} ASPECT RATIO: ${opts.aspect} OUTPUT PATH: ${opts.outputPath} ${refHint} STEPS: 1. Call image_gen with the prompt and aspect ratio above${opts.refImages.length > 0 ? " (using the attached reference images for guidance)" : ""}. 2. Move or copy the resulting image from Codex default location ($CODEX_HOME/generated_images/...) to: ${opts.outputPath} 3. Verify with: ls -la ${opts.outputPath} 4. Reply with ONLY this JSON line (no markdown fences, no other text): {"status":"ok","path":"${opts.outputPath}","bytes":} HARD CONSTRAINTS: - Do NOT use curl, wget, Python, or any external API. - Do NOT use bash to fabricate an image; only image_gen produces real pixels. - Use ONLY the image_gen internal tool.`; } ``` The instruction is supplied to a Codex process configured with unrestricted sandbox permissions: ```ts export async function runCodexExec( input: SpawnInput ): Promise { const start = Date.now(); const logDir = await mkdtemp( path.join(tmpdir(), "codex-imggen-") ); const rawLogPath = path.join(logDir, "stream.jsonl"); const args = [ "exec", "--json", "--sandbox", "danger-full-access", "--skip-git-repo-check", ]; for (const img of input.refImages ?? []) { args.push("--image", img); } args.push("-"); ...[truncated 2793 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:31
Finding

Unpinned npx Fallback Retrieves and Executes a Mutable Registry Package

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
Findings (56)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

If the underlying skill actually requests danger-full-access, executes codex, and writes logs while presenting itself merely as an image-generation API wrapper, the mismatch hides materially broader execution capability from users. Concealing or under-disclosing privileged code-execution behavior is dangerous because operators may authorize the skill for simple media tasks while unintentionally granting generic execution paths.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

If the underlying skill actually requests danger-full-access, executes codex, and writes logs while presenting itself merely as an image-generation API wrapper, the mismatch hides materially broader execution capability from users. Concealing or under-disclosing privileged code-execution behavior is dangerous because operators may authorize the skill for simple media tasks while unintentionally granting generic execution paths.

Content

No source excerpt is available for this finding.

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 82)May include surrounding context.

md
${BUN_X} {baseDir}/scripts/main.ts --prompt "A cat" --image out.png --provider dashscope --model qwen-image-2.0-pro

# OpenAI GPT Image 2
${BUN_X} {baseDir}/scripts/main.ts --prompt "A cat" --image out.png --provider openai --model gpt-image-2

# Codex CLI (uses logged-in Codex subscription — no OPENAI_API_KEY required; requires `codex` on PATH)
${BUN_X} {baseDir}/scripts/main.ts --prompt "A cat" --image out.png --provider codex-cli --ar 16:9

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

This example explicitly routes prompts to an external OpenAI model, which means user-supplied text and possibly related content are transmitted off-box to a third-party provider. In this skill's context, external provider use is expected, but it is still security-relevant because users may unknowingly send sensitive material without clear disclosure or approval boundaries.

Content

Scanner excerpt · references/usage-examples.md (reported line 28)May include surrounding context.

bash
# OpenAI
${BUN_X} {baseDir}/scripts/main.ts --prompt "A cat" --image out.png --provider openai --model gpt-image-2

# Azure OpenAI (model = deployment name)
${BUN_X} {baseDir}/scripts/main.ts --prompt "A cat" --image out.png --provider azure --model gpt-image-2

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

This example sends content to Azure OpenAI, an external hosted service, so prompts and related data may be disclosed beyond the local environment. Although Azure may be enterprise-approved in some deployments, the documentation does not state trust assumptions, tenancy boundaries, or the need to confirm that external transmission is acceptable.

Content

Scanner excerpt · references/usage-examples.md (reported line 31)May include surrounding context.

md
${BUN_X} {baseDir}/scripts/main.ts --prompt "A cat" --image out.png --provider openai --model gpt-image-2

# Azure OpenAI (model = deployment name)
${BUN_X} {baseDir}/scripts/main.ts --prompt "A cat" --image out.png --provider azure --model gpt-image-2

# OpenAI GPT Image 2 custom 4K size
${BUN_X} {baseDir}/scripts/main.ts --prompt "A cinematic landscape" --image out.png --provider openai --model gpt-image-2 --size 3840x2160

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

This example directs a prompt to an external OpenAI image model with a custom size, reinforcing that generated content requests are handled by a third party. The main risk is not the image size itself, but normalized examples that encourage external transmission without privacy caveats in a skill likely to be used with user-supplied creative or proprietary prompts.

Content

Scanner excerpt · references/usage-examples.md (reported line 34)May include surrounding context.

md
${BUN_X} {baseDir}/scripts/main.ts --prompt "A cat" --image out.png --provider azure --model gpt-image-2

# OpenAI GPT Image 2 custom 4K size
${BUN_X} {baseDir}/scripts/main.ts --prompt "A cinematic landscape" --image out.png --provider openai --model gpt-image-2 --size 3840x2160

# Google with explicit model
${BUN_X} {baseDir}/scripts/main.ts --prompt "Make blue" --image out.png --provider google --model gemini-3-pro-image --ref source.png

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
94% confidence
Finding

This example sends both a prompt and a reference image to Google's external model, which materially raises the risk because uploaded images can contain sensitive visual content or embedded metadata. In an image-generation skill, reference-image workflows are especially dangerous without explicit warnings because users may assume examples are purely local operations.

Content

Scanner excerpt · references/usage-examples.md (reported line 37)May include surrounding context.

md
${BUN_X} {baseDir}/scripts/main.ts --prompt "A cinematic landscape" --image out.png --provider openai --model gpt-image-2 --size 3840x2160

# Google with explicit model
${BUN_X} {baseDir}/scripts/main.ts --prompt "Make blue" --image out.png --provider google --model gemini-3-pro-image --ref source.png

# OpenRouter (recommended default)
${BUN_X} {baseDir}/scripts/main.ts --prompt "A cat" --image out.png --provider openrouter

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

This example routes prompts to Z.AI's external model, which has the same core risk as other provider-selection examples: user content leaves the local environment for third-party processing. The skill context makes this expected behavior, but still dangerous when documentation does not clearly distinguish local file handling from remote model invocation.

Content

Scanner excerpt · references/usage-examples.md (reported line 64)May include surrounding context.

md
${BUN_X} {baseDir}/scripts/main.ts --prompt "一张带清晰中文标题的科技海报" --image out.png --provider zai

# Z.AI with custom size
${BUN_X} {baseDir}/scripts/main.ts --prompt "A science illustration with labels" --image out.png --provider zai --model glm-image --size 1472x1088

# MiniMax
${BUN_X} {baseDir}/scripts/main.ts --prompt "A fashion editorial portrait" --image out.jpg --provider minimax

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill invokes an external codex CLI with --sandbox danger-full-access, giving the subprocess unrestricted filesystem access while also passing it user-controlled instructions and optional image paths. In an image-generation skill, this is unnecessarily powerful and creates a strong path for prompt-driven local file access, data exfiltration, or unintended system modification if the CLI interprets the instruction as an agentic task rather than pure image generation.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/main.ts (reported line 168)May include surrounding context.

ts
BAOYU_CODEX_IMAGEGEN_RETRIES  Codex-side retry attempts on retryable errors (default: 2)
  BAOYU_CODEX_IMAGEGEN_LOG_FILE  Append JSONL diagnostic log for codex-cli provider

Env file load order: CLI args > EXTEND.md > process.env > <cwd>/.baoyu-skills/.env > ~/.baoyu-skills/.env`);
}

export function parseArgs(argv: string[]): CliArgs {

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/main.ts (reported line 828)May include surrounding context.

ts
BAOYU_CODEX_IMAGEGEN_RETRIES  Codex-side retry attempts on retryable errors (default: 2)
  BAOYU_CODEX_IMAGEGEN_LOG_FILE  Append JSONL diagnostic log for codex-cli provider

Env file load order: CLI args > EXTEND.md > process.env > <cwd>/.baoyu-skills/.env > ~/.baoyu-skills/.env`);
}

export function parseArgs(argv: string[]): CliArgs {

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/main.ts (reported line 389)May include surrounding context.

ts
const home = homedir();
  const cwd = process.cwd();

  const homeEnv = await loadEnvFile(path.join(home, ".baoyu-skills", ".env"));
  const cwdEnv = await loadEnvFile(path.join(cwd, ".baoyu-skills", ".env"));

  for (const [k, v] of Object.entries(homeEnv)) {

Credential Access

High
Category
Privilege Escalation
Confidence
73% confidence
Finding

The skill loads secrets from <cwd>/.baoyu-skills/.env, meaning a malicious project directory can influence credential-bearing environment variables when the user runs the tool inside that workspace. This can silently redirect provider selection, endpoints, or local codex-cli behavior using attacker-supplied configuration, which is a meaningful trust-boundary issue even if it does not directly exfiltrate keys here.

Content

Scanner excerpt · scripts/main.ts (reported line 390)May include surrounding context.

ts
const cwd = process.cwd();

  const homeEnv = await loadEnvFile(path.join(home, ".baoyu-skills", ".env"));
  const cwdEnv = await loadEnvFile(path.join(cwd, ".baoyu-skills", ".env"));

  for (const [k, v] of Object.entries(homeEnv)) {
    if (!process.env[k]) process.env[k] = v;

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/main.ts (reported line 905)May include surrounding context.

ts
}

export function addAspectRatioToPrompt(prompt: string, ar: string | null): string {
  if (!ar) return prompt;
  return `${prompt} Aspect ratio: ${ar}.`;
}

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/providers/google.ts (reported line 183)May include surrounding context.

ts
}

export function addAspectRatioToPrompt(prompt: string, ar: string | null): string {
  if (!ar) return prompt;
  return `${prompt} Aspect ratio: ${ar}.`;
}

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/providers/openrouter.ts (reported line 218)May include surrounding context.

ts
}

export function addAspectRatioToPrompt(prompt: string, ar: string | null): string {
  if (!ar) return prompt;
  return `${prompt} Aspect ratio: ${ar}.`;
}

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares no explicit tool scope or allowed-tools despite instructing use of shell execution, environment-variable access, and networked provider/API interactions. This weakens least-privilege boundaries and can let a runtime grant broader capabilities than users expect, which is risky for a skill that also invokes external binaries and reads credentials from the environment.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description says to use the skill when the user asks to "generate, create, or draw images." Terms like "create" and "draw images" are broad enough to collide with ordinary conversational requests, and the file does not provide negative examples or tighter activation constraints in the invocation description.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Using npx -y bun without pinning a version creates a supply-chain risk because the runtime may fetch and execute whatever package version is current at execution time. If the package or resolution path is compromised, the skill could run attacker-controlled code before any image-generation logic begins.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/config/first-time-setup.md (reported line 27)May include surrounding context.

md
│                            │
        ▼                            ▼
┌─────────────────────┐    ┌──────────────────────┐
│ Create EXTEND.md    │    │ Update EXTEND.md     │
└─────────────────────┘    └──────────────────────┘
        │                            │
        ▼                            ▼

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The documentation recommends using npx -y bun as a fallback, which fetches and executes a package at runtime without a pinned version. That creates a supply-chain risk: users may install an unexpected or compromised release, and because this skill later uses that runtime to execute the image-generation wrapper, the fetched tool would run with the user's privileges.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation states that http(s):// reference image URLs are forwarded as-is, which can cause user-supplied external URLs to be transmitted to the DashScope provider without an explicit privacy/security warning. In an image-generation skill, reference images often contain sensitive or proprietary content, so silent external forwarding increases the risk of unintended data disclosure and may also enable provider-side fetching of attacker-controlled URLs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation explicitly states that local --ref files are sent to MiniMax as Data URLs, but it does not clearly warn users that local image contents will be transmitted to a third-party provider. This can lead to unintended disclosure of sensitive local images, especially because this skill is specifically designed to upload user-supplied reference images to external image-generation APIs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The examples instruct users to send prompts and reference images to many third-party providers, but they do not warn that user content, images, and metadata will leave the local environment and be processed by external services. In a skill specifically designed for image generation across multiple vendors, this omission increases the risk of accidental disclosure of sensitive or proprietary data.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access, suspicious.exposed_secret_literal

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/codex-imagegen/spawn.ts:35

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/providers/codex-cli.ts:91

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/providers/google.ts:99

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/providers/agnes.ts:15

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/providers/azure.ts:36

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/providers/dashscope.ts:113

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/providers/google.ts:19

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/providers/jimeng.ts:7

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/providers/minimax.ts:39

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/providers/openai.ts:6

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/providers/openrouter.ts:44

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/providers/replicate.ts:38

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/providers/seedream.ts:49

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/providers/zai.ts:43

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/providers/jimeng.ts:268