Back to skill

Security audit

Baoyu Imagine

Security checks for vulnerabilities and agentic risk

Overview

This is a real image-generation skill, but it needs Review because project-local settings can redirect API-keyed requests and its runtime fallback downloads unpinned code.

Review carefully before installing. Use it only in directories you trust, check any project `.baoyu-skills/.env` before running, avoid combining global API keys with project-defined `*_BASE_URL` settings, and prefer a preinstalled trusted Bun binary instead of the `npx` fallback. Treat prompts, prompt files, reference images, and remote reference URLs as data that may be sent to the selected provider.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/main.ts:343
Finding

Project-Level Endpoint Override Can Redirect Home-Scoped API Credentials

Content
View full analysis
> { try { const content = await readFile(p, "utf8"); const env: Record = {}; for (const line of content.split("\n")) { const trimmed = line.trim(); if (!trimmed || trimmed.startsWith("#")) continue; const idx = trimmed.indexOf("="); if (idx === -1) continue; const key = trimmed.slice(0, idx).trim(); let val = trimmed.slice(idx + 1).trim(); if ((val.startsWith('"') && val.endsWith('"')) || (val.startsWith("'") && val.endsWith("'"))) { val = val.slice(1, -1); } env[key] = val; } return env; } catch { return {}; } } async function loadEnv(): Promise { const home = homedir(); const cwd = process.cwd(); const homeEnv = await loadEnvFile(path.join(home, ".baoyu-skills", ".env")); const cwdEnv = await loadEnvFile(path.join(cwd, ".baoyu-skills", ".env")); for (const [k, v] of Object.entries(homeEnv)) { if (!process.env[k]) process.env[k] = v; } for (const [k, v] of Object.entries(cwdEnv)) { if (!process.env[k]) process.env[k] = v; } } ``` The OpenAI provider then combines an unrestricted endpoint value with the available credential: ```ts export async function generateImage( prompt: string, model: string, args: CliArgs ): Promise { const baseURL = process.env.OPENAI_BASE_URL || "https://api.openai.com/v1"; const apiKey = process.env.OPENAI_API_KEY; if (!apiKey) { throw new Error( ...[truncated 5320 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:28
Finding

Unpinned Runtime Package Is Downloaded and Executed Through npx

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Rogue AgentSelf-Modification, Session Persistence
Findings (45)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 235)May include surrounding context.

md
outline.md` + `prompts/` (e.g. from `baoyu-article-illustrator`) | Batch — use `scripts/build-batch.ts` to assemble the payload | The outline + prompt files alr

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 82)May include surrounding context.

bash
# OpenAI
${BUN_X} {baseDir}/scripts/main.ts --prompt "A cat" --image out.png --provider openai --model gpt-image-2

# Azure OpenAI (model = deployment name)
${BUN_X} {baseDir}/scripts/main.ts --prompt "A cat" --image out.png --provider azure --model gpt-image-2

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · references/usage-examples.md (reported line 28)May include surrounding context.

bash
# OpenAI
${BUN_X} {baseDir}/scripts/main.ts --prompt "A cat" --image out.png --provider openai --model gpt-image-2

# Azure OpenAI (model = deployment name)
${BUN_X} {baseDir}/scripts/main.ts --prompt "A cat" --image out.png --provider azure --model gpt-image-2

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · references/usage-examples.md (reported line 31)May include surrounding context.

md
${BUN_X} {baseDir}/scripts/main.ts --prompt "A cat" --image out.png --provider openai --model gpt-image-2

# Azure OpenAI (model = deployment name)
${BUN_X} {baseDir}/scripts/main.ts --prompt "A cat" --image out.png --provider azure --model gpt-image-2

# OpenAI GPT Image 2 custom 4K size
${BUN_X} {baseDir}/scripts/main.ts --prompt "A cinematic landscape" --image out.png --provider openai --model gpt-image-2 --size 3840x2160

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · references/usage-examples.md (reported line 34)May include surrounding context.

md
${BUN_X} {baseDir}/scripts/main.ts --prompt "A cat" --image out.png --provider azure --model gpt-image-2

# OpenAI GPT Image 2 custom 4K size
${BUN_X} {baseDir}/scripts/main.ts --prompt "A cinematic landscape" --image out.png --provider openai --model gpt-image-2 --size 3840x2160

# Google with explicit model
${BUN_X} {baseDir}/scripts/main.ts --prompt "Make blue" --image out.png --provider google --model gemini-3-pro-image-preview --ref source.png

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · references/usage-examples.md (reported line 37)May include surrounding context.

md
${BUN_X} {baseDir}/scripts/main.ts --prompt "A cinematic landscape" --image out.png --provider openai --model gpt-image-2 --size 3840x2160

# Google with explicit model
${BUN_X} {baseDir}/scripts/main.ts --prompt "Make blue" --image out.png --provider google --model gemini-3-pro-image-preview --ref source.png

# OpenRouter (recommended default)
${BUN_X} {baseDir}/scripts/main.ts --prompt "A cat" --image out.png --provider openrouter

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · references/usage-examples.md (reported line 64)May include surrounding context.

md
${BUN_X} {baseDir}/scripts/main.ts --prompt "一张带清晰中文标题的科技海报" --image out.png --provider zai

# Z.AI with custom size
${BUN_X} {baseDir}/scripts/main.ts --prompt "A science illustration with labels" --image out.png --provider zai --model glm-image --size 1472x1088

# MiniMax
${BUN_X} {baseDir}/scripts/main.ts --prompt "A fashion editorial portrait" --image out.jpg --provider minimax

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/main.ts (reported line 160)May include surrounding context.

ts
BAOYU_IMAGE_GEN_<PROVIDER>_CONCURRENCY  Override provider concurrency
  BAOYU_IMAGE_GEN_<PROVIDER>_START_INTERVAL_MS  Override provider start gap in ms

Env file load order: CLI args > EXTEND.md > process.env > <cwd>/.baoyu-skills/.env > ~/.baoyu-skills/.env`);
}

export function parseArgs(argv: string[]): CliArgs {

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/main.ts (reported line 775)May include surrounding context.

ts
BAOYU_IMAGE_GEN_<PROVIDER>_CONCURRENCY  Override provider concurrency
  BAOYU_IMAGE_GEN_<PROVIDER>_START_INTERVAL_MS  Override provider start gap in ms

Env file load order: CLI args > EXTEND.md > process.env > <cwd>/.baoyu-skills/.env > ~/.baoyu-skills/.env`);
}

export function parseArgs(argv: string[]): CliArgs {

Credential Access

High
Category
Privilege Escalation
Confidence
91% confidence
Finding

The skill reads API credentials from ~/.baoyu-skills/.env and /.baoyu-skills/.env and injects them into process.env. This is legitimate for provider authentication, but it still expands the skill's access to locally stored secrets and, in the current design, trusts the current working directory, which can be attacker-influenced in shared or untrusted repos.

Content

Scanner excerpt · scripts/main.ts (reported line 371)May include surrounding context.

ts
const home = homedir();
  const cwd = process.cwd();

  const homeEnv = await loadEnvFile(path.join(home, ".baoyu-skills", ".env"));
  const cwdEnv = await loadEnvFile(path.join(cwd, ".baoyu-skills", ".env"));

  for (const [k, v] of Object.entries(homeEnv)) {

Credential Access

High
Category
Privilege Escalation
Confidence
91% confidence
Finding

Loading secrets from the current working directory enables a form of ambient credential ingestion: if a user runs the skill in an untrusted project, that project can supply credentials or alter provider behavior. While not exfiltration by itself, this widens the trusted boundary around sensitive material.

Content

Scanner excerpt · scripts/main.ts (reported line 372)May include surrounding context.

ts
const cwd = process.cwd();

  const homeEnv = await loadEnvFile(path.join(home, ".baoyu-skills", ".env"));
  const cwdEnv = await loadEnvFile(path.join(cwd, ".baoyu-skills", ".env"));

  for (const [k, v] of Object.entries(homeEnv)) {
    if (!process.env[k]) process.env[k] = v;

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/main.ts (reported line 850)May include surrounding context.

ts
}

export function addAspectRatioToPrompt(prompt: string, ar: string | null): string {
  if (!ar) return prompt;
  return `${prompt} Aspect ratio: ${ar}.`;
}

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/providers/google.ts (reported line 181)May include surrounding context.

ts
}

export function addAspectRatioToPrompt(prompt: string, ar: string | null): string {
  if (!ar) return prompt;
  return `${prompt} Aspect ratio: ${ar}.`;
}

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/providers/openrouter.ts (reported line 215)May include surrounding context.

ts
}

export function addAspectRatioToPrompt(prompt: string, ar: string | null): string {
  if (!ar) return prompt;
  return `${prompt} Aspect ratio: ${ar}.`;
}

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill explicitly instructs the runtime to use shell execution, read environment variables for API keys, and access external networked providers, but it declares no tool scope or allowed-tools boundary. In an agent setting, missing capability declarations weakens policy enforcement and increases the chance the skill is invoked with broader-than-necessary privileges or without adequate user visibility.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description says to use the skill when the user asks to "generate, create, or draw images." Terms like "create" and "draw images" are broad everyday phrases and the file does not provide negative examples or tighter activation constraints, increasing the chance of accidental activation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

Using npx -y bun pulls and executes a package at runtime without a pinned version, which creates a supply-chain risk if the resolved package changes or is compromised. Because this skill is designed to handle API credentials and make network calls, executing an unpinned runtime bootstrapper materially increases the blast radius.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/config/first-time-setup.md (reported line 27)May include surrounding context.

md
│                            │
        ▼                            ▼
┌─────────────────────┐    ┌──────────────────────┐
│ Create EXTEND.md    │    │ Update EXTEND.md     │
└─────────────────────┘    └──────────────────────┘
        │                            │
        ▼                            ▼

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation states that reference images may be uploaded inline as base64 or that remote http(s) URLs are forwarded directly to DashScope, but it does not clearly warn users that local file contents and remote resource identifiers will be transmitted to a third-party provider. In an image-generation skill, users may supply sensitive local images or signed/private URLs, so the lack of explicit disclosure creates a real privacy and data-handling risk even if the behavior is expected for the feature.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This section explicitly says local files are inlined and http(s) URLs are forwarded as-is, but it omits a direct privacy/security warning about sending potentially sensitive user content and URL metadata to an external API. Because this skill's purpose is to transmit images to third-party generation providers, the context makes the omission more dangerous: users are likely to assume convenience behavior without realizing the disclosure implications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The examples instruct users to send prompts, prompt files, and reference images to third-party image providers but do not warn that these inputs may leave the local environment and be processed by external APIs. In a skill centered on multi-provider image generation, this omission increases the chance that users unintentionally transmit sensitive text or images to external services.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The batch examples normalize repeated external API calls and multiple output writes without warning about cost, rate limits, accidental bulk disclosure of prompt/reference content, or overwriting/creating many files. Because batch mode amplifies side effects, the missing warning makes misuse and unintended data exposure more likely.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access, suspicious.exposed_secret_literal

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/providers/google.ts:97

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/providers/azure.ts:36

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/providers/dashscope.ts:113

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/providers/google.ts:17

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/providers/jimeng.ts:7

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/providers/minimax.ts:39

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/providers/openai.ts:6

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/providers/openrouter.ts:44

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/providers/replicate.ts:38

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/providers/seedream.ts:49

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/providers/zai.ts:43

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/providers/jimeng.ts:268