Back to skill

Security audit

Baoyu Xhs Images

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly generates social-media image cards, but one fallback path can run unverified local or downloaded code before rendering images.

Review this skill before installing if your agent might use the codex-imagegen fallback. Prefer native image generation or a trusted installed backend, avoid BAOYU_CODEX_IMAGEGEN_BIN unless you fully trust the target file, and do not allow npx -y bun runtime installation without separate approval. Also treat the sensitive/copyrighted-figure prompt guidance as subordinate to your platform safety rules.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
references/codex-imagegen.md:41
Finding

Unpinned Package Download and Execution Through npx Fallback

Content
View full analysis

Vulnerability Details

File Location: references/codex-imagegen.md, line 41
Vulnerability Type: Supply-chain risk caused by unpinned package execution
Risk Level: High

Vulnerable Code

bash
If `bun` is missing, `npx -y bun <WRAPPER>/main.ts ...` works as a fallback.

Technical Analysis

The documented fallback instructs the Agent to use npx -y to download and immediately execute the package resolved under the name bun. It does not specify an exact version, integrity hash, trusted registry, lockfile, or other provenance control.

The -y option suppresses the normal installation confirmation. Consequently, selecting this fallback can execute package code without a separate user decision. The effective code may also change after the Skill has been audited because package resolution occurs at runtime.

This creates a third-party supply-chain boundary: compromise of the resolved package, its dependency graph, the configured package registry, or local package-manager configuration could result in arbitrary code execution under the Agent's operating-system identity.

Attack Path

  1. The runtime has no native imagegen Skill but does have an authenticated Codex CLI.
  2. The workflow selects the codex-imagegen fallback.
  3. The baoyu-image-gen route is unavailable, and the wrapper has otherwise been located.
  4. The trusted bun executable is absent.
  5. The Agent follows line 41 and runs npx -y bun <WRAPPER>/main.ts ....
  6. npx resolves and downloads package content from its configured registry without an explicit confirmation.
  7. An attacker who has compromised the package, a transitive dependency, registry resolution, or package-manager configuration supplies malicious code.
  8. The downloaded code executes with the same permissions and environment access as the Agent.

Impact Assessment

Successful exploitation provides arbitrary local code execution with the Agent process's privileges. The malicious package could r ...[truncated 349 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the automatic npx -y bun fallback and require a preinstalled, trusted Bun executable.
  2. If runtime installation is unavoidable, pin an exact audited package version rather than resolving the latest available release.
  3. Enforce integrity verification using an approved lockfile, package hash, signed artifact, or equivalent provenance control.
  4. Use an explicitly configured trusted registry and reject unexpected package sources or redirects.
  5. Do not suppress installation confirmation. Obtain informed user approval before downloading or executing a new dependency.
  6. Run the dependency in a restricted environment with minimal filesystem, credential, environment-variable, and network access.
  7. Record the resolved package version and integrity metadata in logs so executions can be reproduced and investigated.
  8. Prefer a bundled, reviewed runtime or a native image-generation tool that does not require runtime package installation.

T09 · Insecure Skill Coding Practices

Error
Location
references/codex-imagegen.md:22
Finding

Arbitrary Environment-Selected Wrapper Execution

Content
View full analysis

Vulnerability Details

File Location: references/codex-imagegen.md, lines 22–25
Vulnerability Type: Unsafe executable selection through an environment variable
Risk Level: High

Vulnerable Code

markdown
Only when `baoyu-image-gen` is NOT installed in the current runtime. Discover the wrapper's location at runtime — do NOT hard-code `../../packages/...` from this skill:

1. **Honor explicit override**: if `$BAOYU_CODEX_IMAGEGEN_BIN` is set and points to a real file, use that path. It may be `.ts` (spawn `bun <path>`) or `.sh`/binary (spawn directly).
2. **Search the plugin root**: walk up from this skill's directory looking for `packages/baoyu-codex-imagegen/src/main.ts`. If found, that is the wrapper. Spawn it with `bun`.

Technical Analysis

The wrapper-discovery procedure gives priority to BAOYU_CODEX_IMAGEGEN_BIN and validates only that its value points to a real file. It does not require that the file reside in an approved directory, be owned by a trusted principal, have safe permissions, match a known hash or signature, or correspond to the expected wrapper.

The selected file may be a TypeScript program, shell script, or native binary. Shell scripts and binaries are explicitly spawned directly. Therefore, control over the inherited environment variable is effectively control over which local program the Skill executes.

Environment variables can be influenced by parent processes, shell profiles, CI job configuration, development containers, runtime launchers, or compromised project tooling. Treating such a value as an executable trust decision creates an arbitrary-code-execution path when the environment is not fully trusted.

Attack Path

  1. An attacker gains the ability to influence the Agent's inherited environment, such as through CI configuration, a runtime launcher, container configuration, shell initialization, or compromised local tooling.
  2. The attacker creates a malicious TypeScript file, shell script, or b ...[truncated 1240 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove support for selecting an executable through BAOYU_CODEX_IMAGEGEN_BIN, or treat the variable only as a non-authoritative hint.
  2. Resolve wrappers exclusively through a trusted runtime Skill registry or a fixed, approved installation directory.
  3. If the override must remain, require explicit user confirmation that displays the canonical executable path before first execution.
  4. Canonicalize the path and reject symlinks, traversal, relative paths, world-writable directories, and locations outside an allowlisted root.
  5. Verify trusted ownership and restrictive permissions for the executable and every parent directory.
  6. Validate the wrapper against an approved cryptographic hash or digital signature before execution.
  7. Restrict accepted file types and avoid spawning shell scripts or arbitrary native binaries directly.
  8. Invoke the wrapper without a shell and pass every argument as a separate process argument.
  9. Run the wrapper in a sandbox with minimal filesystem and network access and a sanitized environment.
  10. Log the canonical path, ownership, permissions, and verified digest for every wrapper execution.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (17)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
100% confidence
Finding

The phrase 'DO NOT refuse' is an explicit anti-refusal statement embedded in the prompt template. In a reusable assembly guide, this is especially risky because it propagates to every generated prompt and can systematically undermine safety controls across many requests.

Content

Scanner excerpt · references/workflows/prompt-assembly.md (reported line 22)May include surrounding context.

md
## Core Principles

- Hand-drawn quality throughout - NO realistic or photographic elements
- If content involves sensitive or copyrighted figures, create stylistically similar alternatives - DO NOT refuse to generate
- Keep information concise, highlight keywords and core concepts
- Use ample whitespace for easy visual scanning
- Maintain clear visual hierarchy

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The instruction 'DO NOT refuse to generate' is a direct anti-safety directive that attempts to override refusal behavior for sensitive/copyrighted figure requests. This can pressure downstream models or agents to ignore safeguards and produce prohibited or infringing content variants.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description mixes specific trigger phrases with a broad fallback condition: "or wants social media infographic series." That condition is not constrained by context, negative examples, or a precise invocation boundary, so it could overlap with many generic content-creation requests and cause unintended activation.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

md
- Treat explicit skill invocation, a file path, matched signals/presets, and `EXTEND.md` defaults as **recommendation inputs only**. None of them authorizes skipping confirmation.
- Do **not** start Step 3 until the user completes Step 2.
- Skip confirmation only when the current request explicitly says to do so, for example: `--yes`, "直接生成", "不用确认", "跳过确认", "按默认出图", or equivalent wording.
- If confirmation is skipped explicitly, state the assumed strategy / style / layout / palette / count / backend in the next user-facing update before generating.

## Language

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 89)May include surrounding context.

md
| `--preset <name>` | Style + layout + optional palette shorthand (see Presets below; per-preset prompt fragments in `references/style-presets.md`) |
| `--ref <files...>` | Reference images applied to image 1 as the series anchor |
| `--batch-size <n>` | Temporary generation batch size for this run. Default: `generation_batch_size` from EXTEND.md, otherwise 4. Clamp to 1-8. |
| `--yes` | Non-interactive: skip all confirmations, use EXTEND.md or built-in defaults, auto-confirm recommended plan (Path A) |

## Dimensions

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The guidance recommends npx -y bun as a fallback, which pulls and executes a package at runtime without pinning a version or verifying integrity. In an agent skill that may be invoked automatically, this creates a supply-chain risk: a compromised or unexpected bun package/version could execute arbitrary code on the host.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/config/first-time-setup.md (reported line 33)May include surrounding context.

md
│
        ▼
┌─────────────────────┐
│ Create EXTEND.md    │
└─────────────────────┘
        │
        ▼

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The confirmation options shown to users include Chinese labels while the surrounding interface text is in English, and the file does not state that this skill is Chinese-language or region-specific. That can force a language/locale on users without opt-in, which matches the language policy violation category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file includes natural-language guidance that sets both source_language and user_language to zh in the prescribed output format example. Because the skill does not mention user opt-in, alternatives, or a clearly justified region-only constraint, it risks violating language/locale policy by implicitly forcing Chinese output.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The example outline hard-codes Chinese text throughout hooks, titles, subtitles, CTAs, and interaction prompts, while the file does not indicate that Chinese is optional or that the template is specifically limited to a Chinese-only workflow. This can violate language/locale policy because it implicitly directs skill output into a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The prompt explicitly instructs the model to proceed when content involves sensitive or copyrighted figures and to create stylistically similar alternatives rather than refusing. In an image-generation workflow, this is a policy-bypass pattern because it normalizes transformation of restricted subjects into near-substitutes while suppressing safety refusal behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The screen-print override repeats the same unsafe pattern by adding alternate handling for sensitive or copyrighted figures instead of deferring to safety policy. Although phrased as a style-specific rule, it still broadens the system's willingness to render restricted subjects through stylized silhouettes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The schema defines language as zh|en|ja|ko|auto, which is a locale restriction expressed in natural language content. The file does not explain that this is optional by user choice beyond null, nor provide a documented justification for limiting outputs to those locales.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The file is written specifically for 'Xiaohongshu infographics' and recommends defaults based on 'XHS' engagement. Under the policy criteria, locale/platform-specific guidance can be a natural-language policy concern when it prescribes a specific language/locale context without stating user choice or documenting the constraint as optional.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This markdown file is natural-language content, so SQP-3 applies. The description targets Xiaohongshu infographics and immediately mixes in Chinese headings, which can impose a specific language/locale context without any explicit opt-in or clarification that the skill is region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This reference document includes Chinese headings and filter names such as '抠图', '描边', and '清透感' alongside English content, but does not state that bilingual output is optional or intended. Under the language/locale policy rule, forcing or assuming a specific language without opt-in can be a natural-language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The markdown specifies "CJK optimized," which imposes a language/locale preference in the skill description without indicating that users can choose another language or opt in to this constraint. This matches the policy category for language or locale restrictions expressed in natural language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.