Back to skill

Security audit

Flux Image Generator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Flux image-generation helper, but it relies on an unpinned third-party npm CLI and a media-service API key.

Install only if you trust the ai-media-generator npm package and publisher. Use a limited ricebowl.ai API key if possible, monitor credit usage, and rotate the key if you suspect the local CLI configuration or npm package was compromised.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:16
Finding

Unpinned Third-Party Executable Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 16–20
Vulnerability Type: Unpinned executable npm dependency
Risk Level: Medium

yaml
homepage: https://github.com/214140846/ai-media-generator
install:
  - kind: node
    package: ai-media-generator
    bins: [ai-media]

Technical Analysis

The Skill installs the executable npm package ai-media-generator without specifying an exact version or integrity hash. Consequently, installation may resolve to a future package release whose contents were not included in this audit. The package supplies the ai-media binary and may also execute npm lifecycle scripts during installation.

The configured homepage points to a user-owned GitHub repository, but the Skill provides no publisher verification, source pinning, checksum validation, or other mechanism that establishes the downloaded package as an immutable, audited artifact. This creates a supply-chain risk if the package, publisher account, repository, or distribution channel is compromised.

Attack Path

  1. An attacker compromises the npm publisher account, repository, or another relevant distribution component.
  2. The attacker publishes a malicious version of ai-media-generator.
  3. A subsequent Skill installation resolves the unpinned dependency to that malicious release.
  4. Malicious npm lifecycle code executes during installation, or the substituted ai-media binary executes when the Skill is invoked.
  5. The malicious code accesses resources available to the Agent process, potentially including the required AI_MEDIA_API_KEY, local files, and network connectivity.

Impact Assessment

Successful exploitation could permit arbitrary code execution with the privileges of the account installing or invoking the Skill. The resulting scope may include theft of the media-service API key, unauthorized API usage and credit consumption, access to files readable by the Agent, and further ne ...[truncated 153 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin ai-media-generator to an exact version that has undergone security review.
  • Use a lockfile and validate the package with a trusted integrity hash.
  • Verify and document the npm publisher and source-repository ownership.
  • Disable npm lifecycle scripts during installation where operationally possible, or explicitly audit all required scripts.
  • Prefer an immutable, signed release artifact and verify its signature before installation.
  • Run the CLI with least privilege and restrict its filesystem and network access.
  • Supply API credentials only at execution time, scope them to the minimum required permissions, and support rapid rotation if compromise is suspected.
  • Re-audit the dependency before approving version upgrades.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.