Back to skill

Security audit

Image To Image

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward image-to-image workflow helper, but users should handle the API key carefully and be aware it installs a mutable npm CLI package.

Install only if you trust the ai-media-generator npm package and ricebowl.ai workflow. Prefer setting AI_MEDIA_API_KEY through a secret manager or protected environment variable instead of typing a real key into a shell command, and review the installed CLI version before use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:16
Finding

Unpinned Executable npm Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 16–19
Vulnerability Type: Supply-chain risk from an unpinned third-party executable dependency
Risk Level: Medium

Vulnerable Code:

yaml
install:
  - kind: node
    package: ai-media-generator
    bins: [ai-media]

Technical Analysis

The Skill declares ai-media-generator as an installable npm package without specifying an exact version or integrity hash. Consequently, installation can resolve to a package release that was not reviewed as part of this audit.

Because the dependency supplies the executable ai-media, compromise of the package publisher, npm registry account, or a future package release could introduce malicious installation lifecycle scripts or runtime behavior. Such code would execute with the privileges of the user installing or invoking the Skill.

The dependency implementation is not included in the project, so its current runtime behavior could not be independently assessed. This finding identifies the unsafe dependency-resolution mechanism rather than asserting that the current package is malicious.

Attack Path

  1. An attacker compromises the package publisher or gains the ability to release a malicious version of ai-media-generator.
  2. The attacker publishes a modified release containing a malicious npm lifecycle script or altered ai-media executable.
  3. A user installs the Skill after the malicious release becomes the version selected by npm.
  4. The package manager downloads and installs the unreviewed release.
  5. Malicious code executes during installation or when the ai-media command is invoked.
  6. The code accesses resources available to the current user, potentially including the configured API key, prompts, reference images, and local files.

Impact Assessment

Successful exploitation could provide code execution with the installing user's privileges. The accessible scope may include the ...[truncated 249 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin ai-media-generator to an exact, reviewed version rather than accepting the package registry's current version.
  • Enforce package integrity verification using a lockfile and registry-provided integrity hashes.
  • Review the package source, maintainers, release history, lifecycle scripts, and transitive dependencies before approving upgrades.
  • Use a trusted registry and prevent dependency resolution from unapproved registries or package sources.
  • Disable npm lifecycle scripts during installation where they are unnecessary.
  • Execute the CLI in a restricted environment with minimal filesystem access and only the credentials required for the task.
  • Automate dependency vulnerability scanning and require security review before changing the pinned version.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:42
Finding

API Key Exposed Through Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 42 and 60
Vulnerability Type: Sensitive credential passed as a command-line argument
Risk Level: Medium

Vulnerable Code at line 42:

bash
ai-media config set-key <KEY>

Repeated vulnerable code at line 60:

bash
ai-media config set-key <KEY>

Technical Analysis

The documented workflow instructs users to substitute an API key directly into a shell command. A real key entered this way can be retained in shell history, terminal session logs, command auditing systems, or synchronized history files. Depending on the operating system and process isolation, command-line arguments may also be observable by other local processes while the command executes.

Although the metadata identifies AI_MEDIA_API_KEY as the primary environment variable, the recommended and core command examples instead encourage direct command-line entry. The audit found no hardcoded credential in the file; exposure occurs when a user follows the example and substitutes a real secret.

Attack Path

  1. A user replaces the <KEY> placeholder with a valid ricebowl.ai API key.
  2. The shell records the complete command in its history, or a local monitoring or logging facility captures the process arguments.
  3. Another local user, support process, malicious program, backup operator, or history-synchronization recipient gains access to the recorded command.
  4. The party extracts the API key.
  5. The exposed key is used to authenticate to the associated service and consume resources available to that credential.

Impact Assessment

Exploitation could permit unauthorized use of the affected API account within the permissions granted to the exposed key. Potential consequences include consumption of paid credits, submission of generation requests, access to API-visible task information, and exposure of associated prompts or generated media if t ...[truncated 178 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace command-line secret entry with an interactive hidden prompt that does not echo or retain the key in shell history.
  • Prefer the declared AI_MEDIA_API_KEY environment variable, populated through an approved secret manager rather than a literal shell command.
  • Where supported, accept the key through standard input or a protected file descriptor.
  • If a configuration file is required, create it with owner-only permissions and avoid plaintext storage when an operating-system credential store is available.
  • Add an explicit warning that users must not substitute secrets directly into commands retained by shell history.
  • Redact credentials from application logs, diagnostics, error messages, telemetry, and configuration display commands.
  • Issue narrowly scoped keys, rotate them regularly, and revoke any key suspected of appearing in command history or process logs.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill description and trigger examples are broad enough to match many generic image-editing requests, which can cause over-selection of this skill in situations where a narrower or safer skill should be used. In an agent environment, ambiguous routing can lead to unintended external API use, unnecessary credentialed actions, and reduced operator control over which automation executes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Forcing Chinese-language operational instructions without offering language selection can cause user misunderstanding of workflow steps, parameters, or safety-relevant guidance. While not a direct exploit primitive, it increases the chance of incorrect execution and makes oversight harder in multilingual environments.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.