Back to skill

Security audit

agnes-图片生成

Security checks for vulnerabilities and agentic risk

Overview

This image-generation skill mostly does what it says, but it ships and automatically uses a hardcoded Agnes API key, which is unsafe and should be reviewed before installation.

Install only after the publisher removes and rotates the embedded API key, requires user-provided credentials, and clearly warns that prompts and selected local images are sent to Agnes servers and outputs may be saved locally. Treat the exposed key as compromised.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/agnes_gen.py:39
Finding

Hardcoded Agnes API Credential Exposed in Executable Code and Documentation

Content
View full analysis

Vulnerability Details

File Location: scripts/agnes_gen.py:36-39, 139-145; SKILL.md:97, 119, 208, 223, 241, 260, 284
Vulnerability Type: Hardcoded secret and insecure credential fallback
Risk Level: High

The project embeds a live-looking Agnes bearer token in executable code and repeatedly exposes it in command examples.

python
# Built-in default key (fallback)
DEFAULT_API_KEY = "sk-8Rzd2yCbFzOi1vxojseH8C5D8w3u4aMdNWsPNzxk0G7339Cz"

The credential is automatically selected when the caller does not provide another key:

python
def get_api_key(user_key=None):
    """Priority: user-provided, environment variable, built-in default."""
    if user_key:
        return user_key
    env_key = os.environ.get("AGNES_API_KEY", "").strip()
    if env_key:
        return env_key
    return DEFAULT_API_KEY

The documentation also exposes the bearer token in directly executable examples:

bash
curl -s -X POST "https://apihub.agnes-ai.com/v1/images/generations" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer sk-8Rzd2yCbFzOi1vxojseH8C5D8w3u4aMdNWsPNzxk0G7339Cz" \
  -d '{
    "model": "agnes-image-2.1-flash",
    "prompt": "<user image description>",
    "size": "2K",
    "ratio": "1:1",
    "extra_body": {
      "response_format": "url"
    }
  }'

Technical Analysis

API bearer tokens must be treated as secrets and supplied through a protected runtime secret mechanism. Embedding one in a distributable Skill grants every package recipient access to the credential. It can also persist in source-control history, build artifacts, logs, caches, forks, and copied documentation after removal from the current version.

The fallback behavior makes the exposure operational rather than illustrative: unless --key or AGNES_API_KEY is set, the script transmits the embedded credential in the Authorization header to a configured Agnes endpoint ...[truncated 2053 chars]

Remediation
View remediation

Remediation Suggestions

  1. Immediately revoke and rotate the exposed credential. Treat it as compromised even if usage logs currently appear normal.
  2. Remove DEFAULT_API_KEY and eliminate the built-in fallback. Fail closed with a clear error when no credential is securely supplied.
  3. Obtain the key only through a protected runtime mechanism, such as AGNES_API_KEY, an operating-system credential store, or the deployment platform's secret manager.
  4. Replace every credential in SKILL.md with a nonfunctional placeholder such as YOUR_API_KEY.
  5. Remove the secret from repository history, release archives, caches, generated artifacts, and previously published Skill packages where feasible.
  6. Inspect Agnes API usage and authentication logs for unauthorized activity associated with the exposed key.
  7. Apply the narrowest available API scope, per-user or per-deployment credentials, spending limits, rate limits, expiration, and rotation policies.
  8. Add automated secret scanning to pre-commit and CI pipelines to reject future bearer tokens and similar credentials.
  9. Avoid accepting secrets through command-line arguments where possible because process listings and shell history may expose them; prefer protected environment or secret-store injection.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill description does not fully match the documented behavior: it embeds a default API key and downloads remote outputs to local storage without clearly disclosing those side effects. Behavior-description mismatches are dangerous because they hide credential use and filesystem changes from users and auditors, reducing informed consent and making abuse harder to detect.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The documentation contains a hardcoded live-looking Agnes API key directly in example requests. Embedded credentials can be copied by anyone with access to the skill, enabling unauthorized API use, quota theft, billing abuse, and potential attribution of malicious activity to the key owner.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill explicitly states that the API key is hardcoded in requests and repeats credential exposure throughout the document. Repetition increases the likelihood of secret leakage and normalizes insecure handling of production credentials, making downstream compromise more likely.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script hardcodes a live Agnes API key and automatically falls back to it when the user does not provide one. Embedding credentials in distributable code exposes the key to anyone with access to the skill, enables unauthorized use of the associated account/quota, and normalizes silent credential substitution without explicit user consent.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares no explicit tool scope even though its documented behavior requires network access and likely environment/file interactions. Missing permission boundaries increases the chance of unintended or silent data transmission and makes review and enforcement harder.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

External transmission is expected for an image-generation skill, but here it includes sending user prompts and potentially user-provided images to third-party endpoints using an exposed hardcoded credential. In this context the network behavior is not inherently malicious, yet it becomes security-relevant because sensitive content may be transmitted without strong disclosure and because the credential handling is unsafe.

Content

Scanner excerpt · SKILL.md (reported line 95)May include surrounding context.

1. 文生图(Text-to-Image)

bash
curl -s -X POST "https://apihub.agnes-ai.com/v1/images/generations" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer sk-8Rzd2yCbFzOi1vxojseH8C5D8w3u4aMdNWsPNzxk0G7339Cz" \
  -d '{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill describes sending prompts and possibly source images to external endpoints, then downloading generated images and saving them locally, but does not provide a clear upfront warning about data transmission and filesystem effects. This can expose sensitive user content or create unexpected local artifacts without informed consent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The manifest specifically says the skill uses the upgraded Agnes image generation model agnes-image-2.1-flash. However, both text-to-image and image-to-image requests are configured to use agnes-image-2.0-flash, so the implemented behavior does not match the declared model/version.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

In image-to-image mode, local files are read, base64-encoded, and sent to remote Agnes endpoints without an explicit warning, confirmation, or privacy notice. This can leak sensitive local image contents—such as personal photos, screenshots, IDs, or confidential documents—to a third-party service when users may reasonably think they are only performing a local transformation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The file contains extensive Chinese-specific prompting guidance such as '中文文本生成优化' and states that Chinese prompts are optimized, but it does not offer users a language/locale choice or explain that the skill is intentionally region- or language-specific. This can conflict with language/locale policy expectations when a skill appears to prescribe one language by default.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

User-facing natural-language strings in the module docstring and CLI/help text are consistently Chinese-only, which effectively forces a specific language experience. The file does not offer an opt-in language choice or explain that the skill is intentionally restricted to a Chinese-speaking context.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/agnes_gen.py:39

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:97