Back to skill

Security audit

Z-image Local image generation with OpenVINO (no API key)

Security checks for vulnerabilities and agentic risk

Overview

The skill is for local Windows image generation, but it gives agents broad automatic setup authority, including silent installer and dependency downloads that modify the host with limited verification.

Review this before installing on a primary or managed machine. It is not clearly malicious, but you should only use it if you accept silent prerequisite installation, large model downloads, persistent local files, and dependency/model supply-chain risk. Prefer manually installing Python and Git, verifying installer sources, reviewing or locking dependencies, and running setup in a contained user environment.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:119
Finding

Remote Installers Are Downloaded and Executed Without Integrity Verification

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 119-123 and 147-151
Vulnerability Type: Unverified remote executable retrieval and execution
Risk Level: High

Vulnerable Code

powershell
$f = "$env:TEMP\python-installer.exe"
Invoke-WebRequest "https://www.python.org/ftp/python/3.12.10/python-3.12.10-amd64.exe" -OutFile $f
Start-Process $f -ArgumentList "/quiet InstallAllUsers=0 PrependPath=1 Include_pip=1" -Wait
Remove-Item $f
powershell
$f = "$env:TEMP\git-installer.exe"
Invoke-WebRequest "https://github.com/git-for-windows/git/releases/download/v2.49.0.windows.1/Git-2.49.0-64-bit.exe" -OutFile $f
Start-Process $f -ArgumentList "/VERYSILENT /NORESTART /NOCANCEL /SP- /CLOSEAPPLICATIONS /RESTARTAPPLICATIONS /COMPONENTS=icons,ext\\reg\\shellhere,assoc,assoc_sh" -Wait
Remove-Item $f

Technical Analysis

The Skill instructs the Agent to retrieve native Windows executables and launch them immediately without checking a cryptographic digest or validating the Authenticode publisher signature. HTTPS protects the transport connection but does not independently establish that the downloaded artifact is the exact release reviewed by the Skill author.

The highlighted Git download is hosted by the official git-for-windows/git GitHub project rather than a pastebin. Nevertheless, the release asset remains an external executable whose contents could change through repository compromise, account compromise, release-asset replacement, CDN compromise, malicious proxying, or an unexpected redirect.

The installers run as the current user. The Python command correctly requests a per-user installation, but it modifies PATH. The Git command also installs shell integration and file associations and permits closing or restarting applications. Those additional modifications are not the minimum changes needed merely to provide Git for dependency installation.

Attack Path

  1. An attacker comp ...[truncated 987 chars]
Remediation
View remediation

Remediation Suggestions

  • Do not automatically install system prerequisites without explicit, informed user consent.
  • Publish a trusted SHA-256 digest for each exact installer and verify it before execution with Get-FileHash.
  • Validate the Authenticode signature with Get-AuthenticodeSignature, require a valid signature, and verify the expected publisher.
  • Reject redirects to unexpected hosts and fail closed if any verification step fails.
  • Prefer an existing package manager with integrity and publisher validation where available.
  • Remove unnecessary Git components such as shell integration and file associations unless the user explicitly requests them.
  • Keep installation per-user and avoid elevation.
  • Retain sufficient audit output to identify the final URL, digest, signer, and installer exit status.

T08 · Insecure Dependencies

Error
Location
requirements_imagegen.txt:1
Finding

Python Dependency Installation Is Not Fully Pinned or Hash-Verified

Content
View full analysis

Vulnerability Details

File Location: requirements_imagegen.txt, lines 1-28; setup.py, lines 121-133
Vulnerability Type: Non-reproducible and insufficiently verified dependency installation
Risk Level: High

Vulnerable Code

text
--extra-index-url https://download.pytorch.org/whl/cpu

openvino==2026.0.0

torch==2.8
torchvision==0.23.0

git+https://github.com/openvino-dev-samples/optimum-intel.git@2f62e5aee74b4acba3836e1f26678c0db0a09c00

git+https://github.com/huggingface/diffusers.git@a1f36ee3ef4ae1bf98bd260e539197259aa981c1

modelscope
Pillow
transformers
accelerate
huggingface_hub

numpy<2.0
python
req_file = Path(__file__).parent / REQUIREMENTS_FILE
if req_file.exists():
    print(f"  Using {req_file}")
    venv_run(["-m", "pip", "install", "-r", str(req_file)], check=True)
else:
    print(f"  {REQUIREMENTS_FILE} not found — installing fallback list")
    venv_run(["-m", "pip", "install"] + PACKAGES_FALLBACK, check=True)

Technical Analysis

Although openvino, torch, and torchvision are version-pinned and the two Git dependencies use full commit identifiers in the requirements file, several direct dependencies are unconstrained. Transitive dependencies are also not locked, and no package hashes are required.

The --extra-index-url option causes pip to consider candidates from more than one package index. Candidate selection across indexes increases exposure to dependency-confusion and package-origin ambiguity. Installing Python packages may execute package-controlled build backends, setup logic, or native extension installation code.

The fallback list in setup.py is weaker still: it uses minimum versions for multiple packages and abbreviated Git commit references. While the normal project includes the requirements file, fallback behavior would become relevant if that file were missing or removed.

Attack Path

  1. An attacker compromise ...[truncated 1048 chars]
Remediation
View remediation

Remediation Suggestions

  • Generate and commit a complete dependency lock file containing exact versions for all direct and transitive packages.
  • Record hashes for every accepted wheel and enforce installation with pip --require-hashes.
  • Prefer binary wheels from explicitly approved indexes and disallow source builds unless required and reviewed.
  • Install PyTorch in a separate command using an exclusive --index-url rather than applying a global extra index to all dependencies.
  • Replace the fallback dependency list with the same locked, hash-verified dependency set, or fail safely when the lock file is absent.
  • Continue using full immutable Git commit identifiers, and preferably build, review, and hash fixed wheels from those commits.
  • Add automated checks that reject unpinned requirements and unexpected package origins.

T08 · Insecure Dependencies

Warning
Location
download_model.py:20
Finding

Model Snapshot Is Mutable and Is Loaded Without Artifact Integrity Verification

Content
View full analysis

Vulnerability Details

File Location: download_model.py, lines 20 and 122; generated inference code in setup.py, lines 252-253
Vulnerability Type: Unverified third-party model supply chain
Risk Level: Medium

Vulnerable Code

python
MODEL_ID = "snake7gun/Z-Image-Turbo-int4-ov"
python
snapshot_download(MODEL_ID, local_dir=str(model_dir))
python
import torch
from optimum.intel import OVZImagePipeline
pipe = OVZImagePipeline.from_pretrained(str(model_dir), device=device)

Technical Analysis

The ModelScope download specifies a model identifier but no immutable revision. Downloaded files are not compared with a trusted manifest of cryptographic hashes, and the completion check only tests for expected directories and sufficiently large .bin files.

Consequently, a future snapshot can differ from the artifact originally reviewed while retaining the same model identifier and directory structure. The model is published under a third-party namespace and is parsed by a complex model-loading stack. Malformed model weights or configuration files could target vulnerabilities in ModelScope, OpenVINO, Optimum Intel, Diffusers, or related parsers.

The reviewed code does not explicitly enable model-provided Python code or establish intentional execution of remote model code. The confirmed weakness is therefore missing revision and integrity validation, rather than confirmed execution of a model-hosted script.

Attack Path

  1. The model publisher account or repository is compromised, or the mutable model snapshot is replaced.
  2. The attacker publishes altered model weights or configuration files under the same model identifier.
  3. snapshot_download retrieves the latest available snapshot because no immutable revision is specified.
  4. Directory and size checks accept the files without cryptographic verification.
  5. OVZImagePipeline.from_pretrained parses and loads the alte ...[truncated 549 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin the model to an immutable ModelScope revision or commit.
  • Maintain a signed manifest containing every expected relative path, file size, and SHA-256 digest.
  • Verify the complete manifest before reporting the model as ready or loading it.
  • Reject unexpected files, symbolic links, reparse points, and unsafe file types.
  • Explicitly disable remote or custom code loading where the underlying APIs support that option.
  • Document the model publisher, immutable revision, license, and verification procedure.
  • Run model parsing and inference with minimal OS permissions and without network access after setup.

T07 · Tool Hijacking and Spoofing

Warning
Location
download_model.py:24
Finding

User-Writable State File Controls Executable and Runtime Paths

Content
View full analysis

Vulnerability Details

File Location: download_model.py, lines 24-47; related state consumption in check_env.py, lines 13-23 and 118-129
Vulnerability Type: Executable path hijacking through untrusted persistent state
Risk Level: Medium

Vulnerable Code

python
def find_state():
    for d in string.ascii_uppercase:
        sf = Path(f"{d}:\\") / f"{os.environ.get('USERNAME', 'user').lower()}_openvino" / "imagegen" / "state.json"
        if sf.exists():
            return json.loads(sf.read_text(encoding="utf-8"))
    return None

state = find_state()
if not state:
    print("[ERROR] state.json not found.")
    print("  Please run setup.py first:")
    print(f"    python \"{Path(__file__).parent / 'setup.py'}\"")
    sys.exit(1)

venv_py = Path(state["VENV_PY"])
if not venv_py.exists():
    print(f"[ERROR] venv not found at {venv_py}")
    print("  Please re-run setup.py.")
    sys.exit(1)

if Path(sys.executable).resolve() != venv_py.resolve():
    print(f"[INFO] Switching to venv python: {venv_py}")
    result = subprocess.run([str(venv_py), str(Path(__file__).resolve())])
    sys.exit(result.returncode)

Related environment validation also trusts state-provided paths:

python
venv_py = Path(state["VENV_PY"])
imagegen_dir = Path(state["IMAGE_GEN_DIR"])
model_dir = imagegen_dir / "Z-Image-Turbo-int4-ov"

Technical Analysis

state.json is stored in a user-writable directory and is treated as authoritative for VENV_PY and IMAGE_GEN_DIR. The code verifies only that the selected Python path exists before launching it. It does not require the path to be under the expected Skill-owned root, validate file ownership, reject reparse-point traversal, or verify the executable's identity.

The documented workflow also uses IMAGE_GEN_DIR to locate the deployed generate_image.py. Script staleness checking compares a plaintext version string embedded in the ...[truncated 1576 chars]

Remediation
View remediation

Remediation Suggestions

  • Derive the runtime root deterministically from a fixed trusted location instead of accepting executable paths from JSON.
  • Canonicalize every path with resolve() and verify that it remains under the expected root before use.
  • Reject symbolic links, junctions, and reparse points for executables, deployed scripts, state files, and sensitive parent directories where practical.
  • Apply restrictive access-control entries so only the intended user can modify the runtime directory.
  • Verify the deployed script against a trusted cryptographic hash rather than a self-declared version string.
  • Validate that VENV_PY is the expected virtual-environment interpreter and not merely an existing executable.
  • Write state atomically with restrictive permissions and validate its schema and allowed values before use.
  • If integrity validation fails, stop and require a clean environment rebuild rather than executing the selected path.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (34)

Known Vulnerable Dependency: torch==2.8 — 8 advisory(ies): CVE-2025-3001 (PyTorch is vulnerable to memory corruption through its torch.lstm_cell function); CVE-2025-3000 (PyTorch is vulnerable to memory corruption through its torch.jit.script function); CVE-2025-2999 (PyTorch is vulnerable to memory corruption through its unpack_sequence function) +5 more

Critical
Category
Supply Chain
Confidence
98% confidence
Finding

The manifest explicitly pins 'torch==2.8', and the finding indicates that this exact version has multiple critical memory-corruption advisories. In this image-generation/ML context, PyTorch is a core runtime component, so a vulnerable version materially increases the risk of denial of service, memory corruption, or potentially code execution when processing crafted inputs or model artifacts.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 158)May include surrounding context.

md
> git is required for the `git+https://` dependency in `requirements_imagegen.txt`; without git, `pip install` will fail with `git: command not found`.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger phrases are broad enough to match ordinary requests like 'draw something' or 'make an image,' causing this skill to activate in many benign contexts. Because the skill can perform setup, downloads, and system modification, overly broad activation increases the chance that high-risk behavior is invoked when the user did not intend to authorize such actions.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
94% confidence
Finding

The skill instructs the agent to automatically run setup.py up to three times when environment checks fail, without requiring prior user confirmation. In this skill, setup is not a harmless retry: it can create environments, install packages from the network, and modify the host, so autonomous recovery materially increases risk.

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

md
**Auto-recovery policy — try before asking user:**

* If `STATE=MISSING`, `VENV_PY=BROKEN`, `PACKAGES_MISSING`, or `SCRIPTS_STALE`: automatically run `setup.py` (up to 3 attempts). Only ask user if all 3 fail.
* If `MODEL_STATUS=MISSING`: automatically run `download_model.py` (up to 3 attempts). Stop if a single attempt exceeds 20 minutes — download supports resume, partial progress is not lost.
* Always announce before each attempt: `[INFO] Auto-installing environment (attempt N/3)…`

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

The skill also directs automatic model downloads up to three times, potentially transferring about 10 GB and interacting with external network resources without an explicit approval step for each operation. Autonomous network activity of this size can have cost, policy, and privacy implications, especially on managed or metered systems.

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

md
**Auto-recovery policy — try before asking user:**

* If `STATE=MISSING`, `VENV_PY=BROKEN`, `PACKAGES_MISSING`, or `SCRIPTS_STALE`: automatically run `setup.py` (up to 3 attempts). Only ask user if all 3 fail.
* If `MODEL_STATUS=MISSING`: automatically run `download_model.py` (up to 3 attempts). Stop if a single attempt exceeds 20 minutes — download supports resume, partial progress is not lost.
* Always announce before each attempt: `[INFO] Auto-installing environment (attempt N/3)…`

**[WARNING] Network / proxy handling** — when running `setup.py` or `download_model.py`:

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

| 'python' is not recognized as an internal or external command | Python is not installed; install is required (see below) | | Python was not found; run without arguments... | Windows Store alias — see below |

If output contains "run without arguments to install from the Microsoft Store", the Windows Store App Execution Alias is shadowing the real Python. Do NOT ask the user to change settings, and do NOT write helper scripts. Run this command to find the real Python:

powershell
where.exe python 2>$null | Where-Object { $_ -notlike "*WindowsApps*" } | Select-Object -First 1

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to download and silently install Python and Git executables, which exceeds the expected scope of an image-generation skill and performs significant host modification. Silent installation of developer tooling from the network can be abused to change system state without meaningful user consent, expand execution capability, and increase supply-chain risk if the download source or path is compromised.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The instructions include silent downloads and installer execution without a prominent upfront warning at the point of action that the host will be modified and external binaries fetched. Even though the document mentions setup needs network access, the operational flow still encourages automatic execution, which weakens informed consent and increases the likelihood of unsafe installs.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · check_env.py (reported line 84)May include surrounding context.

python
"""
    try:
        # 1. venv Python itself must be executable
        proc = subprocess.run(
            [str(venv_py), "--version"],
            capture_output=True,
            timeout=3,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · check_env.py (reported line 98)May include surrounding context.

python
"import openvino; import torch; import PIL; "
            "import modelscope; from optimum.intel import OVZImagePipeline"
        )
        proc2 = subprocess.run(
            [str(venv_py), "-c", check_script],
            capture_output=True,
            timeout=15,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
90% confidence
Finding

The script executes a Python interpreter path taken from state.json without validating that the file is trusted, expected, or located in a safe directory. If an attacker can tamper with state.json or the referenced VENV_PY path, they can cause arbitrary code execution by making this launcher invoke a malicious executable instead of the intended virtualenv Python.

Content

Scanner excerpt · download_model.py (reported line 47)May include surrounding context.

python
# This ensures modelscope and all deps are available.
if Path(sys.executable).resolve() != venv_py.resolve():
    print(f"[INFO] Switching to venv python: {venv_py}")
    result = subprocess.run([str(venv_py), str(Path(__file__).resolve())])
    sys.exit(result.returncode)

# ─────────────────────────────────────────────────────────────

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · setup.py (reported line 62)May include surrounding context.

python
print(f"\n  Python {vi.major}.{vi.minor}.{vi.micro} OK ✅")

# ── Check git ──────────────────────────────────────────────
r = subprocess.run(["git", "--version"], capture_output=True)
if r.returncode != 0:
    print("\n[ERROR] git not found — required for pinned git+https dependencies")
    print("  Download: https://git-scm.com/download/win")

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
88% confidence
Finding

This executes an existing venv_py binary before establishing trust in that file. Since the venv location is auto-discovered on available drives under a predictable name based on USERNAME, a local attacker could plant a malicious executable there and have it run during the validation step.

Content

Scanner excerpt · setup.py (reported line 99)May include surrounding context.

python
venv_ok = False
if venv_py.exists():
    try:
        r = subprocess.run([str(venv_py), "--version"], capture_output=True, timeout=10)
        if r.returncode == 0:
            print(f"  Existing venv OK: {r.stdout.decode().strip()}")
            venv_ok = True

Tainted flow: 'venv_py' from os.environ.get (line 112, credential/environment) → subprocess.run (code execution)

Medium
Category
Data Flow
Confidence
90% confidence
Finding

The environment-derived path influences selection of venv_py, and the script executes it during the 'Existing venv OK' check. In this skill context, that is more dangerous because the script is an installer that will commonly be run by a user with the expectation of preparing code and dependencies, making pre-planted local tampering a realistic privilege and persistence vector.

Content

Scanner excerpt · setup.py (reported line 99)May include surrounding context.

python
venv_ok = False
if venv_py.exists():
    try:
        r = subprocess.run([str(venv_py), "--version"], capture_output=True, timeout=10)
        if r.returncode == 0:
            print(f"  Existing venv OK: {r.stdout.decode().strip()}")
            venv_ok = True

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · setup.py (reported line 111)May include surrounding context.

python
print("  Existing venv is broken — rebuilding...")
        shutil.rmtree(venv_dir, ignore_errors=True)
    print("  Creating venv...")
    subprocess.run([sys.executable, "-m", "venv", str(venv_dir)], check=True)
    venv_py = venv_dir / "Scripts" / "python.exe"
    r = subprocess.run([str(venv_py), "--version"], capture_output=True)
    print(f"  Venv created: {r.stdout.decode().strip()} ✅")

Tainted flow: 'venv_dir' from os.environ.get (line 83, credential/environment) → subprocess.run (code execution)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · setup.py (reported line 111)May include surrounding context.

python
print("  Existing venv is broken — rebuilding...")
        shutil.rmtree(venv_dir, ignore_errors=True)
    print("  Creating venv...")
    subprocess.run([sys.executable, "-m", "venv", str(venv_dir)], check=True)
    venv_py = venv_dir / "Scripts" / "python.exe"
    r = subprocess.run([str(venv_py), "--version"], capture_output=True)
    print(f"  Venv created: {r.stdout.decode().strip()} ✅")

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · setup.py (reported line 113)May include surrounding context.

python
print("  Creating venv...")
    subprocess.run([sys.executable, "-m", "venv", str(venv_dir)], check=True)
    venv_py = venv_dir / "Scripts" / "python.exe"
    r = subprocess.run([str(venv_py), "--version"], capture_output=True)
    print(f"  Venv created: {r.stdout.decode().strip()} ✅")

def venv_run(args, **kw):

Tainted flow: 'venv_py' from os.environ.get (line 112, credential/environment) → subprocess.run (code execution)

Medium
Category
Data Flow
Confidence
89% confidence
Finding

Although not shell injection, this is still a genuine execution-of-untrusted-binary issue because venv_py is derived from a predictable, environment-influenced path and then executed. If an attacker can control that path or pre-seed the venv directory, this line will run attacker code.

Content

Scanner excerpt · setup.py (reported line 113)May include surrounding context.

python
print("  Creating venv...")
    subprocess.run([sys.executable, "-m", "venv", str(venv_dir)], check=True)
    venv_py = venv_dir / "Scripts" / "python.exe"
    r = subprocess.run([str(venv_py), "--version"], capture_output=True)
    print(f"  Venv created: {r.stdout.decode().strip()} ✅")

def venv_run(args, **kw):

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
91% confidence
Finding

venv_run executes whatever binary exists at venv_py, and that path is derived from a root directory influenced by environment state and discovered drives. Because the script reuses an existing venv if python.exe --version succeeds, an attacker who can pre-place or replace ...\venv\Scripts\python.exe in that location can gain arbitrary code execution when subsequent pip/install/verify commands are run.

Content

Scanner excerpt · setup.py (reported line 117)May include surrounding context.

python
print(f"  Venv created: {r.stdout.decode().strip()} ✅")

def venv_run(args, **kw):
    return subprocess.run([str(venv_py)] + args, **kw)

# ── Upgrade pip ────────────────────────────────────────────
print("\n[2/3] Upgrading pip...")

Tainted flow: 'venv_py' from os.environ.get (line 112, credential/environment) → subprocess.run (code execution)

Medium
Category
Data Flow
Confidence
93% confidence
Finding

This helper is the main sink for repeated execution of the discovered venv_py interpreter and therefore amplifies the trust problem. Once a malicious binary is accepted at that path, all package installation and verification operations execute under attacker control.

Content

Scanner excerpt · setup.py (reported line 117)May include surrounding context.

python
print(f"  Venv created: {r.stdout.decode().strip()} ✅")

def venv_run(args, **kw):
    return subprocess.run([str(venv_py)] + args, **kw)

# ── Upgrade pip ────────────────────────────────────────────
print("\n[2/3] Upgrading pip...")

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill directs the agent to inspect HTTPS_PROXY/HTTP_PROXY and WinHTTP proxy settings, exposing host network configuration that is not strictly necessary to fulfill a simple image-generation request. While limited in scope, proxy settings can reveal enterprise infrastructure details and should not be collected or echoed unless required and user-approved.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The header documentation frames this as a standalone terminal-only script, yet the body is clearly part of the OpenClaw skill setup flow: it locates the skill state file, depends on setup.py, switches into the configured venv, and downloads the model used by the image-generation skill. This is a mild documentation/intent mismatch because the comments describe where to run it rather than its broader operational role, but they still understate what the code is actually for.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The comment and implementation explicitly impose a specific encoding behavior to address one locale scenario ('Chinese Windows') rather than offering user choice or a configurable locale/output option. This is a natural-language locale policy concern because the file describes and enforces a language/locale-related behavior without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This plain-text requirements file contains multiple Chinese-only comments describing dependency purpose and constraints. Because SQP-3 applies to all file types and the file does not indicate that Chinese is optional or required for a region-specific skill, this can be interpreted as a language/locale policy issue.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The unpinned dependency 'modelscope' makes builds non-reproducible and allows future installs to silently pull different releases, including potentially vulnerable or malicious ones. In this skill context, the package is used for model download/loading, which increases exposure to supply-chain and unsafe-deserialization style risks if an unexpected version is resolved.

Content

Scanner excerpt · requirements_imagegen.txt (reported line 17)May include surrounding context.

text
git+https://github.com/huggingface/diffusers.git@a1f36ee3ef4ae1bf98bd260e539197259aa981c1

# 模型下载
modelscope

# 图像保存
Pillow

Static analysis

No suspicious patterns detected.