Back to skill

Security audit

AI图像创作(AI付版) - 聚合数据

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent paid AI image-generation integration, but it includes unsafe install and shell-command patterns that deserve review before use.

Install only if you are comfortable using a paid third-party image service and sending your prompt text to Juhe. Do not include private or regulated information in prompts. Verify the Alipay payment installer source and exact version before running it, and prefer an implementation that sends the API request through a structured HTTP client rather than interpolating prompts into a shell command.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:82
Finding

Shell Command Injection Through an Unescaped Image Prompt

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 82-95
Vulnerability Type: Shell command injection through unsafe interpolation of user-controlled input
Risk Level: High

Vulnerable Code

bash
curl https://apis.juhe.cn/a2a/query \
    -d '{"resourceId":"824","data":{"prompt":"<用户描述的图像内容>","size":<用户描述的尺寸>}}' \
    -H "Content-Type: application/json"

Technical Analysis

The Skill directs the Agent to substitute a user-controlled image prompt into a single-quoted shell argument and then execute the resulting curl command. Although the document mentions escaping quotation marks for JSON, JSON escaping does not make data safe for interpolation into a shell command.

A single quote in the prompt can terminate the shell argument. Subsequent prompt content can then be interpreted by the shell as operators, commands, redirections, or substitutions rather than as JSON data. Escaping only JSON double quotes is therefore insufficient.

The size value is also inserted without JSON string delimiters. The documented validation limits it to values from 1 through 5, but this protection depends entirely on the Agent consistently enforcing the natural-language instruction.

Attack Path

  1. An attacker requests image generation and accepts the paid-service terms.
  2. The attacker supplies a prompt containing a single quote followed by shell syntax and an additional command.
  3. The Agent directly replaces the prompt placeholder in the documented curl template.
  4. The shell parses the injected quote as the end of the original -d argument.
  5. The attacker-controlled shell syntax executes with the privileges of the Agent process.
  6. The injected command can access files, environment variables, credentials, network resources, or other capabilities available to that process.

Exploitation requires the Agent to implement the documented request by textual substitution into a shell command. ...[truncated 759 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not build shell commands by inserting user-controlled text into command templates.
  • Use a structured HTTP library that accepts an object and performs JSON serialization without invoking a shell.
  • If a command-line client is unavoidable, construct the request body with a trusted JSON serializer such as jq, pass values as discrete arguments, and avoid sh -c, eval, or equivalent shell evaluation.
  • Treat JSON escaping and shell escaping as separate security boundaries. JSON quote handling alone must not be presented as sufficient.
  • Enforce the prompt length limit programmatically and validate size using a strict allowlist of integer values 1 through 5.
  • Add security tests using prompts containing single quotes, double quotes, backticks, command substitutions, newlines, redirection operators, and shell separators.
  • Run the Agent with least privilege and restrict its filesystem and network access to reduce the impact of any future command-injection defect.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:20
Finding

Unpinned Third-Party Package Download and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 20-22
Vulnerability Type: Unsafe dependency installation from a mutable package tag
Risk Level: Medium

Vulnerable Code

text
- `alipay-authenticate-wallet`: Alipay wallet identity authentication Skill
- `alipay-payment-skill`: A2M 402 payment collection core Skill
- If not installed, prompt the user to run: npx -y @alipay/agent-payment@latest install

The source instruction specifically invokes:

bash
npx -y @alipay/agent-payment@latest install

Technical Analysis

The installation instruction uses npx with the mutable latest tag and the automatic-confirmation option -y. This causes npm to retrieve and execute whichever package version is associated with latest at installation time.

The dependency is not pinned to a reviewed version, and the instruction does not require integrity verification, provenance validation, package-signature checks, or inspection before execution. Consequently, the code that executes can change after the Skill itself has been audited.

This creates a supply-chain risk if the publisher account, npm package, release process, or transitive dependency graph is compromised. It can also introduce unreviewed behavior through an otherwise legitimate but incompatible future release.

Attack Path

  1. An attacker compromises the npm publisher account, release process, package, or a dependency used by @alipay/agent-payment.
  2. The attacker publishes a malicious release and causes the mutable latest tag to resolve to it.
  3. A user invokes this Skill without the required payment capabilities installed.
  4. The Skill recommends running npx -y @alipay/agent-payment@latest install.
  5. npx downloads the current package and executes its entry point or installation behavior without pinning it to the previously audited version.
  6. Malicious code runs with the permissions of the user or Agent perform ...[truncated 925 chars]
Remediation
View remediation

Remediation Suggestions

  • Replace the mutable @latest reference with an exact, reviewed package version.
  • Verify package provenance and integrity before installation, using a trusted lockfile, registry controls, checksums, signatures, or npm provenance attestations where available.
  • Remove -y so installation requires explicit user review and approval.
  • Display the exact package name, version, registry, requested permissions, and reason for installation before proceeding.
  • Perform dependency installation separately from normal Skill execution and require an administrator-controlled approval process.
  • Review and pin transitive dependencies where practical.
  • Execute installation in a sandbox or least-privileged environment with restricted access to wallet credentials, sensitive files, and unrelated network destinations.
  • Monitor the approved package version for advisories and deliberately review upgrades before changing the pinned version.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The skill instructs users to run npx -y @alipay/agent-payment@latest install, which fetches and executes remote package code at install time without version pinning. Using @latest makes the executed code mutable over time, so a compromised publisher account, malicious update, or supply-chain attack could cause arbitrary code execution on the user's machine.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The skill sends user-provided prompts to an external third-party service (apis.juhe.cn) for image generation, which is a real external data transmission. While this is part of the stated functionality, it still creates privacy and data-handling risk because users may submit sensitive information, and the prompt is transmitted off-platform to a vendor-controlled endpoint.

Content

Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

向用户展示待生成图像的参数,严格遵守请求约束,向以下 URL 发起请求:

bash
curl https://apis.juhe.cn/a2a/query \
    -d '{"resourceId":"824","data":{"prompt":"<用户描述的图像内容>","size":<用户描述的尺寸>}}' \
    -H "Content-Type: application/json"

Static analysis

No suspicious patterns detected.