Back to skill

Security audit

gpt-image-2

Security checks for vulnerabilities and agentic risk

Overview

This image-generation skill is mostly coherent, but it sends user access keys and prompts to a hard-coded server over unencrypted HTTP and handles the key in exposed command-line arguments.

Install only if you trust the operator of the hard-coded image service and are comfortable sending your access key and prompts over unencrypted HTTP. Treat the key as exposed after use, avoid sensitive prompts, and expect generated files to be written to a predictable temporary path unless changed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate_image.py:21
Finding

Access Key and User Prompts Transmitted over Plaintext HTTP

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:13
Finding

Access Key Exposed through Command-Line Arguments

Content
View full analysis
--quota ``` Image generation uses the same credential-passing method: ```bash python3 "$HOME/.openclaw/skills/gpt-image-2/scripts/generate_image.py" \ --key \ --prompt "" \ --quality low ``` The script explicitly accepts the secret as an argument: ```python parser.add_argument("--key", required=True, help="访问密钥") ``` ### Technical Analysis Command-line arguments are not an appropriate secret-transport mechanism. Depending on the operating system and execution environment, process arguments may be visible through process inspection interfaces, monitoring agents, diagnostic tools, audit logs, command histories, or Agent tool-call transcripts. The Skill also instructs the Agent to retain the key throughout the session. Although session retention supports repeated requests, repeatedly interpolating the credential into commands expands its exposure beyond what is necessary. Authentication can be performed without placing the secret in process metadata. ### Attack Path 1. The user submits an access key to the Agent. 2. The Agent inserts the key into the script's `--key` command-line argument. 3. The full invocation is recorded in a tool transcript, shell history, process audit log, or monitoring system, or is temporarily exposed through process-inspection facilities. 4. A local user or an operator with access to those records retrieves the key. 5. The observer reuses the key against the image service to query quota or generate images. Exploitation through process inspection depends on o ...[truncated 598 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate_image.py:23
Finding

Predictable Shared Temporary Output Path Permits Symlink and Overwrite Attacks

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script sends the access key in an HTTP header to a server over plain HTTP, which allows network attackers to intercept the key and associated prompts via sniffing or man-in-the-middle attacks. Because the key appears to control paid quota and account access, compromise could lead to unauthorized usage, data exposure, and account abuse.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill instructs the agent to invoke a Python script that performs network-backed key validation and image generation, but the manifest declares no explicit tool scope or allowed-tools restrictions. This creates a capability mismatch: an installer or runtime may treat the skill as lower risk than it really is, while the skill can still cause external requests and handle secrets, increasing the chance of unsafe execution or policy bypass.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description advertises broad triggers such as '生成图片、画图、AI绘图、文生图、生成一张图', which can cause the skill to activate for loosely related user requests without strong intent confirmation. In practice this can lead to unintended execution, unnecessary secret prompting, or invocation in contexts where the user did not actually want this skill to run.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The runtime instruction to execute on 'any image description' is overly ambiguous and can treat ordinary conversational text as a command to call the generation script. Because the skill stores and reuses the user's access key across the session, accidental triggering could consume quota, transmit sensitive prompts externally, or perform unintended billable actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill's docstring, CLI description, help text, and runtime messages are written only in Chinese, which imposes a specific language on users without any opt-in or language-selection mechanism. The file does not document a region-specific requirement that would justify this locale restriction.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The script transmits user prompts and an access key to an external hard-coded server, which is security-relevant because sensitive user input and credentials leave the local environment. In this skill context, external transmission is expected for an image-generation API, but it becomes dangerous because the destination is a fixed third-party host and, more importantly, uses insecure transport.

Content

Scanner excerpt · scripts/generate_image.py (reported line 32)May include surrounding context.

python
payload = {"prompt": prompt, "size": "1024x1024", "quality": quality, "n": n}

    try:
        r = requests.post(f"{SERVER}/generate", headers=headers, json=payload, timeout=200)
    except Exception as e:
        print(f"[ERROR] 连接服务器失败: {e}", file=sys.stderr)
        sys.exit(1)

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes a text-to-image generation skill for creating images from prompts, but this script also exposes a separate /quota capability to inspect remaining quota and usage state. Querying account quota is adjacent to the service, but it is still a distinct behavior not reflected in the stated skill description.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.