Back to skill

Security audit

Memorable Image Generator

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it claims: it generates images with Gemini, scores them locally with ResMem, and saves the best result, with no evidence of hidden persistence or unrelated data access.

Install this in a separate Python environment, use a restricted Gemini API key, avoid passing the key directly on the command line, and remember that your prompts are sent to Google's Gemini API. Commercial users should also review the ResMem non-commercial license before using outputs in business contexts.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate_memorable_image.py:21
Finding

Gemini API Key Exposed Through Process Arguments and URL Query Parameters

Content
View full analysis
str: if cli_key: return cli_key env_key = os.environ.get("GEMINI_API_KEY") if env_key: return env_key config_path = Path.home() / ".config" / "gemini" / "api_key" if config_path.exists(): return config_path.read_text().strip() print( "Error: Gemini API key not found.\n" "Provide it via --api-key, the GEMINI_API_KEY environment variable,\n" "or by writing it to ~/.config/gemini/api_key", file=sys.stderr, ) sys.exit(1) def generate_image(prompt: str, api_key: str) -> bytes | None: url = ( "https://generativelanguage.googleapis.com/v1beta/models/" f"gemini-2.0-flash-exp:generateContent?key={api_key}" ) payload = { "contents": [{"parts": [{"text": prompt}]}], "generationConfig": {"responseModalities": ["TEXT", "IMAGE"]}, } response = requests.post(url, json=payload, timeout=60) ``` The command-line option is registered as follows: ```python parser.add_argument("--api-key", help="Gemini API key") ``` The documentation explicitly demonstrates passing the credential through that option: ```bash python scripts/generate_memorable_image.py \ --prompt "your image description" \ --output path/to/output.png \ --threshold 0.75 \ --max-attempts 3 \ --api-key YOUR_KEY \ --verbose ``` ### Technical Analysis The Skill accepts the Gemini API key as a command-line argument. Command-line arguments can be exposed through shell history, process inspection facilities, job-control systems, diagnostic tools, audit logs, and automation logs. The key is then concatenated into the request URL as a query param ...[truncated 1879 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/generate_memorable_image.py:58
Finding

Unpinned Executable Dependencies and Unverified Pretrained Model Retrieval

Content
View full analysis
float: try: from PIL import Image from resmem import ResMem, transformer import torch except ImportError as e: print( f"Import error: {e}\n" "Install required packages with:\n" " pip install resmem torch torchvision pillow requests", file=sys.stderr, ) sys.exit(1) model = ResMem(pretrained=True) model.eval() ``` The Skill metadata likewise declares dependencies without versions: ```yaml requires: env: ["GEMINI_API_KEY"] python_packages: ["resmem", "torch", "torchvision", "pillow", "requests"] ``` ### Technical Analysis Python packages can execute code during installation and whenever they are imported. The Skill directs users to install packages using names alone, without reviewed version pins, cryptographic hashes, a lock file, or an explicitly controlled package source. The effective code executed by the Skill can therefore change after this Skill package has been audited. `ResMem(pretrained=True)` may also rely on dependency-controlled retrieval or loading of pretrained model material. This project does not specify the expected artifact location, version, or checksum. The audit does not establish that the current packages or model are malicious; the issue is the lack of controls that bind installation and model loading to reviewed artifacts. All listed dependencies are relevant to image generation and ...[truncated 1707 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill advertises capabilities that require access to environment variables, local file reads/writes, and outbound network calls, but it does not declare any explicit tool scope or permission boundaries. This increases the risk that an agent runtime will grant broader-than-necessary access, making misuse, data exposure, or unintended side effects more likely if the skill is invoked in a permissive environment.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: Memorable Image Generator
description: "Science-backed image generation agent that scores and optimizes images for memorability using ResMem (Brain Bridge Lab, University of Chicago) before returning results. Unlike generic image generators, this agent iterates until the image clears a memorability threshold — producing visuals that stick in viewers' minds. Use for blog hero images, marketing visuals, social media graphics, product thumbnails, or any context where image recall matters. Triggers on: generate a memorable image, create a blog hero image, make a marketing visual that sticks, image that people will remember, or any image generation request where memorability is a goal."
license: ResMem Non-commercial License
metadata:
  openclaw:

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger text includes a very broad activation condition such as 'any image generation request where memorability is a goal,' which can cause the skill to activate in many loosely related contexts. Overbroad matching raises the chance of unintended execution of a networked, file-writing skill, potentially exposing prompts, consuming API credits, or producing outputs when the user did not explicitly request this specific workflow.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/generate_memorable_image.py (reported line 50)May include surrounding context.

python
"contents": [{"parts": [{"text": prompt}]}],
        "generationConfig": {"responseModalities": ["TEXT", "IMAGE"]},
    }
    response = requests.post(url, json=payload, timeout=60)
    if response.status_code != 200:
        print(
            f"Gemini API error {response.status_code}: {response.text}",

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The manifest describes an image generator optimized for memorability, but does not mention credential discovery from the local environment or ~/.config. While calling a remote image model is expected for this purpose, probing multiple local credential sources adds a local-data access capability beyond the stated user-facing function.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.