Back to skill

Security audit

Deepsop Genvis 助手

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its AI image/video generation purpose, but optional notification and download paths can expose prompts or fetch arbitrary URLs without enough safeguards.

Review this before installing if prompts, reference media, or generated-media URLs may be sensitive. Only set FEISHU_WEBHOOK_URL to a trusted HTTPS Feishu endpoint you control, avoid inherited webhook values, be cautious with --download in shared or sensitive network environments, and prefer pinned dependencies when setting up the Python environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate_image.py:584
Finding

Unrestricted Webhook Can Exfiltrate User Prompts and Generated-Media URLs

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate_image.py:539
Finding

Unvalidated Result URL Enables SSRF-Style Requests and Unbounded Downloads

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate_image.py:33
Finding

Predictable Shared Temporary Cache Permits Local Cache Poisoning and Symlink Attacks

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:47
Finding

Documentation Recommends Installation of an Unpinned Third-Party Dependency

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (73)

Tainted flow: 'headers' from os.environ.get (line 520, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/generate_image.py (reported line 521)May include surrounding context.

python
with open(file_path, 'rb') as f:
            files = {'file': (os.path.basename(file_path), f)}
            headers = {'X-Api-Key': API_KEY}
            response = requests.post(FILE_UPLOAD_URL, headers=headers, files=files, timeout=120)
            response.raise_for_status()
            result = response.json()

Tainted flow: 'FEISHU_WEBHOOK_URL' from os.environ.get (line 52, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
98% confidence
Finding

The script will exfiltrate user prompts, result URLs, and error details to an arbitrary webhook endpoint taken directly from the FEISHU_WEBHOOK_URL environment variable. Because this outbound notification is optional, third-party, and not tightly validated or consent-gated, it creates a real data-leak/SSRF-style risk if the environment variable is misconfigured or attacker-controlled.

Content

Scanner excerpt · scripts/generate_image.py (reported line 639)May include surrounding context.

python
}
            }
        
        response = requests.post(
            FEISHU_WEBHOOK_URL,
            json=content,
            headers={"Content-Type": "application/json"},

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 11)May include surrounding context.

md
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

md
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 199)May include surrounding context.

md
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 358)May include surrounding context.

md
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 361)May include surrounding context.

md
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 364)May include surrounding context.

md
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 367)May include surrounding context.

md
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 370)May include surrounding context.

md
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 373)May include surrounding context.

md
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 374)May include surrounding context.

md
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 377)May include surrounding context.

md
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 379)May include surrounding context.

md
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 381)May include surrounding context.

md
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 384)May include surrounding context.

md
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 387)May include surrounding context.

md
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 390)May include surrounding context.

md
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 393)May include surrounding context.

md
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 396)May include surrounding context.

md
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 399)May include surrounding context.

md
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 402)May include surrounding context.

md
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 405)May include surrounding context.

md
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 408)May include surrounding context.

md
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 411)May include surrounding context.

md
查看当前服务端激活的模型请运行:`python3 scripts/generate_image.py --list-models`。

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tests/test_generate_image.py:36