Back to skill

Security audit

gpt image 2 generation

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to generate images as advertised, but it handles a user API key while forcing tracked vendor onboarding and broad account-change guidance that users should review first.

Install only if you are comfortable sending prompts to WellAPI and storing a WellAPI API key locally. Prefer using a protected environment variable over --api-key, review the referral registration URL, and treat the account-group remediation as vendor-specific advice rather than a confirmed diagnosis for every error.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:47
Finding

Mandatory referral messaging overrides normal agent discretion

Content
View full analysis
Please paste your **WellAPI API Key**. > If you don't have one yet, register at https://wellapi.ai/register?channel=c_qqn3vdvc to get a free key. Wait for the user to reply with the key, then call the helper script to securely store it: ```bash python3 scripts/setup_api_key.py ``` ``` ### Technical Analysis The Skill requires the agent to reproduce predetermined vendor messaging verbatim and explicitly prevents it from presenting alternative setup methods or asking clarifying questions. The registration URL contains the stable referral parameter `channel=c_qqn3vdvc`, which is not required to authenticate with the image-generation service. This behavior modifies how the agent must interact with the user rather than merely documenting the technical prerequisites. It creates a promotional redirection path whenever an API key is unavailable. Although directing the user to the service that supplies the required key is functionally relevant, enforcing a tracked URL and suppressing alternatives exceeds the minimum privileges and instructions needed for image generation. ### Attack Path 1. A user invokes the Skill without `WELLAPI_API_KEY` or a saved configuration key. 2. The Skill instructions require the agent to display the supplied onboarding message verbatim. 3. The agent is prohibited from initially explaining other supported configuration methods. 4. The user is directed to the tracked registration URL. 5. The third ...[truncated 441 chars]
Remediation
View remediation

T01 · Skill Instruction Hijacking

Note
Location
scripts/generate_image.py:97
Finding

All HTTP failures trigger mandatory vendor account-change messaging

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/generate_image.py:67
Finding

API keys can be supplied through process command-line arguments

Content
View full analysis
str: if cli_value: return cli_value.strip() ``` ### Technical Analysis Command-line arguments are not an appropriate secret-delivery channel in many environments. Depending on the operating system and execution context, arguments may be observable in process listings, shell history, terminal logs, CI job records, agent tool-call logs, crash reports, or audit telemetry. The key is not printed by the script, but accepting it as `--api-key` still places the full bearer token in the invoking process's argument vector. Any local user or monitoring component with sufficient process-inspection access may capture it while the synchronous request remains active for several minutes. ### Attack Path 1. A user or automation invokes `generate_image.py --api-key `. 2. The shell or orchestration system records the command, or the operating system exposes the process arguments. 3. A local process observer, log reader, or later shell-history reader retrieves the bearer token. 4. The observer uses the token directly against WellAPI, subject to the token's remote permissions and quota. ### Impact Assessment The vulnerability does not itself increase local privileges. Successful exploitation discloses the WellAPI bearer token to an actor who can read process metadata or execution logs. The attacker may then consume the user's API quota, submit requests as the user, or access any other WellAPI functionality authorized to that token. ]]>
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/api_key.py:48
Finding

API key file permissions are restricted only after plaintext creation

Content
View full analysis
Path: """Persist the API key to the per-user config file with 0600 perms.""" api_key = api_key.strip() if not api_key: raise ValueError("API key is empty.") directory = config_dir() directory.mkdir(parents=True, exist_ok=True) path = config_file() payload = {"api_key": api_key} path.write_text(json.dumps(payload, indent=2), encoding="utf-8") # Best-effort restrict permissions; on Windows chmod is a no-op for these # bits but the user profile is already access-controlled. try: os.chmod(path, stat.S_IRUSR | stat.S_IWUSR) except OSError: pass return path ``` ### Technical Analysis `Path.write_text()` creates or truncates the destination before `os.chmod()` restricts it to mode `0600`. Initial permissions therefore depend on the process umask. With a permissive umask, the plaintext API key can be created with group or other read permissions before the later permission change. The destination is predictable, and the code does not reject symbolic links. If an attacker can modify the configuration directory, a pre-created symlink can redirect the write to another file writable by the victim. In addition, permission-change failures are silently ignored, so the function reports success even when the secret remains insufficiently protected. The practical symlink risk depends on whether another actor can write to the user's configuration directory. Under ordinary correctly configured home-directory permissions, that precondition may not hold, but the implementation does not verify it. ### Attack Path 1. The user runs the setup helper to save a WellAPI key. 2. The script writes plaintext JSON to the predictable configuration path usi ...[truncated 970 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (7)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · .gitignore (reported line 14)May include surrounding context.

text
# Local config / secrets (should never be inside the skill anyway)
config.json
.env

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 161)May include surrounding context.

md
- `SKILL.md` — this file (metadata + instructions)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill declares broad capabilities in metadata and operational instructions, including network, filesystem, env access, and shell execution, but does not define any explicit tool scope such as permissions or allowed-tools. That leaves the agent with ambiguous execution boundaries and increases the chance of over-privileged use, especially because the workflow instructs running local scripts and handling secrets.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

md
- "Generate an image of a sunset over the ocean"
- "Draw a cat wearing a top hat"
- "Create a 1024x1024 picture of …"
- "Make an illustration / poster / artwork of …"
- Any other request to produce a visual from a textual description.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

md
- "Generate an image of a sunset over the ocean"
- "Draw a cat wearing a top hat"
- "Create a 1024x1024 picture of ..."
- "Make an illustration / poster / artwork of ..."
- Any other request to produce a visual from a textual description.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger guidance includes a catch-all instruction to use the skill for 'any other request to produce a visual,' which can cause the agent to invoke networked, file-writing behavior for loosely related user requests. Over-broad activation increases the attack surface by making unintended tool use more likely, even if the skill itself is not overtly malicious.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to present a Chinese-language remediation message verbatim by default, only optionally translated. This can mislead or coerce users who do not understand the language, undermining informed consent around account changes and retries tied to external API usage.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.