Back to skill

Security audit

SiliconFlow Image Gen

Security checks for vulnerabilities and agentic risk

Overview

This image-generation skill is mostly coherent, but it asks for broad command execution and handles the API key in a way that can expose it locally.

Review this skill before installing if you will use a paid or high-privilege SiliconFlow key. Prefer a limited API key with spending controls, avoid prompts containing private data, and consider replacing the curl subprocess with an in-process HTTPS client or a more narrowly scoped runtime permission.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate.py:64
Finding

SiliconFlow API Key Exposed Through Process Arguments

Content
View full analysis

Vulnerability Details

File Location: scripts/generate.py, lines 64-72
Vulnerability Type: API credential exposure through subprocess command-line arguments
Risk Level: Medium

Vulnerable Code:

python
curl_cmd = [
    "curl", "-s", "-X", "POST",
    f"{API_BASE_URL}/images/generations",
    "-H", f"Authorization: Bearer {api_key}",
    "-H", "Content-Type: application/json",
    "-d", json.dumps(data),
    "--max-time", "120"
]

Technical Analysis

The script places the SiliconFlow bearer token directly in the argument list of a curl subprocess. Depending on the operating system and its process-inspection controls, command-line arguments may be visible through process-monitoring utilities, audit or telemetry systems, and process metadata such as /proc.

Although the credential is not written explicitly to application output, placing it in a child process's argument vector unnecessarily expands its exposure beyond the Python process. Exploitation requires local process visibility while the curl request is running.

Attack Path

  1. An attacker obtains access to a local account or monitoring facility capable of viewing another process's command-line arguments.
  2. The victim invokes the image-generation script with a valid SiliconFlow API key.
  3. The script launches curl with Authorization: Bearer <API_KEY> in its argument list.
  4. During the subprocess lifetime, the attacker inspects process metadata and extracts the bearer token.
  5. The attacker uses the recovered token directly against the SiliconFlow API.

Impact Assessment

A successful attacker obtains the user's SiliconFlow API credential, not additional operating-system privileges. The attacker may consume the account's API quota, incur charges where paid models are available, and perform any API operations authorized by that credential. The scope is limited by the privileges and account restrictions ass ...[truncated 29 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace the curl subprocess with a Python HTTPS client and construct the authorization header in process memory.
  • If curl must be retained, provide sensitive configuration through standard input or another mechanism that does not expose the token in the process argument vector.
  • Ensure exception messages, HTTP diagnostics, and debug logs never include authorization headers.
  • Apply least privilege to the API key, including spending limits, operation restrictions, and rotation where supported.
  • Rotate the existing key if there is reason to believe process arguments have been collected by local monitoring or other users.

T08 · Insecure Dependencies

Note
Location
SKILL.md:26
Finding

Unpinned Package Execution in Installation Instructions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 26-30; duplicated in README.md, lines 10-14
Vulnerability Type: Unpinned third-party installer execution
Risk Level: Low

Vulnerable Code in SKILL.md:

bash
npx clawhub install siliconflow-image-gen

Equivalent Instruction in README.md:

bash
# Via ClawHub
npx clawhub install siliconflow-image-gen

Technical Analysis

The documented installation command invokes clawhub through npx without specifying a reviewed version or integrity value. If the package is not already available locally, npx may retrieve and execute the current registry release. Consequently, the installer code executed by a user can change after this project has been reviewed.

This is a supply-chain hardening weakness rather than evidence that the current clawhub package is malicious. Exploitation depends on compromise or malicious replacement of the upstream package, publisher account, or package-distribution channel.

Attack Path

  1. An attacker compromises the relevant package-publisher account, registry entry, or distribution infrastructure.
  2. The attacker publishes a modified release under the package name used by the documentation.
  3. A user follows the installation instructions and runs the unpinned npx clawhub install siliconflow-image-gen command.
  4. npx retrieves and executes the attacker-controlled package release.
  5. The malicious installer operates with the permissions of the user who launched the command.

Impact Assessment

If the upstream package is compromised, arbitrary code could execute with the installing user's privileges. Potential scope includes access to files and credentials available to that user, modification of the user's environment, and installation of additional components. This repository itself does not demonstrate such malicious behavior; the risk arises from executing mutable third-party instal ...[truncated 9 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the installer to a specific reviewed version, for example by using an explicitly versioned package reference supported by npx.
  • Document the expected official package registry and publisher identity.
  • Use lockfiles, package integrity hashes, signed releases, or provenance verification where the distribution tooling supports them.
  • Advise users to review the package source and release provenance before installation.
  • Update the installation commands in both SKILL.md and README.md so they remain consistent.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
Findings (18)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/generate.py (reported line 20)May include surrounding context.

python
DEFAULT_SIZE = "1024x1024"

def get_api_key():
    """Get API key from environment or OpenClaw config"""
    # Try environment first
    api_key = os.environ.get("SILICONFLOW_API_KEY")
    if api_key:

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The README instructs users to run npx clawhub install siliconflow-image-gen without pinning a specific version, which can result in fetching and executing whatever package version is current at install time. In a supply-chain compromise or malicious update scenario, users could unknowingly execute attacker-controlled code during installation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares access to environment variables and a local config file, and its usage instructions invoke a local Python script, but it does not declare an explicit tool/permission scope such as allowed-tools or permissions. That creates a transparency and least-privilege problem: an agent or user may approve the skill without understanding it can read secrets and execute shell-based code paths.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
83% confidence
Finding

The installation command uses npx clawhub without pinning a specific version, so the resolved package can change over time. If the upstream package is compromised, typo-squatted, or a malicious update is published, users may execute unexpected code during installation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
82% confidence
Finding

This skill is explicitly wired to send data to an external internet service. External transmission is expected for a hosted image-generation skill, but it is still a genuine security-relevant behavior because prompts may contain confidential information and data leaves the local trust boundary.

Content

Scanner excerpt · scripts/generate.py (reported line 15)May include surrounding context.

python
import subprocess

# API Configuration
API_BASE_URL = "https://api.siliconflow.cn/v1"
DEFAULT_MODEL = "black-forest-labs/FLUX.1-schnell"
DEFAULT_SIZE = "1024x1024"

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill expands its capabilities beyond image generation by invoking external executables, which increases attack surface and operational risk. While not immediately exploitable as shell injection here, subprocess use can expose secrets via process metadata, complicate sandboxing, and make later unsafe modifications more dangerous.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script transmits the user prompt and authentication token to a third-party service without any explicit disclosure or consent flow. In agent environments, prompts may contain sensitive data, so silent external transmission creates a real privacy and data-governance risk.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/generate.py (reported line 73)May include surrounding context.

python
try:
        # Make API request
        result = subprocess.run(curl_cmd, capture_output=True, text=True)
        if result.returncode != 0:
            print(json.dumps({
                "success": False,

Tainted flow: 'curl_cmd' from os.environ.get (line 62, credential/environment) → subprocess.run (code execution)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/generate.py (reported line 73)May include surrounding context.

python
try:
        # Make API request
        result = subprocess.run(curl_cmd, capture_output=True, text=True)
        if result.returncode != 0:
            print(json.dumps({
                "success": False,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/generate.py (reported line 96)May include surrounding context.

python
# Download image if output path specified
        if output_path:
            download_cmd = ["curl", "-s", "-L", "--max-time", "60", "-o", output_path, image_url]
            download_result = subprocess.run(download_cmd, capture_output=True)
            if download_result.returncode != 0:
                print(json.dumps({
                    "success": False,

Tainted flow: 'download_cmd' from os.environ.get (line 95, credential/environment) → subprocess.run (code execution)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/generate.py (reported line 96)May include surrounding context.

python
# Download image if output path specified
        if output_path:
            download_cmd = ["curl", "-s", "-L", "--max-time", "60", "-o", output_path, image_url]
            download_result = subprocess.run(download_cmd, capture_output=True)
            if download_result.returncode != 0:
                print(json.dumps({
                    "success": False,

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases are broad and likely to match normal conversational requests such as 'create image' or '画一张', causing the skill to activate in situations broader than intended. Overbroad activation can route unrelated user input into a privileged skill path, increasing the chance of unintended API use, exposure of configured secrets to the skill runtime, or invocation of dangerous capabilities such as exec.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · skill.json (reported line 15)May include surrounding context.

json
"生成图像",
      "文生图",
      "画一张",
      "create image",
      "generate image",
      "text to image"
    ]

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest grants the exec capability even though the stated functionality only requires calling an external image-generation API. exec materially expands the attack surface by allowing shell command execution, which could be abused for arbitrary command execution, file access, or secret exfiltration if the skill implementation is compromised or later modified unsafely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill description says it auto-detects an API key and later notes it may read from environment variables or OpenClaw config, which involves accessing credentials. The README does not explicitly warn users that the skill will inspect these sources for secrets, creating a mild transparency gap for privacy-sensitive behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The markdown states that generated images are automatically saved locally, which affects user data/storage, but it does not include any warning or note about where files are written by default or that the skill will create local files. Under the markdown-specific warning criteria, behaviors that affect user data or system state should be disclosed clearly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
71% confidence
Finding

The OpenClaw Agent usage example is given only in Chinese, which may imply a language-specific interaction pattern without user opt-in or explanation. The policy requires avoiding language/locale constraints unless they are optional or clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The manifest hard-codes trigger patterns in Chinese and English only, but does not state whether the skill is intentionally limited to those languages or how users in other locales should invoke it. This can conflict with language-choice expectations when no opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.