Back to skill

Security audit

migu-ai-creative-photo

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Migu creative-photo client that uploads user-approved photos to the stated service and uses documented token/session files for that purpose.

Install only if you are comfortable sending selected portraits, gender/category, scenic-place text, and a Migu JWT to gulangyu.migudm.cn. Keep the JWT file private, avoid sharing the skill directory with other users, and confirm uploads before each generation request.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill declares no explicit tool scope or allowed-tools policy even though it documents use of environment-based token inputs such as MIGU_AI_CREATIVE_PHOTO_TOKEN and related variables. Without a declared scope boundary, an agent runtime may expose broader environment access than intended, increasing the chance of secret leakage or misuse of ambient credentials. In this context, the skill handles JWTs and uploads user photos to a third-party service, so unclear permissions are more sensitive than in a purely local or read-only skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The natural-language content of the skill, including description, workflow, safety guidance, and output instructions, is presented only in Chinese. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script automatically sources bearer tokens from multiple places including local files, environment variables, and a default secrets path, which expands access to credentials beyond the immediate photo-generation action. In a skill context, this increases the chance of unintended credential use or leakage, especially because the token is then sent to a remote service and can also be persisted for later reuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The upload and generation paths send user-provided image data and related inputs to a remote third-party service, but the script provides no user-facing disclosure or confirmation at the time of transmission. Because this skill specifically processes personal photos, the privacy sensitivity is elevated and users may not realize their images leave the local environment.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The standalone token-saving, token-checking, and diagnostics features are not required to generate creative photos and materially broaden the script's handling of sensitive authentication data. They create extra pathways for storing, inspecting, and reusing bearer tokens on disk, which raises the risk of credential exposure or misuse if the skill is invoked in a broader agent environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The script silently reads authentication material from environment variables and token files without notifying the user that sensitive credentials are being accessed and used. While this is common in CLI tooling, in an agent skill it can blur the boundary between user intent and background credential consumption, increasing the risk of surprising or unauthorized account use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The script persists session state to disk and, elsewhere, can also persist tokens, without clear disclosure that local files will be created under the skill directory. This can leave sensitive or stateful artifacts behind that are later accessible to other local users, processes, or future runs.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.