Back to skill

Security audit

青萍 AI 平台

Security checks across malware telemetry and agentic risk

Overview

This Qingping image-generation skill does what it says, but its downloader is under-contained because it trusts API-returned file names and URLs when writing files locally.

Install only if you trust the Qingping/lusyoe service with your prompts and API-key-backed usage. Prefer a revocable API key, avoid placing it in shared shell profiles, and be aware that this version should ideally sanitize returned filenames and restrict downloads to expected HTTPS image domains before writing files locally.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The manifest description advertises very broad trigger phrases such as generic image-generation requests and keyword matching for '生成图片' / 'AI生图', which can cause the skill to activate in situations beyond explicit user intent. This increases the chance of overbroad routing to a third-party service and unintended transmission of user prompts to an external API.

Natural-Language Policy Violations

Medium
Confidence
78% confidence
Finding
The description is written to center Chinese-language behavior and Chinese keywords without stating that language selection follows user preference, which can lead to unexpected language routing or responses. While not a direct code-execution issue, it can degrade user control and increase the likelihood of unintended invocation in multilingual contexts.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.