Back to skill

Security audit

wan-image-gen

Security checks for vulnerabilities and agentic risk

Overview

The skill performs its stated image-generation workflow, but it exposes a plausible DashScope API key and defaults to publishing generated images to a public host.

Review this skill carefully before installing. Do not use the embedded DashScope key; treat it as exposed, revoke it if it belongs to you, and provide your own credential only through a secure environment variable. Only use the workflow for prompts and images you are comfortable sending to Alibaba DashScope and publishing through catbox.moe as a public URL.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:70
Finding

Hard-Coded DashScope API Credential

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 70
Vulnerability Type: Hard-coded secret in published Skill documentation
Risk Level: High

Vulnerable Code Snippet:

bash
export DASHSCOPE_API_KEY="sk-ec70253d8fb14e53a679726ad2e1563c"

Technical Analysis

The complete workflow example embeds a credential-shaped DashScope API key directly in the Skill documentation. Because the key is stored as plaintext in a project file, anyone who can access the Skill package, repository history, distribution archive, or generated audit artifacts may retrieve it.

This is inconsistent with the earlier instruction to obtain the API key from the user at runtime. Secrets must not be included in documentation or source-controlled configuration, even when presented as examples. If the displayed key is valid or can be reactivated, it can be used independently of this Skill to submit authenticated requests to DashScope.

No curl | bash pipeline or remote script execution was found in the audited file. The ordinary curl commands invoke documented API and file-transfer operations rather than downloading and executing code.

Attack Path

  1. An attacker obtains a copy of SKILL.md from the Skill package, repository, cache, log, or other distribution channel.
  2. The attacker extracts the plaintext value assigned to DASHSCOPE_API_KEY.
  3. The attacker supplies the key in a DashScope Authorization: Bearer header.
  4. If the key remains valid, the attacker submits image-generation or other requests permitted by its associated account and authorization scope.
  5. The requests consume the victim account's quota and may incur charges or disrupt legitimate use.

This exploitation path does not require local code execution or system privileges; it depends on the exposed key remaining valid.

Impact Assessment

A successful attacker can obtain the DashScope API privileges granted to the exposed key. Potential ...[truncated 288 chars]

Remediation
View remediation

Remediation Suggestions

  1. Revoke the exposed DashScope API key immediately and issue a replacement through the provider's credential-management interface.

  2. Replace the literal secret with a non-secret placeholder:

    bash
    export DASHSCOPE_API_KEY="${DASHSCOPE_API_KEY}"
    

    Alternatively, omit the export command and document that the variable must be supplied securely at runtime.

  3. Store active credentials in an approved secret manager, protected runtime environment, or platform credential store. Do not place them in Skill files, examples, logs, shell history, or version control.

  4. Review repository history, release archives, caches, and published copies for the exposed key. Removing it only from the current file is insufficient if historical copies remain available.

  5. Inspect DashScope usage and billing records for unauthorized activity associated with the exposed credential.

  6. Restrict replacement credentials to the minimum API permissions and quota needed for image generation.

  7. Add automated secret scanning to pre-commit, continuous-integration, and publication workflows to prevent future credential disclosure.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill’s core workflow uploads generated images to catbox.moe, a public third-party file host, but does not clearly warn the user that content will be made publicly accessible. This can cause inadvertent disclosure of sensitive, personal, or proprietary images derived from user prompts.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

调用 DashScope 同步接口生成图片:

bash
curl --location 'https://dashscope-intl.aliyuncs.com/api/v1/services/aigc/multimodal-generation/generation' \
  --header 'Content-Type: application/json' \
  --header 'Authorization: Bearer $DASHSCOPE_API_KEY' \
  --data '{

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The operational instructions are written entirely in Chinese, which can impose a language constraint on users or operators without any opt-in or explanation that the skill is intended only for Chinese-language contexts. This matches the language/locale policy concern for natural-language content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs use of an API credential but does not include a clear safety warning about secret handling, storage, or exposure in shell history and logs. In practice, users may paste the key into commands or sessions where it can be retained, leaked, or displayed.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The example includes a real-looking DashScope API key directly in documentation, which can lead users to copy, reuse, or accidentally expose sensitive credentials. Even if illustrative, embedding a plausible secret normalizes unsafe handling of API keys and may represent an actual leaked credential.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The skill sends user-supplied prompts and the API credential to an external service, which is expected for image generation but still constitutes external data transmission. In this context, the risk is elevated because the skill does not prominently warn about third-party disclosure of prompt contents and related metadata.

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

调用 DashScope 同步接口生成图片:

bash
curl --location 'https://dashscope-intl.aliyuncs.com/api/v1/services/aigc/multimodal-generation/generation' \
  --header 'Content-Type: application/json' \
  --header 'Authorization: Bearer $DASHSCOPE_API_KEY' \
  --data '{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The example writes generated files to the local Desktop without warning the user that local files will be created. This can surprise users, overwrite files, expose content to other local users, or leave sensitive artifacts in an easily discoverable location.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.