Back to skill

Security audit

Art Director

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent image-generation wrapper with some setup and dependency-safety caveats, but no evidence of hidden malicious behavior.

Before installing, understand that image briefs and your aesthetic file are used with a Gemini-backed generator, so do not include confidential or regulated content unless that is acceptable for your workflow. Only set NANO_BANANA_SCRIPT to a trusted local nano-banana-pro script, and prefer official package-manager or verified installation steps for uv instead of copying the printed curl-to-shell suggestion.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Warning
Location
art_director.py:301
Finding

Unsafe Remote Installer Command Recommends Piping Downloaded Code Directly into a Shell

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (10)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · aesthetic.md (reported line 3)May include surrounding context.

md
# Brand Aesthetic

<!--
This file defines your brand's visual identity. The Art Director skill reads
it on every image generation and merges it with the per-image brief written
by your calling agent.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · presets/orbital.md (reported line 3)May include surrounding context.

md
# Brand Aesthetic — Orbital

<!--
  Bold flat vector graphics in the mid-century modernist poster tradition,
  with a space-travel / scientific-diagram sensibility. Think Simon C. Page,
  Brainstorm Design, NASA travel posters, Saul Bass, Massimo Vignelli.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill advertises shell, file read/write, and environment-variable use but does not declare any explicit tool scope or allowed-tools boundary. That increases the chance an agent runtime grants broader capabilities than necessary, enabling misuse of local files, shell execution, or secrets exposure if the skill is invoked in a permissive environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs users to provide briefs and use a local aesthetic file, then forwards that content to an external image-generation service via Gemini/nano-banana-pro, but it does not clearly warn that user-provided content will leave the local environment. This can lead to unintentional disclosure of sensitive brand strategy, unpublished editorial plans, or proprietary creative direction to a third-party API.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · art_director.py (reported line 77)May include surrounding context.

python
if matches:
                        return str(matches[0])
        else:
            result = subprocess.run(
                ["find", "/usr", str(Path.home() / ".openclaw"),
                 "-name", "generate_image.py", "-path", "*/nano-banana*"],
                capture_output=True, text=True, timeout=5,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · art_director.py (reported line 210)May include surrounding context.

python
"--resolution", resolution,
    ]

    result = subprocess.run(cmd, capture_output=True, text=True)

    if result.returncode != 0:
        print("Generation failed:", file=sys.stderr)

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
90% confidence
Finding

This subprocess call launches a Python script path that can be sourced from the NANO_BANANA_SCRIPT environment variable through find_nano_banana(). Although subprocess.run is used safely without shell=True, an attacker who can control the environment or place a malicious script in a searched location can cause arbitrary code execution when batch generation runs.

Content

Scanner excerpt · art_director.py (reported line 269)May include surrounding context.

python
"--filename", str(output_path),
            "--resolution", resolution,
        ]
        result = subprocess.run(cmd, capture_output=True, text=True)

        if result.returncode != 0:
            print(f"  [ERR] failed: {result.stderr.strip().splitlines()[-1] if result.stderr else 'unknown error'}")

Tainted flow: 'cmd' from os.environ.get (line 263, credential/environment) → subprocess.run (code execution)

Medium
Category
Data Flow
Confidence
95% confidence
Finding

There is a tainted flow from environment-controlled input to code execution: NANO_BANANA_SCRIPT is accepted as a candidate executable path and later passed to uv run. In an agent/skill context, environment variables are often externally influenced, so this creates a realistic arbitrary code execution path if an attacker can set env vars or shape the filesystem.

Content

Scanner excerpt · art_director.py (reported line 269)May include surrounding context.

python
"--filename", str(output_path),
            "--resolution", resolution,
        ]
        result = subprocess.run(cmd, capture_output=True, text=True)

        if result.returncode != 0:
            print(f"  [ERR] failed: {result.stderr.strip().splitlines()[-1] if result.stderr else 'unknown error'}")

External Script Fetching

Low
Category
Supply Chain
Confidence
15% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · art_director.py (reported line 304)May include surrounding context.

python
if shutil.which("uv"):
        print("[OK] uv is available")
    else:
        print("[ERR] uv not found -- install: curl -LsSf https://astral.sh/uv/install.sh | sh")
        problems.append("uv")

    aesthetic = load_aesthetic()

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The anchor phrase "Like the diagrams in Japanese camera manuals" introduces a locale-specific stylistic constraint in the skill instructions. Under the policy, language or locale restrictions should be optional or clearly justified; here the locale reference is presented as a required aesthetic influence without any user choice or rationale.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.