Back to skill

Security audit

Qwen Image Edit

Security checks for vulnerabilities and agentic risk

Overview

This is a real Qwen image tool, but it should be reviewed because it can upload prompts and local images to Alibaba Cloud and includes an option that can disable TLS protection.

Install only if you are comfortable sending prompts and any selected local images to Alibaba Cloud/DashScope. Avoid using --no-verify-ssl, prefer DASHSCOPE_API_KEY over command-line keys, and do not submit private or regulated images unless the service terms and retention rules fit your needs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate_image.py:202
Finding

TLS Certificate Verification Can Be Disabled for Sensitive API Traffic

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate_image.py:230
Finding

API Response URLs Are Downloaded Without Destination or Content Validation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (10)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/generate_image.py (reported line 32)May include surrounding context.

python
def get_api_key(provided_key: str | None) -> str | None:
    """Get API key from argument first, then environment."""
    return provided_key or os.getenv("DASHSCOPE_API_KEY")

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill invokes a script that uses environment-sourced API credentials and communicates with a remote cloud service, but the manifest does not declare any tool scope or permission boundary. This increases the chance of the skill being activated with broader-than-expected access and makes security review, least-privilege enforcement, and user understanding of data flow more difficult.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are very broad and match common requests like 'generate image', 'edit photo', or 'add text', which can cause the skill to activate in many ordinary conversations without clear user intent to use this specific remote service. In this skill's context, that matters because activation can lead to sending prompts and possibly user-supplied images to Alibaba Cloud, creating privacy and consent risks.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The repeated trigger description remains ambiguous and reinforces activation on generic image-related language rather than clearly scoped intents. Repetition of broad triggers can make accidental routing more likely, especially for a skill that may process local files and send them to a third-party API.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The usage and workflow explain how to pass local images or image URLs to the script, but they do not clearly warn users that local images will be transmitted to a remote Alibaba Cloud API for processing. Because this skill supports editing personal or proprietary images, omission of this disclosure can lead to unintentional exfiltration of sensitive visual data and compliance/privacy issues.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The --no-verify-ssl option disables TLS certificate verification for both API calls and image downloads, allowing man-in-the-middle interception or tampering with prompts, API credentials, and returned image URLs/content. Because this tool sends bearer tokens and potentially sensitive user images to a remote service, turning off certificate validation materially increases exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

In edit mode, local images are base64-encoded and included in the outbound API request payload, which sends user-provided image data and prompts to a third-party service. Although the script logs that it is generating/editing an image, it does not clearly disclose that local files and text prompts are uploaded externally.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/generate_image.py (reported line 215)May include surrounding context.

python
try:
        # Make API request
        response = requests.post(
            api_url,
            headers={
                "Content-Type": "application/json",

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The manifest describes an image creation/editing assistant, but does not mention credential discovery from the runtime environment. While using an API key is an implementation detail for a cloud image service, reading environment variables introduces a broader capability beyond the user-facing image manipulation scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The default value for --negative-prompt is hard-coded in Chinese, imposing a specific language choice on all users unless they override it manually. This is a natural-language locale preference that is not presented as an opt-in or user-selectable default.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.