Back to skill

Security audit

Draw Images By Apiyi

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent image-generation skill, but users should treat prompts and output paths carefully because it calls APIYI, uses an API key, downloads the returned image, and writes files locally.

Install only if you are comfortable sending image prompts to APIYI and storing an APIYI key for the skill. Prefer the slash command, choose output paths deliberately, avoid sensitive prompt content, and consider running it in a restricted environment with pinned dependencies. Until the key-handling bug is fixed, rely on APIYI_API_KEY rather than the documented --api-key override.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
scripts/generate_image.py:2
Finding

Unpinned Runtime Dependencies Allow Supply-Chain Substitution

Content
View full analysis
=3.10" # dependencies = [ # "openai>=1.0.0", # "requests", # "pillow>=10.0.0", # ] # /// ``` ### Technical Analysis The script uses PEP 723 inline dependency metadata and is intended to be executed with `uv run`. The declared dependencies are not pinned to exact, audited versions: - `requests` has no version constraint. - `openai` and `pillow` have minimum versions but no upper bounds. - No lockfile or package integrity hashes are present in the audited project. Consequently, dependency resolution may install package versions that differ from those available when the skill was reviewed. Python packages execute code during installation and import, so a compromised package release, dependency-confusion event, malicious transitive dependency, or incompatible future release could execute arbitrary code. The direct package names do not appear to be typographical imitations. The risk arises from mutable dependency resolution rather than evidence that the currently named packages are malicious. ### Attack Path 1. An attacker compromises a declared package, one of its transitive dependencies, or the package distribution channel. 2. The attacker publishes a malicious version that satisfies the skill's broad dependency constraints. 3. A user invokes the documented `uv run` command in an environment where that version has not already been securely locked and cached. 4. `uv` resolves and installs the malicious or compromised release. 5. Malicious package code executes during installation or when imported by `generate_image.py`. 6. The code runs with the operating-system privileges and environment access of the user invoking the skill. ### Impact Assessment Successful exploitation could provi ...[truncated 554 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate_image.py:65
Finding

Unvalidated and Unbounded Image Download from an API-Controlled URL

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (13)

Tainted flow: 'image_url' from os.environ.get (line 70, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

The script retrieves an image URL from an external API response and then fetches it with requests.get() without validating the destination, scheme, or host. This creates a server-side request forgery style risk and can also expose the runtime to unbounded network access or downloads from attacker-controlled locations if the upstream service or response is compromised.

Content

Scanner excerpt · scripts/generate_image.py (reported line 74)May include surrounding context.

python
print(f"Image URL: {image_url}")
        
        # Download image
        img_response = requests.get(image_url)
        img_response.raise_for_status()
        
        image = PILImage.open(BytesIO(img_response.content))

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 33)May include surrounding context.

md
def get_api_key(provided_key: str | None) -> str | None:
    """Get API key from argument first, then environment."""
    if provided_key:
        return provided_key
    return os.environ.get("APIYI_API_KEY")

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/generate_image.py (reported line 28)May include surrounding context.

python
def get_api_key(provided_key: str | None) -> str | None:
    """Get API key from argument first, then environment."""
    if provided_key:
        return provided_key
    return os.environ.get("APIYI_API_KEY")

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README advertises very broad natural-language triggers such as "Draw a cute cat for me" and "Generate an image of a sunset," which overlap with ordinary user requests. In an agent environment, this can cause the skill to activate unexpectedly during unrelated conversations and perform external API calls or file writes without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 17)May include surrounding context.

Just ask:

  • "Draw a cute cat for me"
  • "Generate an image of a sunset"
  • "Can you create a picture of a robot?"

Command Line

bash

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill declares capabilities that require environment access and network use, but it does not explicitly scope or constrain those powers with a permissions or allowed-tools declaration. This increases the chance that the agent can invoke the skill in broader contexts than intended, with insufficient user visibility into secret use and outbound data flow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation omits a clear warning that user prompts are transmitted to APIYI and that generated images are written to disk at a specified path. Users may unknowingly disclose sensitive prompt content to a third party or unintentionally create local files in the workspace or absolute paths.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The natural-language trigger examples are broad, generic requests that commonly appear in normal conversation, making accidental or unintended invocation more likely. Because this skill performs a network request and writes files, over-broad routing can cause user prompts to be sent off-platform and artifacts to be created without clear consent.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

md
Just ask the agent:
- "Draw a cute cat for me"
- "Generate an image of a sunset"
- "Can you create a picture of a robot?"

### Command Line

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/generate_image.py (reported line 57)May include surrounding context.

python
client = OpenAI(
        api_key=api_key,
        base_url="https://api.apiyi.com/v1"
    )

    response = client.images.generate(

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code sends the user-provided prompt to the remote APIYI service via client.images.generate, which is a network operation that transmits user data off-system. Although the script prints status messages, it does not clearly disclose that prompt text will be sent to a third-party service; the module docstring and CLI help also omit that warning.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README states that images are saved to the current workspace directory, but the static finding notes the warning is insufficient. In an agent workspace, undisclosed or under-emphasized file writes can surprise users, overwrite expected artifacts, or leave generated content in sensitive project directories.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The CLI advertises and validates a --api-key override, but generate_image() ignores that value and reads only the environment variable. This inconsistency can cause use of the wrong credential, operational failures, or accidental reliance on ambient secrets rather than the explicit key the caller intended.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.