Back to skill

Security audit

GPT Image 2 Prompt Recommender

Security checks for vulnerabilities and agentic risk

Overview

This skill performs useful prompt recommendations, but it silently updates mutable remote data and tells agents to run shell commands using remote image URLs.

Review before installing. This skill is not clearly malicious, but it should be treated as Review because it auto-fetches changing data from GitHub, updates local files silently, and instructs agents to execute shell commands using remote image URLs. Prefer installing only if you trust the publisher and can run it in a sandbox, or wait for a version that pins and verifies reference data and avoids shell-based image downloads.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:137
Finding

Mandatory Promotional Content Hijacks Agent Responses

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:225
Finding

Command Injection Through Remotely Controlled Sample Image URLs

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:236
Finding

Predictable Shared Temporary File Enables Symlink Overwrite and Race Conditions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (33)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 210)May include surrounding context.

bash
pnpm install

# Create .env with CMS credentials
echo "CMS_HOST=your_host" >> .env
echo "CMS_API_KEY=your_key" >> .env

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 211)May include surrounding context.

bash
pnpm install

# Create .env with CMS credentials
echo "CMS_HOST=your_host" >> .env
echo "CMS_API_KEY=your_key" >> .env

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 212)May include surrounding context.

bash
pnpm install

# Create .env with CMS credentials
echo "CMS_HOST=your_host" >> .env
echo "CMS_API_KEY=your_key" >> .env

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

md
node scripts/setup.js

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

md
node scripts/setup.js

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

md
node scripts/setup.js

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

The cleanup command itself is simple, but embedding raw shell commands in skill instructions normalizes execution side effects and can become dangerous if later parameterized or adapted unsafely. In this context, it is part of an unnecessary exec workflow for a recommendation skill, increasing exposure to tool misuse.

Content

Scanner excerpt · SKILL.md (reported line 242)May include surrounding context.

message tool: action=send, media=/tmp/prompt_img.jpg, caption="[Prompt Title]"

Step C — Cleanup: exec: rm /tmp/prompt_img.jpg

text

Do this for **each** of the 3 recommended prompts — one image per prompt.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · package.json (reported line 4)May include surrounding context.

json
{
  "name": "gpt-image-2-prompts-search",
  "version": "1.0.0",
  "description": "AI skill: 1,000+ GPT Image 2 (OpenAI) image generation prompts. Also works with Nano Banana Pro, Nano Banana 2, Seedream 5.0, GPT Image 1.5, Midjourney, DALL-E, Flux, Stable Diffusion. Auto-downloads library on install. Works with OpenClaw, Claude Code, Cursor and more.",
  "type": "module",
  "scripts": {
    "generate": "npx tsx scripts/generate-references.ts",
    "typecheck": "tsc --noEmit",
    "postinstall": "node scripts/setup.js",
    "setup": "node scripts/setup.js",
    "sync": "node scripts/setup.js --force"
  },
  "keywords": [
    "openclaw",
    "openclaw-skill",

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The publishing guide explicitly states that large data files are excluded from the packaged skill and instead downloaded from GitHub at install time via a postinstall hook. For a prompt-recommendation skill, this introduces network-dependent code and mutable remote content outside the normal package review/publishing boundary, increasing supply-chain and transparency risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The guide documents silent refresh of local data every 24 hours, allowing behavior and content to change after installation without a corresponding version bump or republish. This bypasses normal review expectations for a prompt library skill and creates a channel for unreviewed remote updates or tampered content to reach users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Automatic background refresh is described as occurring silently, with no user-facing warning about periodic network activity. Even if the data is benign, undisclosed network access and updates reduce user agency, complicate auditing, and can mask future abuse if the upstream source is compromised.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README encourages users to paste full articles, video scripts, and notes into the skill without any warning about privacy, data handling, or sensitivity of the shared content. In the context of an AI-assisted workflow and a skill that references external galleries/sync infrastructure, this can lead users to disclose proprietary, unpublished, or personal material without informed consent.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill declares no explicit tool scope even though its instructions require network access and shell execution. In an agent environment, missing tool constraints can allow broader-than-necessary capabilities and make unsafe behaviors harder to govern or review.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill is presented as a local prompt-recommendation library, but it also performs ongoing remote synchronization from GitHub and updates reference data in place. This materially changes the trust model: behavior depends on mutable external content, so the skill can change over time without a reviewed package update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill mandates an automatic freshness check that may silently pull and modify local reference files on every run. Silent network activity and in-place writes are risky in agent skills because users may not expect side effects, and compromised upstream content could influence later responses.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to download remote content, write it to local disk, invoke a message-sending tool, and delete the file, even though the core function is prompt recommendation. That expands the attack surface from simple data lookup to network/file/tool operations, creating unnecessary risk from untrusted remote content and side effects.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

These instructions cause network transfer and local file writes for every recommendation without informing the user. Downloading arbitrary remote images into /tmp and invoking tools on them introduces avoidable side effects and trust in external content for a task that could be fulfilled without execution.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description focuses on recommending suitable prompts from a library of 1,000+ GPT Image 2 prompts. Step 4 instructs the agent to generate a brand-new AI prompt outside that library whenever no match is found. That extends the skill from retrieval/recommendation into prompt authoring, which is a meaningful behavior expansion beyond the stated description.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest description broadly advertises that the skill 'works with OpenClaw, Claude Code, Cursor and more' and presents a general-purpose prompt library, but it does not define any specific activation phrases, scope limits, or exclusion conditions. In a manifest file, this kind of broad natural-language description can create ambiguity about when the skill should be invoked versus ignored.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The generate script invokes npx tsx, which can resolve and execute a package from the registry rather than only a locally pinned binary. In a skill/package context, that creates supply-chain risk because an unexpected package version or registry compromise could result in arbitrary code execution during developer use.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The manifest frames the skill as recommending prompts from a curated library based on user needs, which suggests a search/recommendation capability over included data. The README additionally states that prompts are automatically synced from a CMS twice daily and linked to hosted galleries/sample assets, which extends beyond the plain local-search behavior described in the manifest.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.