Back to skill

Security audit

小红书卡片生成器

Security checks for vulnerabilities and agentic risk

Overview

The skill is a local image-card renderer, but several templates silently add third-party branding or security-looking claims to generated images.

Review the generated images before publishing them. This skill appears locally scoped and not credential-seeking, but users should be aware that some styles add undisclosed branding or decorative security claims and that several styles do less Markdown/detail-page rendering than the documentation implies.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

other

Warning
Location
scripts/render_bauhaus_card.py:91
Finding

Undisclosed Hard-Coded Branding in Generated Images

Content
View full analysis

Vulnerability Details

File Locations:

  • scripts/render_bauhaus_card.py:91
  • scripts/render_cyber_card.py:86
  • scripts/render_cyber_card.py:121
  • scripts/render_dreamy_card.py:100
  • scripts/render_mac_pro_card.py:106
  • scripts/render_mac_pro_card.py:139
  • scripts/render_magazine_card.py:41
  • scripts/render_polaroid_card.py:42
  • scripts/render_vintage_card.py:132
  • scripts/render_vscode_card.py:42

Vulnerability Type: Undisclosed output modification and third-party branding
Risk Level: Medium

Evidence

The following hard-coded strings are written directly into generated images:

python
# scripts/render_bauhaus_card.py:91
draw.text((100, height - 100), "BAUHAUS X XINA", font=font_footer, fill="#999999")
python
# scripts/render_cyber_card.py:86
draw.text((100, height-110), "CONNECTION: SECURE [XINA_V1.0]", font=mono_font, fill="#00FFFF")

# scripts/render_cyber_card.py:121
draw.text((width - 450, height - 100), "ENCRYPTED BY XINA", font=font_footer, fill="#FF00FF")
python
# scripts/render_dreamy_card.py:100
draw.text(((width - font_footer.getlength("DREAMY SERIES / XINA")) // 2, height - 100), "DREAMY SERIES / XINA", font=font_footer, fill="#D1D1D1")
python
# scripts/render_mac_pro_card.py:106 and 139
slogan = "Designed by MrQ × Xina"
python
# scripts/render_magazine_card.py:41
draw.text((100, 1300), "XINA / MAGAZINE ISSUE NO. 1", font=deco_font, fill="black")
python
# scripts/render_polaroid_card.py:42
draw.text((830, 100), "XINA", font=hand_font, fill="#CC0000")
python
# scripts/render_vintage_card.py:132
footer_text = f"XINA ARCHIVES / {page_info}"
python
# scripts/render_vscode_card.py:42
draw.text((120, 100), "v xina_project", font=small_font, fill="#FFFFFF")

Technical Analysis

The documented purpose of the Skill is to convert user-provided text into image ...[truncated 2490 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove all hard-coded XINA, MrQ × Xina, and related attribution strings from the renderers.
  2. Remove decorative claims such as CONNECTION: SECURE and ENCRYPTED BY XINA, or replace them with neutral text that cannot be interpreted as a factual security assertion.
  3. If attribution is legitimately required, document the exact text prominently in SKILL.md before users invoke the Skill.
  4. Make attribution opt-in through an explicit command-line option, such as --branding, with branding disabled by default.
  5. Allow users to configure or omit footer and decorative text independently of the selected visual style.
  6. Add automated image or source-level tests that fail when unapproved branding strings are introduced.
  7. Review all renderer templates for additional fixed text and ensure that every non-decorative label is either user-controlled or clearly disclosed.
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a general-purpose Markdown-to-image card renderer for Xiaohongshu content with multiple artistic styles and automatic cover/detail-page segmentation. The supplied code implements only a narrow subset: a single script that draws one static cover image template with title/subtitle and a border. There is no Markdown parsing, no pagination or segmentation logic, no detail-page rendering, and no configurable style system matching the listed examples. The code’s primary behavior is materially narrower than the declared purpose, so this is a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

描述与代码存在明显行为不一致。代码确实属于图片卡片渲染相关功能,这一点与声明大方向相符;但其核心能力被明显夸大。首先,代码没有任何风格选择、参数分支或模板切换逻辑,无法支持描述中的 Mac Pro、赛博朋克、包豪斯等多种风格,只实现了单一杂志式布局。其次,虽然定义了 detail 页渲染函数,但主程序没有调用该函数,也没有 Markdown 解析、内容分页或自动分段流程,因此“自动分段渲染封面和详情页”的声明与实际执行能力不符。整体看,这不是恶意越权问题,而是声明的产品能力显著超过了当前代码实际实现范围。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明描述的是一个较完整的知识卡片图片渲染技能,核心能力包括:多风格、Markdown 渲染、自动分段、封面与详情页输出。而实际代码只包含 render_minimal_grid_cover,一个非常具体的封面渲染函数,输入参数也是 title/subtitle/output_dir,而不是 Markdown 内容。代码没有看到任何风格选择逻辑、Markdown 解析逻辑、分页/分段逻辑,也没有详情页生成函数。因此其实际行为仅覆盖声明中很小的一部分(生成一种风格的封面图),与声明的主要能力存在明显不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The description promises a broader image-card rendering skill with multiple design styles and automatic conversion of Markdown copy into cover and detail card images. The supplied code only implements a specific polaroid-themed renderer. Although there is a helper for detail-page rendering, it is not invoked in the main program, and there is no logic for parsing Markdown into sections/pages. The code also lacks any style selection mechanism or implementations of the listed styles. This is a material description-to-behavior mismatch in primary functionality and supported capabilities.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明描述的是一个较完整的知识卡片渲染技能,核心能力包括:将 Markdown 文案转为图片卡片、支持多种视觉风格、并自动分段生成封面和详情页。实际代码只包含一个 render_split_color_cover 函数,使用固定配色和固定布局绘制单张封面图,输出文件名也固定为 split_color_cover.png。虽然这与“知识卡片附图生成”大方向相关,但功能范围明显更窄,且缺失声明中的关键能力,因此描述与实际行为存在实质性不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

代码的核心确实与“将文案生成图片卡片、自动分页渲染封面和详情页”基本相关,因此方向上是相近的。但描述中声称支持多种风格,而该代码块只实现了 render_vscode_cover 和 render_vscode_detail,即固定的 VS Code 编辑器视觉风格,没有体现 Mac Pro、赛博朋克、包豪斯等多风格能力。此外,描述说是将 Markdown 文案渲染成图片,但代码没有 Markdown 解析逻辑,只是读取文本文件、删除 emoji 和井号开头行,然后按字符宽度换行分页,属于纯文本渲染而非真正的 Markdown 渲染。综合来看,代码实现的是该技能的一个特定子风格和简化文本处理版本,未达到描述所宣称的广泛能力,因此存在描述与实际行为不一致。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description is entirely in Chinese and describes the skill's use and behavior only in that language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless a locale restriction is clearly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The code explicitly selects "/System/Library/Fonts/STHeiti Medium.ttc", a Chinese font, as the primary rendering font. This imposes a specific language/locale presentation choice in the skill behavior without any user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The script explicitly selects STHeiti, a Chinese system font, as its primary rendering font and does not provide any option for users to choose an alternative locale or font. This creates a language/locale preference baked into the skill without opt-in or explanation, which matches the policy-violation category for forced locale behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script hard-codes a specific system font (STHeiti) and later filters lines containing the Chinese term 标题, which indicates locale-specific behavior embedded in the skill. There is no user choice or documented justification for restricting behavior to this language/locale context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This file includes natural-language and locale-specific presentation choices by forcing the STHeiti font and rendering the stamp text in a fixed style, which may impose a specific language/locale behavior on all users. The policy for this category allows locale constraints only when they are clearly documented and justified or when the user is given a choice, neither of which appears in this code file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The font selection is explicitly limited to Chinese-capable macOS system fonts, and later body filtering also keys off Chinese text. This reflects a baked-in locale assumption rather than offering the user a language or locale option, which can violate language/locale policy when not documented as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The body text processing removes lines containing the Chinese term "标题", which imposes a language-specific rule in the skill logic. Because the file does not present this as a user-selected or clearly justified region-specific behavior, it is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The script creates the output directory and writes image files to disk, but there is no confirmation prompt, comment/docstring disclosure, or other user-facing warning explaining that filesystem changes will occur. For a code file, file writes can merit disclosure when the behavior is not otherwise documented in the file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The script opens and reads a file specified by the user-provided path cp, but the file contains no docstring, comment, or user-facing notice that local content will be read for processing. This is a data-access operation that should be disclosed, especially when paired with generation of derived output files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The script saves a generated image to the provided output path, which is a file write operation. Although it prints the resulting path afterward, there is no prior warning, confirmation, or descriptive docstring/comment explaining to a user that the script will create files and directories on disk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.