other
- Location
scripts/render_bauhaus_card.py:91- Finding
Undisclosed Hard-Coded Branding in Generated Images
- Content
View full analysis
Vulnerability Details
File Locations:
scripts/render_bauhaus_card.py:91scripts/render_cyber_card.py:86scripts/render_cyber_card.py:121scripts/render_dreamy_card.py:100scripts/render_mac_pro_card.py:106scripts/render_mac_pro_card.py:139scripts/render_magazine_card.py:41scripts/render_polaroid_card.py:42scripts/render_vintage_card.py:132scripts/render_vscode_card.py:42
Vulnerability Type: Undisclosed output modification and third-party branding
Risk Level: MediumEvidence
The following hard-coded strings are written directly into generated images:
python # scripts/render_bauhaus_card.py:91 draw.text((100, height - 100), "BAUHAUS X XINA", font=font_footer, fill="#999999")python # scripts/render_cyber_card.py:86 draw.text((100, height-110), "CONNECTION: SECURE [XINA_V1.0]", font=mono_font, fill="#00FFFF") # scripts/render_cyber_card.py:121 draw.text((width - 450, height - 100), "ENCRYPTED BY XINA", font=font_footer, fill="#FF00FF")python # scripts/render_dreamy_card.py:100 draw.text(((width - font_footer.getlength("DREAMY SERIES / XINA")) // 2, height - 100), "DREAMY SERIES / XINA", font=font_footer, fill="#D1D1D1")python # scripts/render_mac_pro_card.py:106 and 139 slogan = "Designed by MrQ × Xina"python # scripts/render_magazine_card.py:41 draw.text((100, 1300), "XINA / MAGAZINE ISSUE NO. 1", font=deco_font, fill="black")python # scripts/render_polaroid_card.py:42 draw.text((830, 100), "XINA", font=hand_font, fill="#CC0000")python # scripts/render_vintage_card.py:132 footer_text = f"XINA ARCHIVES / {page_info}"python # scripts/render_vscode_card.py:42 draw.text((120, 100), "v xina_project", font=small_font, fill="#FFFFFF")Technical Analysis
The documented purpose of the Skill is to convert user-provided text into image ...[truncated 2490 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove all hard-coded
XINA,MrQ × Xina, and related attribution strings from the renderers. - Remove decorative claims such as
CONNECTION: SECUREandENCRYPTED BY XINA, or replace them with neutral text that cannot be interpreted as a factual security assertion. - If attribution is legitimately required, document the exact text prominently in
SKILL.mdbefore users invoke the Skill. - Make attribution opt-in through an explicit command-line option, such as
--branding, with branding disabled by default. - Allow users to configure or omit footer and decorative text independently of the selected visual style.
- Add automated image or source-level tests that fail when unapproved branding strings are introduced.
- Review all renderer templates for additional fixed text and ensure that every non-decorative label is either user-controlled or clearly disclosed.
- Remove all hard-coded
