Back to skill

Security audit

HY Image Generation

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a real Tencent Cloud image-generation helper, but it automatically installs an unpinned Python SDK during normal use while handling cloud credentials and user prompts.

Install only if you are comfortable sending prompts and reference image URLs to Tencent Cloud and with the skill installing the Tencent Cloud Python SDK at runtime. Prefer running it in an isolated environment with preinstalled, pinned dependencies and Tencent Cloud credentials scoped only to the needed image-generation permissions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
scripts/main.py:14
Finding

Unpinned Automatic Dependency Installation at Runtime

Content
View full analysis

Vulnerability Details

File Locations:

  • scripts/main.py:14-24
  • scripts/submit_job.py:13-23
  • scripts/query_job.py:14-24

Vulnerability Type: Runtime installation of an unpinned third-party dependency
Risk Level: Medium

Vulnerable Code:

python
def ensure_dependencies():
    try:
        import tencentcloud  # noqa: F401
    except ImportError:
        print("[INFO] tencentcloud-sdk-python not found. Installing...", file=sys.stderr)
        subprocess.check_call(
            [sys.executable, "-m", "pip", "install", "tencentcloud-sdk-python", "-q"],
            stdout=sys.stderr,
            stderr=sys.stderr,
        )
        print("[INFO] tencentcloud-sdk-python installed successfully.", file=sys.stderr)


ensure_dependencies()

Equivalent dependency-installation logic is executed during module initialization in all three listed scripts.

Technical Analysis

When the tencentcloud module is unavailable, each executable entry point invokes pip to download and install tencentcloud-sdk-python. The dependency is not pinned to a reviewed version and no cryptographic hash is required. Pip also uses the runtime environment's configured package indexes and resolves transitive dependencies dynamically.

This makes the effective code executed by the Skill mutable after the audited package has been published. A compromised upstream release, malicious package-index mirror, unsafe pip configuration, or compromised transitive dependency could introduce attacker-controlled code. Package installation and subsequent imports occur in the same process environment that later accesses Tencent Cloud credentials.

Although the automatic installation behavior is documented in SKILL.md, that disclosure does not provide version integrity or protect the dependency supply chain.

Attack Path

  1. A user or Agent invokes main.py, submit_job.py, or `query_job. ...[truncated 1623 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove automatic package installation from all runtime entry points. If the dependency is absent, terminate with a clear setup error instead of invoking pip.

  2. Declare dependencies in a committed lock file, package metadata, or deployment manifest.

  3. Pin tencentcloud-sdk-python and every transitive dependency to versions that have been reviewed and tested.

  4. Record and enforce cryptographic hashes, such as through:

    bash
    python -m pip install --require-hashes -r requirements.txt
    
  5. Install dependencies during a controlled build or deployment phase rather than while processing a user request.

  6. Use an isolated virtual environment or immutable container image containing preinstalled dependencies.

  7. Restrict dependency retrieval to an approved package repository and verify package provenance where supported.

  8. Run the Skill with least privilege and provide Tencent Cloud credentials restricted to only the required AI image-generation operations.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description says the skill generates images (text-to-image / image-to-image). However, this code only checks the status of an already-submitted text-to-image task using QueryTextToImageJob, optionally polling until completion, and then returns the result metadata/image URL. There is no code to create a generation task, no handling of image-to-image inputs, and no direct image generation logic. The runtime SDK installation is a supporting detail rather than the main mismatch, but the primary purpose is materially different: job querying/monitoring rather than image generation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill declares executable shell and environment-variable capabilities but does not constrain them with an explicit tool scope such as allowed-tools or permissions. That creates an overly broad execution surface: an agent following the instructions may run shell commands, access secrets from the environment, and install packages without policy-level restriction, increasing the risk of unintended command execution or credential exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly tells the agent to execute without confirmation while omitting any notice that prompts and image URLs will be transmitted to Tencent Cloud. That combination creates a privacy and consent problem: sensitive text, proprietary prompts, or private image URLs could be sent to a third-party service automatically, and users are not warned before the transfer occurs.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger condition is broad enough that an agent could invoke the skill whenever a user provides descriptive text that seems image-related, without strong exclusion rules or consent gates. In practice, this can cause external API calls with user content and referenced image URLs in situations where the user did not clearly intend remote processing or paid cloud usage.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/submit_text_to_image_api.md (reported line 15)May include surrounding context.

md
## 输入参数

| 参数名称       | 必选  | 类型              | 描述                                                                                                   |
| ---------- | --- | --------------- | ---------------------------------------------------------------------------------------------------- |
| Prompt     | 是   | String          | 文本描述。算法将根据输入的文本智能生成与之相关的图像。建议详细描述画面主体、细节、场景等,文本描述越丰富,生成效果越精美。不能为空,推荐使用中文。最多可传 8192 个 utf-8 字符。       |
| Images     | 否   | Array of String | 垫图 URL 列表。用于引导生成方向,base64 后大小不超过 10MB。支持 jpg、jpeg、png、webp 格式,最多 3 张图。示例值:`["https://xxx.jpeg"]`     |

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Installing Python packages at runtime expands the skill's capability beyond image generation into software modification and indirect code execution. In this context, the behavior is more dangerous because the skill may run in an automated agent environment with privileged credentials and network access, so a compromised package index, malicious dependency, or manipulated pip configuration could lead to broader host compromise.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
95% confidence
Finding

The script invokes pip at runtime to install a package, which introduces a package-management and code-execution path during normal skill execution. Even though the command is fixed and does not use shell interpolation, it still trusts the runtime Python/pip environment and external package sources, creating supply-chain and environment-manipulation risk that is unnecessary for a simple image-generation skill.

Content

Scanner excerpt · scripts/main.py (reported line 19)May include surrounding context.

python
import tencentcloud  # noqa: F401
    except ImportError:
        print("[INFO] tencentcloud-sdk-python not found. Installing...", file=sys.stderr)
        subprocess.check_call(
            [sys.executable, "-m", "pip", "install", "tencentcloud-sdk-python", "-q"],
            stdout=sys.stderr,
            stderr=sys.stderr,

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Installing Python packages at runtime is not necessary for querying an image-generation job and introduces avoidable remote code execution and supply-chain risk. In a skill context, this is more dangerous because execution may happen automatically in privileged or semi-trusted automation environments where outbound package installation is unexpected and hard to audit.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
92% confidence
Finding

The script automatically invokes pip at runtime to install a dependency, which executes code fetched from an external package index during normal operation. Even though the command is hardcoded and does not use shell=True, this still expands the trust boundary, enables supply-chain compromise if the package or index path is tampered with, and allows unexpected networked code execution in environments that expect skills to be self-contained.

Content

Scanner excerpt · scripts/query_job.py (reported line 19)May include surrounding context.

python
import tencentcloud  # noqa: F401
    except ImportError:
        print("[INFO] tencentcloud-sdk-python not found. Installing...", file=sys.stderr)
        subprocess.check_call(
            [sys.executable, "-m", "pip", "install", "tencentcloud-sdk-python", "-q"],
            stdout=sys.stderr,
            stderr=sys.stderr,

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Auto-installing Python packages at runtime is risky because it causes the skill to fetch and execute third-party code during normal operation, which is not necessary for safely submitting an image-generation job. In this context, the behavior is more concerning because the skill may run in privileged agent environments where package installation can alter shared runtimes or introduce malicious code if the supply chain is compromised.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
93% confidence
Finding

The script executes a pip install at runtime via subprocess when the SDK is missing. Although the command is not built from user input, it still performs network-based code installation and execution in the current environment, which expands the attack surface through dependency confusion, compromised package indexes, or unexpected environment mutation.

Content

Scanner excerpt · scripts/submit_job.py (reported line 18)May include surrounding context.

python
import tencentcloud  # noqa: F401
    except ImportError:
        print("[INFO] tencentcloud-sdk-python not found. Installing...", file=sys.stderr)
        subprocess.check_call(
            [sys.executable, "-m", "pip", "install", "tencentcloud-sdk-python", "-q"],
            stdout=sys.stderr,
            stderr=sys.stderr,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script silently installs a package after only an informational log, without explicit user confirmation. This can surprise operators, modify the host environment, and trigger execution of unreviewed package-install hooks, making it unsafe in automated or multi-tenant agent contexts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file begins with a fully Chinese title and the entire document is written only in Chinese, with no indication that other languages are supported or that the Chinese-only presentation is a region-specific requirement. Under the policy criteria, natural-language content that effectively forces a specific language without user opt-in can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Line L17 states '推荐使用中文', which steers users toward a specific language. Under the policy, language constraints should either be optional, user-selected, or clearly justified as region-specific; this recommendation provides no such opt-in or rationale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The argument help string states 'Chinese recommended', which nudges users toward a specific language/locale in natural-language guidance. The file does not pair this with an explicit user choice or explain a required region-specific constraint, so it fits the locale-policy category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code emits user-facing guidance and status descriptions in Chinese/English mixed form, such as setup steps and task status labels, but does not provide any user opt-in or locale selection. That can violate a language/locale policy when users are implicitly forced into a specific language presentation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.