Back to skill

Security audit

Barbie Style Generator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward external image-generation helper, with privacy and installation hygiene risks but no artifact-backed malicious behavior.

Install only from a source you trust, prefer a pinned or verified install path when available, and avoid putting sensitive personal details, confidential prompts, or reusable secrets into image prompts. Treat the API token as a secret and prefer environment-variable or secret-manager handling over typing it directly into command history.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:31
Finding

Unpinned third-party installer and mutable Skill source

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
barbiestylegenerator.js:5
Finding

API token accepted through command-line arguments

Content
View full analysis
). Pass it via the `--token` flag. ```bash node
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The documented behavior says the skill uses the Neta AI API, but the analysis indicates the actual backend is a different service (api.talesofai.com) and that additional inheritance/editing behavior exists beyond the stated purpose. Misrepresenting the remote service materially changes the data-sharing and trust model, and can mislead users into sending prompts, tokens, or image references to an unexpected third party.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README explicitly instructs users to send free-form prompts and optional reference identifiers to a third-party image generation API, but it does not warn that this data leaves the local environment or may be retained, logged, or processed externally. In a skill aimed at identity-play and portrait generation, prompts and reference IDs could contain personal, sensitive, or proprietary information, making the omission a meaningful privacy and data-sharing risk.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill declares only the Bash tool and does not define an explicit tool scope or permissions boundary, even though the documented workflow depends on outbound network access to an external image API. This creates an under-specified trust boundary: users and orchestrators cannot easily tell that prompts, tokens, and optional reference identifiers may be transmitted off-platform.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The markdown does not warn that user prompts and optional reference image identifiers are sent to an external image-generation API. In a creative portrait skill, users may provide sensitive identity, appearance, or private image context, so the lack of disclosure increases privacy and consent risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation guidance says to use the skill when someone asks to generate or create 'barbie style ai photo generator images,' but it does not define specific trigger phrases, boundaries, or exclusion cases. This broad natural-language condition could overlap with ordinary image-generation requests and cause unintended invocation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

The install command uses an unpinned npx skills invocation, which can fetch and execute whatever package version is current at runtime. That introduces supply-chain risk because a compromised or changed upstream package could execute arbitrary code during installation or update without review.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The hardcoded external destination indicates the skill always transmits data to an internet-hosted service outside the local environment. In this skill context that is functional behavior, but it remains dangerous because users may assume a different provider based on the metadata, while their prompt and token are actually sent to api.talesofai.com.

Content

Scanner excerpt · barbiestylegenerator.js (reported line 60)May include surrounding context.

js
console.error("Generating Barbie-style image...");

const makeRes = await fetch("https://api.talesofai.com/v3/make_image", {
  method: "POST",
  headers,
  body: JSON.stringify(body),

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The hardcoded external destination indicates the skill always transmits data to an internet-hosted service outside the local environment. In this skill context that is functional behavior, but it remains dangerous because users may assume a different provider based on the metadata, while their prompt and token are actually sent to api.talesofai.com.

Content

Scanner excerpt · barbiestylegenerator.js (reported line 60)May include surrounding context.

js
console.error("Generating Barbie-style image...");

const makeRes = await fetch("https://api.talesofai.com/v3/make_image", {
  method: "POST",
  headers,
  body: JSON.stringify(body),

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · barbiestylegenerator.js (reported line 91)May include surrounding context.

js
await new Promise((r) => setTimeout(r, POLL_INTERVAL_MS));

  const pollRes = await fetch(
    `https://api.talesofai.com/v1/artifact/task/${taskUuid}`,
    { headers }
  );

Vague Triggers

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This is a manifest file, so trigger-language quality applies. The description only says "Barbie Style Generator — AI-powered barbie style ai photo generator" and does not define any specific activation phrases, scope limits, or exclusion conditions, which can make invocation matching overly broad or ambiguous.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.