Back to skill

Security audit

Book Cover Generator

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it claims, but it handles an API token and sends prompts to an external image service with under-disclosed provider and credential-handling risks.

Review this before installing. Use a disposable or least-privileged API token, avoid putting long-lived secrets directly in shell commands, do not submit confidential manuscript material unless you accept transmission to the external image provider, and prefer a pinned or ClawHub-verified install path over the unpinned npx command.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
bookcovergenerator.js:4
Finding

API Token Exposed Through Command-Line Arguments

Content
View full analysis
). Pass it via the `--token` flag. ```bash node
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:31
Finding

Unpinned Package Execution Through npx Installation Command

Content
View full analysis
Remediation
View remediation
add omactiengartelle/book-cover-generator ``` 2. Where supported, pin the skill source to an immutable commit hash or verified release rather than a mutable repository name or branch. 3. Publish and verify cryptographic checksums, signatures, or package-lock integrity metadata for distributed installation artifacts. 4. Document a manual installation method that allows users to inspect downloaded files before executing any installer. 5. Periodically audit the pinned installer version and only update it after security review. 6. Advise users not to run installation commands as root or an administrator and to use a minimally privileged environment. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented purpose and declared API usage do not match the observed behavior described by static analysis, including use of a different external API and broader image-generation/editing capabilities than disclosed. This is dangerous because users may provide prompts, tokens, or reference-image data under false assumptions about where their data is sent and what operations are performed, creating consent, privacy, and trust-boundary failures.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README states that user descriptions and optional reference identifiers are sent to a third-party image-generation API, but it does not warn users about privacy, retention, or data-sharing implications. In this skill's context, prompts may contain unpublished manuscript details, character concepts, or other sensitive creative material, so omission of disclosure can lead to unintentional data exposure to an external service.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The README instructs users to install and run tooling via npx skills without pinning a specific version. This creates a supply-chain risk because users may fetch and execute whatever package version is current at install time, including a compromised or malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The second unpinned npx skills reference reinforces the same supply-chain exposure by normalizing execution of a mutable package from a remote registry. If the referenced package or dependency chain is hijacked, users could execute attacker-controlled code during setup.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs users to pass an API token on the command line without warning about credential sensitivity. Command-line secrets can leak through shell history, process listings, logs, screenshots, and support transcripts, so the lack of handling guidance materially raises the risk of credential exposure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The phrase "Use when someone asks to generate or create ai book cover generator images" does not define clear trigger boundaries and uses generic wording like "generate or create" that could overlap with many ordinary image-generation requests. It lacks constraints or negative examples clarifying when this skill should be selected instead of a general image tool.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code instructs users to obtain a token from Neta, yet authenticates requests using that token against a different backend. This can cause users to disclose credentials under false pretenses and may lead to unauthorized use, account confusion, or token harvesting if the mismatch is intentional or later abused.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This code sends user-supplied content and authentication material to an external domain. External transmission alone can be expected for an image-generation skill, but here it is dangerous because the destination conflicts with the advertised provider, making the network exfiltration materially deceptive rather than merely functional.

Content

Scanner excerpt · bookcovergenerator.js (reported line 103)May include surrounding context.

js
}

  // Submit job
  const submitRes = await request("POST", "https://api.talesofai.com/v3/make_image", body);

  let taskUuid;
  if (typeof submitRes === "string") {

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill metadata and user-facing description claim it uses the Neta AI API, but the implementation sends prompts and credentials to api.talesofai.com instead. This mismatch defeats informed consent, can mislead users about who receives their data and token, and is especially risky because the token guidance also points users to a different service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill transmits the user's prompt and authentication token to an external service without any meaningful runtime disclosure or consent messaging beyond requiring a token argument. In a content-generation skill, prompts may contain sensitive manuscript details, and sending them to an undisclosed or mismatched provider increases privacy and trust risks.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The polling request continues transmitting authenticated requests to the same undisclosed third-party service to retrieve job results. While polling is normal behavior, it extends the exposure of user credentials and activity metadata to a provider different from the one users were told they were using.

Content

Scanner excerpt · bookcovergenerator.js (reported line 122)May include surrounding context.

js
const pollRes = await request(
      "GET",
      `https://api.talesofai.com/v1/artifact/task/${taskUuid}`,
      null
    );

Static analysis

No suspicious patterns detected.