T09 · Insecure Skill Coding Practices
- Location
bookcovergenerator.js:4- Finding
API Token Exposed Through Command-Line Arguments
- Content
View full analysis
). Pass it via the `--token` flag. ```bash node- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly does what it claims, but it handles an API token and sends prompts to an external image service with under-disclosed provider and credential-handling risks.
Review this before installing. Use a disposable or least-privileged API token, avoid putting long-lived secrets directly in shell commands, do not submit confidential manuscript material unless you accept transmission to the external image provider, and prefer a pinned or ClawHub-verified install path over the unpinned npx command.
bookcovergenerator.js:4API Token Exposed Through Command-Line Arguments
SKILL.md:31Unpinned Package Execution Through npx Installation Command
The documented purpose and declared API usage do not match the observed behavior described by static analysis, including use of a different external API and broader image-generation/editing capabilities than disclosed. This is dangerous because users may provide prompts, tokens, or reference-image data under false assumptions about where their data is sent and what operations are performed, creating consent, privacy, and trust-boundary failures.
The README states that user descriptions and optional reference identifiers are sent to a third-party image-generation API, but it does not warn users about privacy, retention, or data-sharing implications. In this skill's context, prompts may contain unpublished manuscript details, character concepts, or other sensitive creative material, so omission of disclosure can lead to unintentional data exposure to an external service.
The README instructs users to install and run tooling via npx skills without pinning a specific version. This creates a supply-chain risk because users may fetch and execute whatever package version is current at install time, including a compromised or malicious update.
The second unpinned npx skills reference reinforces the same supply-chain exposure by normalizing execution of a mutable package from a remote registry. If the referenced package or dependency chain is hijacked, users could execute attacker-controlled code during setup.
The skill instructs users to pass an API token on the command line without warning about credential sensitivity. Command-line secrets can leak through shell history, process listings, logs, screenshots, and support transcripts, so the lack of handling guidance materially raises the risk of credential exposure.
The phrase "Use when someone asks to generate or create ai book cover generator images" does not define clear trigger boundaries and uses generic wording like "generate or create" that could overlap with many ordinary image-generation requests. It lacks constraints or negative examples clarifying when this skill should be selected instead of a general image tool.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The code instructs users to obtain a token from Neta, yet authenticates requests using that token against a different backend. This can cause users to disclose credentials under false pretenses and may lead to unauthorized use, account confusion, or token harvesting if the mismatch is intentional or later abused.
This code sends user-supplied content and authentication material to an external domain. External transmission alone can be expected for an image-generation skill, but here it is dangerous because the destination conflicts with the advertised provider, making the network exfiltration materially deceptive rather than merely functional.
}
// Submit job
const submitRes = await request("POST", "https://api.talesofai.com/v3/make_image", body);
let taskUuid;
if (typeof submitRes === "string") {
The skill metadata and user-facing description claim it uses the Neta AI API, but the implementation sends prompts and credentials to api.talesofai.com instead. This mismatch defeats informed consent, can mislead users about who receives their data and token, and is especially risky because the token guidance also points users to a different service.
The skill transmits the user's prompt and authentication token to an external service without any meaningful runtime disclosure or consent messaging beyond requiring a token argument. In a content-generation skill, prompts may contain sensitive manuscript details, and sending them to an undisclosed or mismatched provider increases privacy and trust risks.
The polling request continues transmitting authenticated requests to the same undisclosed third-party service to retrieve job results. While polling is normal behavior, it extends the exposure of user credentials and activity metadata to a provider different from the one users were told they were using.
const pollRes = await request(
"GET",
`https://api.talesofai.com/v1/artifact/task/${taskUuid}`,
null
);
No suspicious patterns detected.