Back to skill

Security audit

Kpop Idol Generator

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real K-pop portrait generator, but it needs review because its documented install and token-handling patterns create avoidable security risk.

Review before installing. Do not pass a real API token literally on the command line unless you accept the local exposure risk; prefer a safer token mechanism if the author adds one, and rotate any token that may have appeared in logs or shell history. Treat prompts and reference UUIDs as data sent to the Neta/TalesOfAI service, and avoid submitting sensitive personal, proprietary, or regulated content. Use a pinned, reviewed installer version instead of the unpinned npx command where possible.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
kpopidolgenerator.js:13
Finding

API Token Exposed Through Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: kpopidolgenerator.js:13-24
Vulnerability Type: API credential exposure through process arguments
Risk Level: Medium

Vulnerable Code

javascript
function parseArgs(argv) {
  const args = { _: [] };
  for (let i = 0; i < argv.length; i++) {
    const a = argv[i];
    if (a === '--size')       args.size  = argv[++i];
    else if (a === '--token') args.token = argv[++i];
    else if (a === '--ref')   args.ref   = argv[++i];
    else if (a === '--help' || a === '-h') args.help = true;
    else args._.push(a);
  }
  return args;
}

The insecure invocation method is also explicitly recommended in SKILL.md:15-19, SKILL.md:25, README.md:20-24, and README.md:66-73:

bash
node kpopidolgenerator.js "your prompt" --token YOUR_TOKEN

Technical Analysis

The Skill requires the Neta API credential to be supplied using the --token command-line option. Command-line arguments are not a suitable secret-delivery mechanism because they may be exposed through:

  • Shell command history.
  • Process inspection utilities and operating-system process metadata.
  • Terminal transcripts and session recordings.
  • CI/CD logs and automation diagnostics.
  • Monitoring or endpoint-management agents that collect process command lines.

The token is legitimately transmitted over HTTPS to https://api.talesofai.com as an x-token header for image generation and task polling. That network transmission is necessary for the declared hosted API functionality. The vulnerability is the local handling of the token through process.argv, not the authenticated API request itself.

No evidence was found that the token is intentionally transmitted to an unrelated service, persisted by the script, or printed directly by the script.

Attack Path

  1. A user follows the documented instructions and invokes the Skill with --token YOUR_TOKEN.
  2. The complet ...[truncated 949 chars]
Remediation
View remediation

Remediation Suggestions

  1. Read the token from a protected environment variable by default:

    javascript
    const TOKEN = process.env.NETA_TOKEN;
    

    Document usage without placing the secret in the command line:

    bash
    export NETA_TOKEN="..."
    node kpopidolgenerator.js "your prompt"
    
  2. For interactive use, support reading the token from a masked prompt or standard input without echoing it.

  3. If --token must remain for compatibility, mark it as deprecated and display a warning that command-line secrets may be visible in history and process listings.

  4. Update README.md, SKILL.md, and built-in help text so the recommended workflow uses NETA_TOKEN or protected standard input.

  5. Advise affected users to remove previously entered literal tokens from shell histories and rotate credentials that may have appeared in logs.

  6. Ensure errors and diagnostic output never include request headers or the token.

T08 · Insecure Dependencies

Warning
Location
README.md:11
Finding

Unpinned Third-Party Package Execution in Installation Instructions

Content
View full analysis

Vulnerability Details

File Location: README.md:11-13
Vulnerability Type: Unpinned package execution and supply-chain exposure
Risk Level: Medium

Vulnerable Code

bash
npx skills add omactiengartelle/kpop-idol-generator

The same installation command is present in SKILL.md:31-34.

Technical Analysis

The installation instructions use npx to resolve and execute the skills package without specifying a reviewed version or integrity constraint. Depending on the local npm configuration and cache state, npx may download the currently resolved package from the configured registry and immediately execute its code.

Because the package version is mutable from the installer’s perspective, the effective installer code may differ from the version reviewed when these instructions were authored. A compromised maintainer account, malicious future release, registry compromise, or unsafe registry configuration could therefore turn the documented installation command into an arbitrary code-execution path.

The project’s own package.json does not declare runtime dependencies, and no malicious dependency was identified in the audited project files. The finding concerns the unpinned external installer invoked by the documentation.

Attack Path

  1. An attacker compromises the publishing account, package source, registry path, or a future release of the unpinned skills package.
  2. The attacker publishes a package version containing malicious CLI or lifecycle code.
  3. A user follows the project documentation and runs the unpinned npx skills add ... command.
  4. npx resolves and downloads the attacker-controlled release.
  5. The malicious package executes with the privileges and environment of the user running the installation command.
  6. The payload may access files, credentials, environment variables, network resources, or other assets available to that user.

Impact Assessment

Successful ...[truncated 497 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the installer to a specifically reviewed version:

    bash
    npx --yes skills@REVIEWED_VERSION add omactiengartelle/kpop-idol-generator
    
  2. Document the exact package version, expected registry, and release provenance.

  3. Where supported, verify package integrity or signatures before execution.

  4. Prefer installing a pinned dependency and invoking its local binary rather than downloading and executing mutable code in one step.

  5. Use lockfiles and reproducible installation procedures in automated environments.

  6. In CI/CD systems, execute installation with a dedicated least-privilege account and avoid exposing unrelated deployment credentials to the installer process.

  7. Keep the installation commands in README.md and SKILL.md synchronized so both use the same pinned and reviewed package version.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared behavior says the skill uses the Neta API, but the analysis indicates it actually calls a different external service and supports additional behavior not transparently disclosed. This is dangerous because users may provide prompts, tokens, or reference-image identifiers under false assumptions about where their data goes and how it is processed, creating a trust-boundary and potential credential or privacy exposure.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README instructs users to send free-form prompts and optional reference-image UUIDs to a third-party image-generation API, but it does not clearly warn that user content will leave the local environment and be processed by an external service. This creates a privacy and data-handling risk because users may unknowingly transmit sensitive descriptions, personal data, or identifiers to a remote provider.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill declares only Bash tooling and does not constrain network-capable behavior with an explicit tool scope or permissions model, even though the described functionality depends on external API access. That makes the effective capability boundary unclear to users and reviewers, and increases the risk of unexpected outbound requests or future code changes silently expanding what the skill can do.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

The manifest description and heading-positioned description direct the skill toward "k-pop," "korean beauty looks," and related locale-specific aesthetics as the default behavior. Under the policy, forcing a specific language or locale style without offering user choice or clearly documenting a justified regional constraint can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

The installation instruction uses an unpinned 'npx skills' reference, which can pull whatever package version is current at install time. This creates a supply-chain risk: a compromised, replaced, or later-malicious package version could be installed and executed without the user realizing it.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The default prompt suffix forcibly appends descriptors like "korean beauty aesthetic" to every user prompt, imposing a specific cultural/locale styling regardless of the user's request. This is a natural-language policy concern because the skill does not offer any language/locale or cultural-style choice or opt-in.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · kpopidolgenerator.js (reported line 57)May include surrounding context.

js
body.inherit_params = { collection_uuid: ref, picture_uuid: ref };
  }

  const res = await fetch("https://api.talesofai.com/v3/make_image", {
    method: "POST",
    headers: {
      "x-token": token,

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · kpopidolgenerator.js (reported line 57)May include surrounding context.

js
body.inherit_params = { collection_uuid: ref, picture_uuid: ref };
  }

  const res = await fetch("https://api.talesofai.com/v3/make_image", {
    method: "POST",
    headers: {
      "x-token": token,

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · kpopidolgenerator.js (reported line 85)May include surrounding context.

js
body.inherit_params = { collection_uuid: ref, picture_uuid: ref };
  }

  const res = await fetch("https://api.talesofai.com/v3/make_image", {
    method: "POST",
    headers: {
      "x-token": token,

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The README frames the skill around producing portraits with specifically Korean aesthetics and does not indicate any option to choose other language/locale/cultural styles. Under the policy, forcing a specific locale without opt-in can be a natural-language policy issue unless the constraint is clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The phrase "Use when someone asks to generate or create kpop idol style portrait images" is an imprecise activation condition for a markdown skill description. It does not define specific trigger phrases, boundaries, or negative examples, which could cause the skill to match loosely phrased everyday requests about portraits or image creation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.