Back to skill

Security audit

Snapchat Filter Art Generator

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a normal image-generation skill, but it sends your prompt and API token to the named Neta/TalesOfAI service and should handle tokens and install commands more safely.

Install from a trusted source, avoid placing a real API token directly in shell history when possible, rotate the token if you already exposed it, and do not send sensitive personal photos, names, or identifying prompts unless you are comfortable sharing them with the Neta/TalesOfAI service.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
snapchatfilterartgenerator.js:15
Finding

API Token Exposed Through Command-Line Arguments

Content
View full analysis
0) args.prompt = rest.join(' '); return args; } ``` The documentation explicitly instructs users to place the secret in the command line: ```bash node
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:31
Finding

Unpinned Third-Party Package Execution Through npx Installation Instructions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The README instructs users to install the skill via npx skills add ... without pinning a specific version of the tool or package. This creates a supply-chain risk because users may fetch whatever version is current at execution time, which could include a compromised or unexpected release if the upstream package or distribution path is tampered with.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill advertises only the Bash tool and does not declare any explicit tool scope or permissions, yet its documented behavior requires outbound network access to the Neta API. That mismatch can cause reviewers and users to underestimate what the skill can do, weakening least-privilege controls and increasing the risk of unintended data exfiltration or unauthorized external calls.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

The install instruction uses npx skills without pinning a specific version, which makes installs depend on whatever package version is current at execution time. This creates a supply-chain risk: a malicious or compromised upstream release could change behavior, introduce unsafe code, or alter transitive dependencies without the user noticing.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This code performs an outbound POST to a third-party image-generation endpoint and includes the user's token, prompt, and image-generation parameters. External transmission is expected for this skill's functionality, but it is still a genuine security/privacy concern because potentially sensitive user content and authentication material are disclosed to an outside service.

Content

Scanner excerpt · snapchatfilterartgenerator.js (reported line 91)May include surrounding context.

js
let createRes;
  try {
    createRes = await fetch('https://api.talesofai.com/v3/make_image', {
      method: 'POST',
      headers,
      body: JSON.stringify(body),

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This code performs an outbound POST to a third-party image-generation endpoint and includes the user's token, prompt, and image-generation parameters. External transmission is expected for this skill's functionality, but it is still a genuine security/privacy concern because potentially sensitive user content and authentication material are disclosed to an outside service.

Content

Scanner excerpt · snapchatfilterartgenerator.js (reported line 91)May include surrounding context.

js
let createRes;
  try {
    createRes = await fetch('https://api.talesofai.com/v3/make_image', {
      method: 'POST',
      headers,
      body: JSON.stringify(body),

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The polling request sends the authentication token and task identifier to the same third-party service to retrieve job results. This is part of normal operation, but it still constitutes external transmission of metadata and credentials to a remote provider, which matters in a tool dealing with personal image generation requests.

Content

Scanner excerpt · snapchatfilterartgenerator.js (reported line 135)May include surrounding context.

js
let pollRes;
    try {
      pollRes = await fetch(`https://api.talesofai.com/v1/artifact/task/${taskUuid}`, {
        method: 'GET',
        headers,
      });

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script sends user-supplied prompt text and an optional reference image identifier to a third-party API, but it gives users only a generic submission message and no clear privacy notice about what data leaves the local environment. In a skill that may be used with personal selfies and identifying prompts, this creates a real privacy risk because users may unknowingly transmit sensitive content to an external service.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.