Back to skill

Security audit

Vaporwave Art Generator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward external API image generator, with no hidden persistence or local data access, but users should treat prompts and the API token as data sent to Neta/TalesOfAI.

Install only if you are comfortable sending your image prompts, optional reference UUIDs, and Neta API token to the TalesOfAI/Neta service. Prefer a pinned or ClawHub-managed install path where available, avoid putting long-lived tokens directly in shell history, and use a limited or revocable token.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:31
Finding

Unpinned Third-Party Package Execution During Installation

Content
View full analysis
Remediation
View remediation
@`. 2. Use a lockfile and npm integrity metadata where installation is managed as part of a Node.js project. 3. Verify the expected package publisher, registry, and provenance before execution. 4. Prefer an installation mechanism that downloads a versioned artifact and verifies its cryptographic checksum or signature before running it. 5. Document that installation commands must not be executed with administrator or root privileges. 6. Apply the corrected installation instructions consistently in both `SKILL.md` and `README.md`. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
vaporwaveartgenerator.js:6
Finding

API Token Exposed Through Command-Line Arguments

Content
View full analysis
"your prompt" --token YOUR_TOKEN ``` ### Technical Analysis The application requires the API token to be passed through the `--token` command-line option. Command-line arguments are not an appropriate secret transport because they can be retained in shell history and may be visible through process-inspection interfaces, process monitoring software, CI/CD diagnostics, terminal session recordings, or command logging. The script does not print the token itself, and the audited code sends it only as the `x-token` header to the documented HTTPS API endpoint. The exposure arises before and during process execution because the credential forms part of the process argument vector. ### Attack Path 1. A user follows the documented command and supplies a valid Neta API token through `--token`. 2. The shell records the command in history, or the operating system exposes the process argument vector while the program is running. 3. Another local user, monitoring agent, CI log collector, support bundle, or other actor with access to those records obtains the token. 4. The actor reuses the token in requests to the Neta API. 5. Requests are attributed to the victim's account until the token expires or is revoked. Exploitation requires access to local process metadata, shell hi ...[truncated 658 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README explains that prompts and optional reference-image UUIDs are used with an external API, but it does not clearly warn users that their text prompts and identifiers are transmitted to a third-party service. This can lead users to unknowingly send sensitive creative content, personal data, or internal asset references outside their trust boundary.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The README instructs users to install and run the skill via npx skills without pinning a specific version. This can cause users to fetch and execute whatever package version is current at install time, increasing supply-chain risk if a malicious or compromised update is published.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill invokes an external image-generation API and requires a user-supplied token, but the manifest does not declare any tool scope or allowed-tools boundaries. That omission weakens least-privilege controls and makes the skill's network behavior less transparent to users and enforcement systems, increasing the chance of unintended outbound access or token misuse.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

The installation command uses npx skills without pinning a specific version, so execution depends on whatever package version is current at install time. This creates a supply-chain risk: a compromised or breaking upstream release could execute unexpected code on the user's machine during installation or setup.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · vaporwaveartgenerator.js (reported line 69)May include surrounding context.

js
};
  }

  const res = await fetch('https://api.talesofai.com/v3/make_image', {
    method: 'POST',
    headers: HEADERS,
    body: JSON.stringify(body),

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · vaporwaveartgenerator.js (reported line 69)May include surrounding context.

js
};
  }

  const res = await fetch('https://api.talesofai.com/v3/make_image', {
    method: 'POST',
    headers: HEADERS,
    body: JSON.stringify(body),

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · vaporwaveartgenerator.js (reported line 96)May include surrounding context.

js
};
  }

  const res = await fetch('https://api.talesofai.com/v3/make_image', {
    method: 'POST',
    headers: HEADERS,
    body: JSON.stringify(body),

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code sends the user's prompt content to an external API and authenticates with a user-supplied token, which is a privacy- and credential-relevant network operation. While the file comments describe image generation generally, there is no explicit disclosure in code comments or user-facing output that prompt data and the token will be transmitted to a third-party service.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.