Back to skill

Security audit

Image Generation

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent AI image generation guide that uses disclosed cloud providers and optional local preference memory, with some normal credential, privacy, and dependency hygiene caveats.

Install only if you are comfortable sending prompts and any reference images to the selected image provider. Keep API keys in environment variables or a secrets manager, avoid sensitive or regulated content in prompts unless approved, and run any pip install examples in an isolated environment with pinned package versions where practical.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T08 · Insecure Dependencies

Warning
Location
replicate.md:10
Finding

Unpinned Replicate Package Installation

Content
View full analysis

Vulnerability Details

File Location: replicate.md:10
Vulnerability Type: Unpinned third-party dependency
Risk Level: Medium

Vulnerable Code:

bash
pip install replicate

Technical Analysis

The setup command installs the latest package release resolved by the configured Python package index. It does not specify a reviewed version, verify package hashes, use a lockfile, or require an isolated environment.

As a result, the installed code can change after the Skill has been audited. A compromised upstream release, compromised package-index account, or unsafe package-index configuration could introduce malicious installation or runtime code.

Attack Path

  1. An attacker compromises the upstream package, maintainer account, release process, or package source used by pip.
  2. A malicious version becomes the version selected by the unpinned command.
  3. A user follows the documented setup instructions.
  4. Pip downloads and installs the mutable release.
  5. Malicious installation hooks or imported package code execute with the privileges of the user running pip.

Impact Assessment

Successful exploitation could execute arbitrary code under the installing user's account. This may expose files, environment variables, API tokens, and other resources accessible to that account. It does not directly provide administrator privileges unless installation is separately performed with elevated permissions.

Remediation
View remediation

Remediation Suggestions

  • Pin the dependency to a reviewed version, such as replicate==<reviewed-version>.
  • Publish a requirements or lock file containing exact transitive dependency versions.
  • Record and verify package hashes with pip install --require-hashes.
  • Recommend installation inside a dedicated virtual environment.
  • Configure pip to use an explicitly trusted package index.
  • Add a controlled dependency-update process that includes security review and testing.

T08 · Insecure Dependencies

Warning
Location
stable-diffusion.md:21
Finding

Unpinned Local Image-Generation Dependencies

Content
View full analysis

Vulnerability Details

File Location: stable-diffusion.md:21
Vulnerability Type: Unpinned third-party dependencies
Risk Level: Medium

Vulnerable Code:

bash
pip install diffusers transformers accelerate torch

Technical Analysis

The command installs several large third-party packages without version constraints, hashes, or a lockfile. The effective dependency graph can therefore change between installations and is not the same dependency set that was reviewed during this audit.

These packages and their transitive dependencies execute Python and native code. A compromised release or unsafe package source could consequently provide an arbitrary code-execution path.

Attack Path

  1. An attacker compromises one of the named packages, a transitive dependency, its release credentials, or the package source.
  2. A malicious version is published and selected by dependency resolution.
  3. A user runs the documented installation command.
  4. Pip retrieves and installs the malicious or compromised component.
  5. Malicious installation-time or import-time code executes under the user's account.

Impact Assessment

Exploitation could provide code execution with the installing user's privileges and access to that user's files, model assets, environment variables, API credentials, and available compute resources. No direct privilege-escalation mechanism is present in the Skill itself.

Remediation
View remediation

Remediation Suggestions

  • Replace the command with a reviewed, version-pinned dependency file.
  • Pin all transitive dependencies through a generated lockfile.
  • Use hashes and pip install --require-hashes where supported.
  • Document compatible Python, CUDA, ROCm, and platform-specific package versions.
  • Require a dedicated virtual environment rather than installing into a global interpreter.
  • Review new package versions before updating the lockfile.

T09 · Insecure Skill Coding Practices

Note
Location
ideogram.md:30
Finding

Ideogram API Request Has No Timeout or HTTP Error Handling

Content
View full analysis

Vulnerability Details

File Location: ideogram.md:30-43
Vulnerability Type: Unbounded network request
Risk Level: Low

Vulnerable Code:

python
response = requests.post(
    "https://api.ideogram.ai/generate",
    headers={
        "Api-Key": IDEOGRAM_API_KEY,
        "Content-Type": "application/json"
    },
    json={
        "image_request": {
            "prompt": "A coffee shop sign that says 'Morning Brew'",
            "model": "V_2",
            "magic_prompt_option": "AUTO",
            "aspect_ratio": "ASPECT_1_1"
        }
    }
)

Technical Analysis

The requests.post call does not define a connection or read timeout. Python Requests does not impose a timeout by default, so the operation can remain blocked indefinitely if the provider or network accepts a connection but fails to complete the response.

The example also does not call raise_for_status() or otherwise validate HTTP status codes. This can cause callers to process an error response as though generation succeeded.

Sending the API key and prompt to the declared Ideogram HTTPS endpoint is necessary for the selected hosted-generation workflow and does not, by itself, exceed the Skill's required privileges. The issue is the absence of bounded and validated network handling.

Attack Path

  1. The user starts an Ideogram generation request.
  2. The remote service, proxy, or network path stalls or returns an error response.
  3. Because no timeout is configured, the request can block the workflow indefinitely.
  4. If an HTTP error is returned, later code may misinterpret the response because the status is not explicitly validated.

Impact Assessment

Exploitation or provider failure can cause denial of service for the current workflow, tie up an Agent worker, and waste execution resources. This issue does not grant an attacker additional local privileges or access beyond the prompt and API reques ...[truncated 32 chars]

Remediation
View remediation

Remediation Suggestions

  • Add explicit connect and read timeouts, for example timeout=(10, 60).
  • Call response.raise_for_status() before parsing or using the response.
  • Catch requests.Timeout, requests.ConnectionError, and malformed-response errors.
  • Use a small, bounded retry count with exponential backoff and jitter.
  • Avoid retrying non-transient authentication and validation failures.
  • Return a clear failure to the caller after the retry budget is exhausted.

T09 · Insecure Skill Coding Practices

Note
Location
leonardo.md:22
Finding

Leonardo Generation Request Has No Timeout or Response Validation

Content
View full analysis

Vulnerability Details

File Location: leonardo.md:22-37
Vulnerability Type: Unbounded network request and unchecked response
Risk Level: Low

Vulnerable Code:

python
response = requests.post(
    "https://cloud.leonardo.ai/api/rest/v1/generations",
    headers={
        "Authorization": f"Bearer {LEONARDO_API_KEY}",
        "Content-Type": "application/json"
    },
    json={
        "prompt": "A fantasy warrior character",
        "modelId": "6bef9f1b-29cb-40c7-b9df-32b51c1f67d3",  # Leonardo Creative
        "width": 1024,
        "height": 1024,
        "num_images": 4
    }
)
generation_id = response.json()["sdGenerationJob"]["generationId"]

Technical Analysis

The POST request does not set connection or read timeouts, allowing an unavailable or stalled endpoint to block indefinitely. It also parses the body and accesses nested fields without first validating the HTTP status or response schema. Authentication failures, rate limits, server errors, or malformed responses can therefore produce uncontrolled exceptions.

Transmission of the bearer token and prompt to Leonardo's declared HTTPS endpoint is required for the provider workflow and is consistent with the Skill's disclosed behavior. No unrelated recipient or credential-exfiltration path was identified.

Attack Path

  1. The user initiates Leonardo image generation.
  2. The provider or network stalls, returns an HTTP error, or returns malformed JSON.
  3. Without a timeout, the operation may block indefinitely.
  4. Without status and schema validation, error content may trigger a parsing or key-access exception.
  5. The generation workflow terminates unexpectedly or consumes a worker until externally cancelled.

Impact Assessment

The issue affects availability and reliability of the current Agent workflow. It can consume execution time and prevent completion, but it does not independently provide additiona ...[truncated 49 chars]

Remediation
View remediation

Remediation Suggestions

  • Set explicit connection and read timeouts.
  • Call response.raise_for_status() before parsing JSON.
  • Validate that the response is JSON and contains the expected generation identifier.
  • Handle authentication, rate-limit, timeout, connection, and server errors separately.
  • Apply only bounded retries to transient failures, with exponential backoff and jitter.
  • Avoid logging the authorization header or API key in exception output.

T09 · Insecure Skill Coding Practices

Note
Location
leonardo.md:42
Finding

Leonardo Result Polling Can Continue Indefinitely

Content
View full analysis

Vulnerability Details

File Location: leonardo.md:42-54
Vulnerability Type: Infinite polling loop and unbounded network requests
Risk Level: Low

Vulnerable Code:

python
import time

while True:
    result = requests.get(
        f"https://cloud.leonardo.ai/api/rest/v1/generations/{generation_id}",
        headers={"Authorization": f"Bearer {LEONARDO_API_KEY}"}
    ).json()
    
    if result["generations_by_pk"]["status"] == "COMPLETE":
        images = result["generations_by_pk"]["generated_images"]
        break
    time.sleep(2)

Technical Analysis

The polling loop has no overall deadline or maximum attempt count and exits only when the status equals COMPLETE. It does not recognize terminal failure or cancellation states. If a job remains pending, disappears, or reaches a failed state, polling can continue indefinitely.

Each GET request also lacks a timeout, HTTP status validation, and response-schema validation. A single stalled response can block the loop, while malformed or error responses can terminate it with an uncontrolled exception.

Attack Path

  1. A generation job is created and its identifier enters the polling loop.
  2. The job never reaches COMPLETE, reaches an unhandled failure state, or the provider repeatedly returns a non-terminal response.
  3. The loop sends a request every two seconds without a maximum duration.
  4. The workflow remains active indefinitely, consuming Agent time and generating unnecessary provider traffic.
  5. Alternatively, one stalled GET request blocks forever because no request timeout exists.

Impact Assessment

This can cause denial of service for the active workflow, consume worker capacity, create unnecessary API traffic, and potentially contribute to rate limiting. It does not grant additional system privileges or establish persistence beyond the running process.

Remediation
View remediation

Remediation Suggestions

  • Replace while True with a monotonic-clock deadline and maximum attempt count.
  • Set explicit connect and read timeouts on every GET request.
  • Recognize terminal states such as failed, cancelled, and expired.
  • Call raise_for_status() and validate the response schema before field access.
  • Use bounded exponential backoff with jitter rather than fixed indefinite polling.
  • Return a controlled timeout or provider-failure error when the polling budget is exhausted.
  • Consider the bounded wait_for_job pattern already documented in api-patterns.md.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (19)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · ideogram.md (reported line 19)May include surrounding context.

Setup

  1. Create account: https://ideogram.ai/
  2. Get API key from settings
bash
export IDEOGRAM_API_KEY="your-key"

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

The setup steps direct the user to obtain an API key and use it for the integration, which is normal, but the skill does not provide adequate guidance on secure storage, rotation, or limiting exposure. In a skill consumed by less technical users or agents, this can lead to keys being pasted into code, shells, shared transcripts, or repositories.

Content

Scanner excerpt · leonardo.md (reported line 10)May include surrounding context.

Setup

  1. Create account: https://leonardo.ai/
  2. Get API key from dashboard
  3. $5 free credit to start
bash

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file includes curl examples that send user-provided prompts to api.bfl.ai and use a bearer token from BFL_API_KEY, but the surrounding documentation does not warn that prompt content is transmitted to a third-party service. Because markdown files should disclose behaviors affecting user data or privacy, the omission is a meaningful safety gap.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · flux.md (reported line 34)May include surrounding context.

Text-to-Image

bash
curl -X POST "https://api.bfl.ai/v1/flux-pro" \
  -H "Authorization: Bearer $BFL_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · flux.md (reported line 34)May include surrounding context.

Text-to-Image

bash
curl -X POST "https://api.bfl.ai/v1/flux-pro" \
  -H "Authorization: Bearer $BFL_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · flux.md (reported line 47)May include surrounding context.

Text-to-Image

bash
curl -X POST "https://api.bfl.ai/v1/flux-pro" \
  -H "Authorization: Bearer $BFL_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · flux.md (reported line 107)May include surrounding context.

md
## Common Mistakes

- Calling `flux-2-pro` directly on BFL API (not an official endpoint)
- Using generation model IDs for edit endpoints without checking docs
- Assuming all provider aliases share identical parameters and response formats

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · gemini.md (reported line 25)May include surrounding context.

Basic REST Example

bash
curl -X POST \
  "https://generativelanguage.googleapis.com/v1beta/models/gemini-2.5-flash-image-preview:generateContent?key=$GEMINI_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
77% confidence
Finding

The sample shows a full POST request with headers and JSON payload to Ideogram, confirming active transmission of user-supplied content to an external service. The risk is contextual rather than inherently malicious: the skill is designed for cloud image generation, but users are not warned about privacy, retention, or third-party processing.

Content

Scanner excerpt · ideogram.md (reported line 30)May include surrounding context.

python
import requests

response = requests.post(
    "https://api.ideogram.ai/generate",
    headers={
        "Api-Key": IDEOGRAM_API_KEY,

External Transmission

Medium
Category
Data Exfiltration
Confidence
77% confidence
Finding

The sample shows a full POST request with headers and JSON payload to Ideogram, confirming active transmission of user-supplied content to an external service. The risk is contextual rather than inherently malicious: the skill is designed for cloud image generation, but users are not warned about privacy, retention, or third-party processing.

Content

Scanner excerpt · ideogram.md (reported line 30)May include surrounding context.

python
import requests

response = requests.post(
    "https://api.ideogram.ai/generate",
    headers={
        "Api-Key": IDEOGRAM_API_KEY,

External Transmission

Medium
Category
Data Exfiltration
Confidence
74% confidence
Finding

The referenced API endpoint identifies a third-party destination for generated requests, meaning prompts and associated request metadata are sent outside the user's environment. Given the skill's cloud-provider focus, this is expected, but the lack of disclosure makes it a real privacy and data handling concern.

Content

Scanner excerpt · ideogram.md (reported line 31)May include surrounding context.

md
import requests

response = requests.post(
    "https://api.ideogram.ai/generate",
    headers={
        "Api-Key": IDEOGRAM_API_KEY,
        "Content-Type": "application/json"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs users to send prompts and an API bearer token to Leonardo's external cloud service but does not clearly warn that prompts, images, and account-linked metadata leave the local environment. In an agent skill context, users may unknowingly submit sensitive data or mishandle credentials, creating privacy and token-exposure risk even if the documentation is otherwise legitimate.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This finding is a duplicate view of the same POST-based external transmission to Leonardo's API. The risk is not that the code is inherently malicious, but that the skill normalizes sending potentially sensitive prompts and account credentials to a third-party service without surrounding safety guidance.

Content

Scanner excerpt · leonardo.md (reported line 22)May include surrounding context.

python
import requests

response = requests.post(
    "https://cloud.leonardo.ai/api/rest/v1/generations",
    headers={
        "Authorization": f"Bearer {LEONARDO_API_KEY}",

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This finding is a duplicate view of the same POST-based external transmission to Leonardo's API. The risk is not that the code is inherently malicious, but that the skill normalizes sending potentially sensitive prompts and account credentials to a third-party service without surrounding safety guidance.

Content

Scanner excerpt · leonardo.md (reported line 22)May include surrounding context.

python
import requests

response = requests.post(
    "https://cloud.leonardo.ai/api/rest/v1/generations",
    headers={
        "Authorization": f"Bearer {LEONARDO_API_KEY}",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs creation and ongoing update of a persistent memory file containing user/project preferences, but it does not tell the user that session-derived data will be stored on disk. This creates a privacy and consent issue: prompts, style constraints, and workflow history may persist longer than the user expects and could be exposed to other local users, backups, or later processes.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · setup.md (reported line 51)May include surrounding context.

test -n "$BFL_API_KEY" && echo "BFL configured"

text

Never ask users to paste secret values into chat.

## Memory Updates

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs users to send prompts and request data to Ideogram's third-party API but does not disclose that user inputs, including potentially sensitive prompts, will leave the local environment. This is a genuine transparency and privacy issue because users may assume prompt content is handled locally when it is actually transmitted externally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file includes an instruction to export a live API credential, but it does not warn users to avoid committing tokens, sharing shell history, or exposing credentials in logs. Under the markdown-file criteria for missing user warnings, credential-related behavior should include some disclosure when it affects privacy or account security.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This is a markdown file, so SQP-2 applies to missing user-facing warnings in the skill description. The example writes an image file with image.save("lion.png"), but the document does not disclose that the workflow creates a local file or advise the user to choose a safe output path/name.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.