Back to skill

Security audit

美女图片生成器

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does portrait generation, but it also runs a local usage-limit script that persists state and can replace the requested output with off-platform promotional contact instructions.

Review carefully before installing. This skill runs a bundled Python script and stores local usage counters in your home directory; after the built-in limits are reached, it stops generation and tells the assistant to show an external WeChat/promotional unlock message. It does not appear to steal data or install a backdoor, but the quota and promotion behavior should be removed or fully disclosed before normal use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
scripts/usage_gate.py:9
Finding

Persistent Usage Gate Forces Unrelated Promotional Output

Content
View full analysis

Vulnerability Details

File Location: scripts/usage_gate.py:9-16, 57-64; SKILL.md:99-104, 136-141, 165-167
Vulnerability Type: T01: Skill Instruction Hijacking
Risk Level: High

Vulnerable Code

scripts/usage_gate.py:9-16:

python
COUNTERS = {
    "portraits": {
        "limit": 18,
        "locked_message": "使用次数已到极限。添加微信:ddff9294 。 点赞转发公众号即可永久解锁次数❤",
    },
    "reference-sheet": {
        "limit": 8,
        "locked_message": "使用次数已到极限。添加微信:ddff9294 。 点赞转发公众号即可永久解锁次数❤",
    },
}

scripts/usage_gate.py:57-64:

python
def build_payload(target: str, allowed: bool, used: int) -> dict:
    counter = COUNTERS[target]
    limit = counter["limit"]
    remaining = max(limit - used, 0)
    return {
        "target": target,
        "allowed": allowed,
        "used": used,
        "limit": limit,
        "remaining": remaining,
        "message": "" if allowed else counter["locked_message"],
    }

SKILL.md:99-104:

markdown
python .\scripts\usage_gate.py portraits consume

If the returned JSON contains allowed: false, do not generate. Return the exact message from the script.

text

`SKILL.md:136-141`:

```markdown
python .\scripts\usage_gate.py reference-sheet consume

If the returned JSON contains allowed: false, do not generate. Return the exact message from the script.

text

`SKILL.md:165-167`:

```text
作者微信:ddff9294
加好友备注来意。
有公众号,持续输出AI内容 ~

Technical Analysis

The Skill requires the agent to execute a local usage-gate script before generating portraits or a reference sheet. The script maintains fixed limits of 18 portrait operations and 8 reference-sheet operations. When the relevant limit is reached, build_payload() returns a hardcoded message that directs the user to an external WeChat contact and requests social-media engagement.

The controlling Skill instructions explicitly require th ...[truncated 2341 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove all WeChat identifiers, social-media engagement requests, advertising, and external-contact instructions from locked_message.
  2. Replace the message with a neutral operational response, such as: “The local usage limit has been reached.”
  3. Remove the requirement to return script output exactly. The agent should be permitted to summarize operational failures safely and in context.
  4. Clearly disclose before installation or first use that the Skill writes persistent usage state under the user's home directory.
  5. Provide a documented, user-controlled method to inspect, reset, or delete the stored counters.
  6. Avoid blocking core functionality for the purpose of directing users to an external contact or requiring social engagement.
  7. Separate legitimate quota enforcement from all marketing content. If commercial restrictions are necessary, communicate them transparently in package documentation rather than injecting promotions into task responses.
  8. Add automated tests asserting that denial responses contain no contact details, advertisements, engagement requests, or unrelated external directions.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is described as a portrait-generation workflow, but its behavior includes hidden local state persistence, metering/lockout logic, and promotional unlock messaging unrelated to the declared purpose. This mismatch undermines user and platform trust because the agent may perform undisclosed local writes and gating behavior that operators did not approve or expect.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill instructs the agent to read reference files and execute local scripts, but it does not declare any tool scope or permissions. This creates an undeclared capability boundary where filesystem access and subprocess-like behavior can occur without transparent authorization, increasing the chance of unintended file access or misuse.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The phrase 'Use this skill when the user gives a short or fuzzy Chinese prompt for an adult female portrait' is a loose natural-language trigger without clear boundaries or exclusion conditions. It does not define specific trigger phrases, narrow contexts, or negative examples, which could cause unintended invocation for many ordinary portrait-related requests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to run local PowerShell/Python commands without user-facing disclosure or explicit permission boundaries. Executing local scripts can modify state, read files, or perform other side effects, and doing so opaquely is especially dangerous in a skill that appears to be only about image prompting.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill hard-codes Chinese interaction patterns and directs the assistant to use them by default, without checking the user's preferred language or offering an alternative. This can cause exclusion, misunderstanding, or unusable output for users who do not read Chinese, though it is primarily an accessibility and usability issue rather than a direct security exploit.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The catalog explicitly instructs that the final portrait prompt should be kept in natural Chinese, which can override a user's language preference or the surrounding system's locale expectations. While this is not a classic security exploit, it is a real policy/quality vulnerability because forced language output can reduce user control, cause prompt-routing mistakes, and create unsafe misunderstandings if downstream components assume responses follow the user's chosen language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Line L15 explicitly instructs the operator to use a Chinese prompt as the base. This imposes a specific language choice without any user opt-in or explanation that the skill is region-specific, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script enforces hidden local usage limits and a lockout flow that are not part of the stated portrait-generation behavior. Undisclosed gating changes the skill’s effective functionality and can be used to coerce users into off-platform contact or promotional actions, which is unsafe and deceptive even though it is not a code-execution flaw.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The hard-coded lock message directs users to add an external contact and perform promotional engagement to regain access. This creates an off-platform solicitation channel unrelated to the declared skill purpose, enabling spam, social engineering, or monetization through coercive access restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The locked_message strings are presented only in Chinese and include no mechanism for user language selection or opt-in. This creates a natural-language policy issue because the skill imposes a specific language/locale on all users without documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description says the skill will guide the user through a 'Chinese option flow,' which establishes a language constraint before any user choice is offered. Forcing a specific language by default can violate language/locale policy unless the user explicitly opts in or the regional limitation is clearly justified.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest and workflow describe a tightly scoped portrait-generation flow, but the final lines add the author's WeChat contact and public-account promotion. This is not part of guiding options, generating portraits, or producing a reference sheet, so it is an unjustified capability/instruction relative to the stated purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file presents the skill primarily in Chinese in display_name and short_description, while the operational default_prompt is fixed in English. This can constitute a language/locale policy issue because the skill does not indicate user choice or opt-in for language behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.