Back to skill

Security audit

GPT Image 2 Prompts

Security checks for vulnerabilities and agentic risk

Overview

This is a prompt-writing skill for GPT image generation, and its files are coherent with that purpose without hidden execution or data access.

Installers should expect Chinese-language guidance and mostly English generated image prompts unless they ask for another language. No hidden code execution, credential use, persistence, or broad local access was found.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger says the skill enters professional mode whenever the user 'clearly describes their needs,' but it does not define what counts as clear versus unclear. This creates an ambiguous boundary between professional mode and guided mode, which could lead to unintended invocation of the wrong interaction pattern.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The phrase 'trigger when user needs are vague' is subjective and does not specify how vagueness is determined. Without explicit thresholds, examples, or negative examples, the skill may inconsistently choose guided mode for ordinary requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instruction states that Chinese requests default to English prompts except for Chinese-specific content, which imposes a language choice on the user. This is a natural-language policy concern because it does not offer the user a language preference or opt-in before switching output language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language content begins with a Chinese-only description ('所有版本变更记录。') and the entire changelog is written exclusively in Chinese, which can indicate a fixed language/locale assumption. Under the policy, locale-specific language is only acceptable when users are given a choice or the constraint is clearly documented and justified, neither of which appears here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file presents all user-facing guidance and templates exclusively in Chinese, including the invocation guidance and response template. Under the policy for natural-language violations, forcing a specific language without user opt-in can be a locale-policy issue unless the constraint is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire guide is written in Chinese and provides no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the language/locale policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document title and introductory guidance are entirely in Chinese, while the file provides no indication that users may choose another language or locale. Under the policy, a skill that imposes a fixed language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

YARA rule 'network_reconnaissance': Network reconnaissance and scanning patterns [hacktools]

Medium
Category
YARA Match
Confidence
65% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · references/prompt-patterns.md (reported line 227)May include surrounding context.

[角色基础] + [种族/职业] + [体型] + [服装装备] + [武器] + [发型] + [面部] + [姿态] + [背景] + [光线] + [渲染风格] + [比例] + [参数]

text

**示例**:

Fantasy warrior female, human with battle-worn steel armor, athletic build, myth rune engravings glowing on breastplate, worn crimson cape, dual-wielding curved swords in combat stance, long wavy auburn hair, fierce expression with battle scars, standing on cliff edge overlooking dark fantasy forest, dramatic backlight with volumetric god rays, cool blue ambient, digital concept art style, clean lineart with detailed render, 16:9 widescreen, highly detailed textures, portfolio-quality

text

### 动漫角色

[风格定位] + [角色类型] + [外貌] + [服装] + [标志性元素] + [表情] + [姿态] + [场景] + [画风] + [比例]

text

**示例**:

Anime cel-shaded character, strong female lead archetype, medium long silver hair with twin tails, bright crimson eyes, school uniform with

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

该速查表从标题到各节说明均强制采用中文表述,且未见任何提示说明可切换其他语言或该文档仅面向中文用户。按规则,若技能在自然语言层面默认强制特定语言而未提供用户选择,可构成语言/locale 策略问题。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file contains user-facing instructional content predominantly in Chinese, beginning at L001 and continuing throughout, but it does not indicate that users may choose another language. Under the language/locale policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.