Back to skill

Security audit

Keplerjai Image Gen

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent image-generation tool, but it exposes real-looking API credentials and allows sensitive prompts/images to be sent through loosely scoped API configuration.

Review before installing. Use only your own rotated ThinkZone key, remove all bundled plaintext keys, avoid machine-wide or hardcoded secrets, and do not send sensitive prompts or private reference images unless you intend them to be uploaded to the configured external API endpoint.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/gen_image.py:27
Finding

Hardcoded ThinkZone API Credentials Committed to Source and Documentation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/gen_image.py:409
Finding

Caller-Controlled API Destination Can Receive Bearer Credentials and Private Reference Images

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (39)

Tainted flow: 'req' from os.environ.get (line 236, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/gen_image.py (reported line 130)May include surrounding context.

python
)
    
    try:
        with urllib.request.urlopen(req, timeout=120) as response:
            result = json.loads(response.read().decode("utf-8"))
    except urllib.error.HTTPError as e:
        error_body = e.read().decode("utf-8")

Tainted flow: 'req' from os.environ.get (line 236, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/gen_image.py (reported line 186)May include surrounding context.

python
)
    
    try:
        with urllib.request.urlopen(req, timeout=120) as response:
            result = json.loads(response.read().decode("utf-8"))
    except urllib.error.HTTPError as e:
        error_body = e.read().decode("utf-8")

Tainted flow: 'req' from os.environ.get (line 236, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/gen_image.py (reported line 244)May include surrounding context.

python
)
    
    try:
        with urllib.request.urlopen(req, timeout=120) as response:
            result = json.loads(response.read().decode("utf-8"))
    except urllib.error.HTTPError as e:
        error_body = e.read().decode("utf-8")

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file contains what appears to be a live ThinkZone API key directly in documentation and instructs users to persist it in their environment. Hardcoding and publishing secrets in a skill repository enables anyone with access to the file to reuse the credential, leading to unauthorized API usage, quota exhaustion, billing abuse, and possible access to associated account resources.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The test command embeds the real API key in an example shell command, which increases exposure through shell history, terminal logs, screenshots, copy/paste sharing, and CI transcripts. In the context of an image-generation skill that calls a paid external API, this directly facilitates credential theft and downstream billing or service abuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The document contains a live-looking API key in plaintext and instructs users to copy it directly into an environment variable. This is a real secret exposure issue because anyone with access to the repository or documentation can reuse the credential for unauthorized API calls, billing abuse, or pivoting into connected services; in a distributable agent skill, that context makes the leak more dangerous rather than less.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The document contains what appears to be a live API key in plaintext, which is a direct secret exposure. Anyone with access to this file can reuse the credential to call the external image-generation service, incur charges, access account-linked resources, or pivot into broader compromise depending on the provider's permissions.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is configured to auto-trigger for any agent on very common phrases like '生成图片' or '做一张图', creating a broad activation surface and increasing the chance of unintended execution. In a multi-agent environment, this can cause accidental external API calls, unexpected spending, and transmission of user content without deliberate consent or contextual validation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The document explicitly includes a live API key and recommends hardcoding it into source code or setting it broadly at the system level. This creates a direct secret exposure risk: anyone with access to the repository, docs, logs, screenshots, or host environment can reuse the credential to make unauthorized API calls, incur cost, and potentially access account-scoped resources.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file discloses an actual API key and instructs users to set it at machine scope without any warning about secret hygiene, access control, rotation, or auditability. For an image-generation skill, this is unjustified and broadens exposure across all processes on the host, making theft or misuse more likely through local compromise, debugging tools, accidental disclosure, or shared administration.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose focuses on image generation, but the documented behavior also implies reading local reference images, writing generated files to disk, and using external network access with sensitive credentials. That mismatch is dangerous because users may provide prompts or local files without realizing data leaves the machine and artifacts are persisted locally, creating confidentiality and consent risks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared purpose focuses on image generation, but the documented behavior also implies reading local reference images, writing generated files to disk, and using external network access with sensitive credentials. That mismatch is dangerous because users may provide prompts or local files without realizing data leaves the machine and artifacts are persisted locally, creating confidentiality and consent risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The document plainly discloses what appears to be a live ThinkZone API key in a markdown file. Exposed API credentials can be copied by anyone with repository or artifact access and then abused to generate images, incur charges, exhaust quotas, or access related account resources; the surrounding 'test success' context makes it look like a real working secret rather than a placeholder.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The test instructions tell users to export the same real API key into environment variables, further propagating credential exposure and encouraging unsafe handling of secrets. This increases the chance the key will be copied into shell history, screenshots, logs, support messages, or reused by others who read the file.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code silently falls back to a hardcoded API key when THINKZONE_API_KEY is unset, which embeds a live credential in the skill and causes undisclosed use of that credential. In a distributed skill, anyone with code access can extract and abuse the key, leading to unauthorized API consumption, billing exposure, and possible account compromise or service suspension.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

A hardcoded fallback API key is a credential exposure issue and also hides from users/operators that the script may authenticate with an embedded secret. This enables unauthorized reuse by anyone who can read the repository or packaged skill, potentially causing financial loss and abuse of the linked ThinkZone account.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

A sensitive API credential is embedded and used without any disclosure, consent flow, or operational safeguards. Beyond secrecy loss, this means anyone running the script may unknowingly consume external paid resources and send requests under the owner’s account.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file is entirely written in Chinese and even the example prompt content is fixed to Chinese, with no indication that language choice is optional. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation describes automatic image generation through an external API but does not clearly disclose that prompts and possibly reference images will be sent to a third-party service. This creates a privacy and compliance risk because users or downstream agents may unknowingly transmit sensitive data outside the local environment.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Presenting credential embedding as a normal configuration fallback normalizes insecure secret handling and increases the chance that developers will copy the pattern into production code. Even if framed as a backup option, it undermines environment-based secret management and can lead to long-lived credentials being committed to source control or distributed to multiple agents and hosts.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes an image-generation skill supporting exactly three model families: Gemini, MiniMax, and Seedream. The README instead presents the skill as a BytePlus Seedream-only tool with five supported models, which materially changes the claimed capabilities and scope exposed to users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README documents an image parameter that accepts URL or Base64 reference images, but it does not warn users that those images may be transmitted to an external third-party service for processing. This creates a privacy and data-handling risk because users may unknowingly upload sensitive, personal, or proprietary images outside their environment.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 184)May include surrounding context.

--model seedream-5-0-260128

text

### 示例 5:cURL 调用

```bash
curl -X POST "https://open.thinkzoneai.com/v3/images/generations" \

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill advertises executable behavior involving environment variables, shell execution, network access, and file writes, but it does not declare any explicit tool scope such as permissions or allowed-tools. This weakens reviewability and containment because a host may grant broader capabilities than users or operators expect, especially for a skill that can transmit prompts and local image paths to an external service and save outputs locally.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad everyday terms like '画图', '生成图片', and '做一张图', which can cause the skill to activate in situations where the user did not intend external API usage or file handling. In context, unintended activation matters because the skill can send prompts and possibly reference images to a third-party service and write outputs locally.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
API_KEY_SETUP.md:7

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
API_KEY.md:17

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
ENV_FIX.md:49

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/gen_image.py:33

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
TEST_SUCCESS.md:41