Back to skill

Security audit

tl-aliyun-image-generator

Security checks for vulnerabilities and agentic risk

Overview

This image-generation skill is functional but asks users to paste a cloud API key into chat and stores it permanently in a plaintext local file.

Review before installing. Use only a dedicated low-privilege Alibaba/DashScope key with spending limits, avoid pasting real long-lived credentials into chat, and remove or replace the plaintext .aliyun_key storage and runtime pip install behavior before routine use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate_image.py:25
Finding

API Key Collected Through Chat, Exposed in Process Arguments, and Persisted in Plaintext

Content
View full analysis
[api_key]") sys.exit(1) user_prompt = sys.argv[1] # 如果 sys.argv 有第 3 个参数,说明大模型把 Key 传进来了 user_key = sys.argv[2] if len(sys.argv) > 2 else None generate_and_save_image(user_prompt, user_key) ``` The Skill explicitly directs the agent to request and pass the credential through the command line: ```markdown When the user replies with the API Key, rerun using a command containing the Key: python3 scripts/generate_image.py "your expanded image description" "sk-xxxxxxxxxxxx" (The Python script automatically saves it permanently and it does not need to be passed next time.) ``` ### Technical Analysis The Alibaba Cloud API key is handled through three insecure channels: 1. The user is instructed to disclose the key in an agent conversation, where it may remain in conversation history, platform telemetry, diagnostic logs, or backups. 2. The key is passed as a command-line argument. On applicable multi-user systems, command arguments can be exposed through process inspection facilities or captured in shell and agent execution logs. 3. The key is written indefinitely to `scripts/.aliyun_key` as plaintext. The file is opened using the process's default umask rather than being explicitly created with owner-only permissions. The fact that its name begins with a dot ...[truncated 1897 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/generate_image.py:7
Finding

Automatic Installation of an Unpinned Runtime Dependency

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (23)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The manifest presents the skill as a narrowly scoped image generator, but the documented behavior includes credential collection, permanent local secret storage, filesystem writes, and dependency installation. This mismatch is dangerous because reviewers and users may approve or route to the skill based on an incomplete understanding of its real capabilities and data handling.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill tells the agent to ask the user for an API key directly in chat and then persist it locally for reuse. Collecting credentials through ordinary conversation is high risk because chat channels may be logged, exposed to other tools, or mishandled, turning a simple image-generation workflow into credential harvesting and retention.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to collect and permanently store the user's API key without clear notice about persistence, security implications, or retention. This is dangerous because users may reveal a reusable secret without informed consent, and the stored key can later be abused for unauthorized API usage or billing charges.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill directs the agent to receive a secret in chat, reuse it, and store it locally, which expands the attack surface from one-time image generation to persistent credential exposure. In this context, the skill's narrow image-generation purpose does not justify secret collection and reuse, making the behavior more dangerous rather than less.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script writes a supplied API key to a hidden file without warning the user or requesting consent. This is dangerous because users may believe they are providing a one-time credential for a single image request, while the skill silently retains a reusable secret on disk.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script explicitly instructs the agent to ask the user for an API key in chat and then stores that secret locally. Collecting secrets through chat and persisting them to disk is especially dangerous in an agent setting because users may not understand retention, logs, or downstream access to the credential.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explicitly instructs users to send an API key through chat so the agent can capture and persist it locally, which introduces unnecessary sensitive-data handling beyond simple image generation. Collecting credentials via chat increases exposure to logging, replay, accidental disclosure, and insecure storage, especially when no storage protections or threat warnings are described.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation normalizes sending API credentials in chat without warning users that chat messages may be logged, retained, inspected by other components, or exposed in transcripts. This creates unsafe operational guidance that can lead users to disclose sensitive secrets through an inappropriate channel.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Telling users to paste an API key directly into chat enables the agent to ingest credentials through a high-risk channel that may be logged or surfaced to unintended parties. For an image-generation skill, this sensitive-data collection path is broader than necessary and materially increases the chance of credential compromise.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The example conversation operationalizes credential capture by having the agent prompt for an sk- key and then save it locally, making secret harvesting part of the normal user flow. This is dangerous because examples strongly shape real behavior and can cause users to expose active cloud credentials in a channel that may not be confidential.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Describing persistent storage of the user's API key in a hidden local file creates a credential-retention capability that is not necessary for the narrow task of generating images on demand. A hidden file is not a security control, and long-lived plaintext secrets on disk are vulnerable to local compromise, backup leakage, or inadvertent sharing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Claiming the key will be automatically and 'safely' saved locally, without explaining storage details or risks, can mislead users into overtrusting an unsafe persistence mechanism. This is especially risky because hidden-file storage often implies plaintext retention and gives a false sense of protection.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Stating that the API key will be stored in a local hidden file after being provided in chat combines two risky practices: insecure collection and persistent retention of a secret. In the context of a trigger-based image skill, this capability is disproportionate and expands the blast radius if the host environment or filesystem is compromised.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares shell, file, and network-capable behavior but does not define any explicit tool scope or permission boundary. That omission increases the chance the agent can execute broader actions than users expect, including local file writes and outbound API access, without transparent authorization constraints.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation explicitly allows permanent local storage of a user-supplied API key, which exceeds the stated purpose of generating an image from text. Persisting secrets creates ongoing exposure if the host is shared, logs are accessible, or later processes can read the stored key.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script's comments and especially its runtime user-facing messages are written in Chinese, including prompts, status, and error text, with no option to choose another language. This can violate language/locale policy when a skill imposes a specific language without user opt-in or documented regional justification.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

An image-generation skill should not silently change the runtime by installing packages during execution. This unnecessary capability increases attack surface, weakens deployment predictability, and can expose the environment to package supply-chain risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script performs a pip install automatically and suppresses output, so the user is not meaningfully informed that code and packages are being fetched and installed. Silent environment modification is risky because it can surprise operators and mask failures or malicious package-resolution outcomes.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
95% confidence
Finding

The script automatically invokes pip at runtime to install a dependency, which allows the skill to modify the local Python environment without explicit user consent. Even though the package name is fixed to requests, this still expands the skill’s behavior beyond image generation and creates supply-chain and environment-tampering risk.

Content

Scanner excerpt · scripts/generate_image.py (reported line 13)May include surrounding context.

python
import requests
    except ImportError:
        print("正在自动安装必要的依赖 (requests)...")
        subprocess.check_call([sys.executable, "-m", "pip", "install", "requests"], stdout=subprocess.DEVNULL,
                              stderr=subprocess.DEVNULL)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill stores the user’s API key in a local hidden file for future reuse, which exceeds the stated purpose of generating an image for the current request. Persisting secrets locally creates a confidentiality risk because other local users, processes, backups, or later code execution may access the stored credential.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/generate_image.py (reported line 66)May include surrounding context.

python
}

    try:
        response = requests.post(API_URL, headers=headers, json=payload)

        # 如果 Key 错误或欠费
        if response.status_code != 200:

Tainted flow: 'task_url' from requests.post (line 78, network input) → requests.get (network output)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/generate_image.py (reported line 84)May include surrounding context.

python
image_url = None
        while True:
            time.sleep(3)
            status_resp = requests.get(task_url, headers={"Authorization": f"Bearer {API_KEY}"})
            status_data = status_resp.json()
            status = status_data["output"]["task_status"]
            if status == "SUCCEEDED":

Tainted flow: 'image_url' from requests.get (line 88, network input) → requests.get (network output)

Medium
Category
Data Flow
Confidence
84% confidence
Finding

The script fetches image_url directly from a prior network response without validating the scheme, host, or content type. If the upstream service or response is manipulated, this can cause unexpected outbound requests to arbitrary hosts, enabling SSRF-like behavior or retrieval of malicious/non-image content.

Content

Scanner excerpt · scripts/generate_image.py (reported line 95)May include surrounding context.

python
return

        if image_url:
            img_data = requests.get(image_url).content
            download_dir = os.path.join(os.path.dirname(os.path.abspath(__file__)), "downloads")
            os.makedirs(download_dir, exist_ok=True)
            filename = f"generated_img_{int(time.time())}.png"

Static analysis

No suspicious patterns detected.