T08 · Insecure Dependencies
- Location
SKILL.md:10- Finding
Unpinned Security-Sensitive Runtime Dependency
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a straightforward CivitAI image-generation helper, with expected network/API-token use and no evidence of hidden persistence, exfiltration, or destructive behavior.
Before installing, use a dedicated CivitAI token with limited exposure, avoid putting private or sensitive information in prompts, and prefer pinning the `civitai` npm dependency with a lockfile. Run it in a normal restricted workspace and choose output paths carefully.
SKILL.md:10Unpinned Security-Sensitive Runtime Dependency
scripts/get_illust.js:197Unrestricted and Unbounded Retrieval of a Service-Controlled Image URL
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
## Prerequisites
- Node.js 18+ environment
- CivitAI API access token (stored in environment variable `CIVITAI_API_TOKEN`)
- `civitai` npm package installed
## Installation
Referenced artifact was not completely inspected
node scripts/get_illust.js [options]
Referenced artifact was not completely inspected
node scripts/get_illust.js [options]
Referenced artifact was not completely inspected
node scripts/get_illust.js [options]
Referenced artifact was not completely inspected
node scripts/get_illust.js [options]
Referenced artifact was not completely inspected
node scripts/get_illust.js [options]
Referenced artifact was not completely inspected
node scripts/get_illust.js [options]
The skill documents use of environment variables and outbound network access to CivitAI, but it does not declare any explicit tool scope or permissions boundaries. This is dangerous because consumers and execution frameworks may not realize the skill can access secrets and send user-supplied content off-platform, increasing the risk of overbroad execution and unintended data exposure.
The skill does not clearly warn users that prompts and generation parameters are transmitted to CivitAI using an API token. This matters because prompts may contain sensitive or proprietary content, and without an explicit disclosure users may unknowingly send private data to a third-party service.
Several example comments and usage notes are written in Chinese, while the rest of the document is in English. This introduces an implicit language preference without telling users that the skill supports or expects a specific language, which can conflict with language/locale policy expectations.
This code file contains user-facing help output in Chinese for several option descriptions and examples, but it does not indicate that the language is configurable or optional. Under the policy rule for language/locale, forcing a specific language in user-facing text without opt-in is a violation unless clearly justified.
Detected: suspicious.env_credential_access