Back to skill

Security audit

Civitai Generation API

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward CivitAI image-generation helper, with expected network/API-token use and no evidence of hidden persistence, exfiltration, or destructive behavior.

Before installing, use a dedicated CivitAI token with limited exposure, avoid putting private or sensitive information in prompts, and prefer pinning the `civitai` npm dependency with a lockfile. Run it in a normal restricted workspace and choose output paths carefully.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:10
Finding

Unpinned Security-Sensitive Runtime Dependency

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/get_illust.js:197
Finding

Unrestricted and Unbounded Retrieval of a Service-Controlled Image URL

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 13)May include surrounding context.

md
## Prerequisites

- Node.js 18+ environment
- CivitAI API access token (stored in environment variable `CIVITAI_API_TOKEN`)
- `civitai` npm package installed

## Installation

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

md
node scripts/get_illust.js [options]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

md
node scripts/get_illust.js [options]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

md
node scripts/get_illust.js [options]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

md
node scripts/get_illust.js [options]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

md
node scripts/get_illust.js [options]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
node scripts/get_illust.js [options]

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill documents use of environment variables and outbound network access to CivitAI, but it does not declare any explicit tool scope or permissions boundaries. This is dangerous because consumers and execution frameworks may not realize the skill can access secrets and send user-supplied content off-platform, increasing the risk of overbroad execution and unintended data exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill does not clearly warn users that prompts and generation parameters are transmitted to CivitAI using an API token. This matters because prompts may contain sensitive or proprietary content, and without an explicit disclosure users may unknowingly send private data to a third-party service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

Several example comments and usage notes are written in Chinese, while the rest of the document is in English. This introduces an implicit language preference without telling users that the skill supports or expects a specific language, which can conflict with language/locale policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code file contains user-facing help output in Chinese for several option descriptions and examples, but it does not indicate that the language is configurable or optional. Under the policy rule for language/locale, forcing a specific language in user-facing text without opt-in is a violation unless clearly justified.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/get_illust.js:216