Back to skill

Security audit

Turn pet photos into cinematic character posters.

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says: it helps create pet movie posters through Mew APIs, with expected third-party image and API-key use disclosed in the workflow.

Before installing, be comfortable sharing pet images, poster text, and a mew.design API key with Mew's API. Prefer public image URLs you control, and only approve temporary third-party uploads if that privacy tradeoff is acceptable.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The install instruction is embedded in the skill metadata description as a natural-language phrase a user might casually repeat, which can cause unintended installation or invocation in contexts broader than explicit skill-management requests. Because installation is a privileged action, trigger phrasing should be tightly scoped to clear user intent rather than common conversational wording.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example intents include broad phrases like 'Help me install this ClawHub skill' and 'Install this skill and then use it' without requiring the exact skill identifier, creating ambiguity about what should be installed. In an agent ecosystem, ambiguous install triggers can be abused for confusion, unintended installs, or social-engineering-driven privilege expansion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The workflow mandates a specific Chinese onboarding message for users who need an API key, but it does not ask for the user's preferred language or present this as optional. Forcing a specific language without opt-in is a natural-language policy violation under the locale/language rule.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The direct reference to https://api.mew.design/ confirms dependency on an external network endpoint, expanding the attack surface to include third-party compromise, logging, retention, and misuse of submitted media and authentication material. In skill contexts, external transmission is more dangerous when the workflow asks users to paste API keys into conversation and then forwards requests off-platform.

Content

Scanner excerpt · SKILL.md (reported line 162)May include surrounding context.

For stage 1, call the official Mew image-process API directly:

bash
curl -sS -X POST "https://api.mew.design/open/api/image/process" \
  -H "Content-Type: application/json" \
  -H "x-api-key: USER_PROVIDED_KEY" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The direct reference to https://api.mew.design/ confirms dependency on an external network endpoint, expanding the attack surface to include third-party compromise, logging, retention, and misuse of submitted media and authentication material. In skill contexts, external transmission is more dangerous when the workflow asks users to paste API keys into conversation and then forwards requests off-platform.

Content

Scanner excerpt · SKILL.md (reported line 162)May include surrounding context.

For stage 1, call the official Mew image-process API directly:

bash
curl -sS -X POST "https://api.mew.design/open/api/image/process" \
  -H "Content-Type: application/json" \
  -H "x-api-key: USER_PROVIDED_KEY" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

The second-stage design generation call sends transformed user content and prompt text to another external endpoint, continuing the same third-party data exposure. Because the skill chains multiple external calls, the cumulative privacy risk increases, especially if images are temporarily uploaded elsewhere first to obtain public URLs.

Content

Scanner excerpt · SKILL.md (reported line 176)May include surrounding context.

For stage 2, call the official Mew design-generate API directly:

bash
curl -sS -X POST "https://api.mew.design/open/api/design/generate" \
  -H "Content-Type: application/json" \
  -H "x-api-key: USER_PROVIDED_KEY" \
  -d '{

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file instructs the agent to use a specific Chinese-language explanation when discussing third-party uploads of local images. Because no language choice or opt-in is offered, the skill imposes a locale preference that may conflict with user expectations or organizational language policy.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:164