Back to skill

Security audit

Antigravity Image Gen

Security checks for vulnerabilities and agentic risk

Overview

This image-generation skill is mostly coherent, but it uses local Google OAuth credentials with an internal API, spoofed client headers, broad activation rules, and an unrestricted output path.

Only install this if you intentionally want an internal Antigravity/Google API workflow to use your local Google OAuth profile. Review the account/project whose token will be used, avoid broad automatic activation, and do not let untrusted prompts or agents choose the output path.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate.js:105
Finding

Internal API Control Bypass and Client Identity Spoofing

Content
View full analysis
{ ``` ### Technical Analysis The script sends a locally obtained OAuth bearer token to an internal sandbox API at a `v1internal` endpoint. It also supplies client-identification headers that claim the request originates from Antigravity, Google Cloud SDK, and a VS Code Cloud Shell editor integration. The source comment explicitly states that the user-agent version is intended to bypass deprecation checks. This defeats server-side compatibility controls rather than handling deprecation through a supported API migration. The declared client identities also do not truthfully identify this standalone skill. Although the destination is under `googleapis.com` and no credential transmission to an unrelated domain was observed, using an undocumented internal interface makes its authorization requirements, stability, and account-policy behavior difficult to verify. The bearer token grants the endpoint the authority associated with the user's OAuth profile. ### Attack Path 1. A user or agent invokes the image-gen ...[truncated 1317 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate.js:143
Finding

Arbitrary File Overwrite Through Unrestricted Output Path

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (5)

Credential Access

High
Category
Privilege Escalation
Confidence
89% confidence
Finding

The script accesses a bearer token from a local auth profile and uses it to call an internal Google API. Credential access is security-sensitive in an agent skill because compromise, repurposing, or unexpected invocation of this code could enable unauthorized API use under the user's identity or project context.

Content

Scanner excerpt · scripts/generate.js (reported line 69)May include surrounding context.

js
const auth = profiles.profiles[profileKey];

    if (!auth || !auth.access) {
        console.error("Error: No google-antigravity profile or access token found.");
        process.exit(1);
    }

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill explicitly requires local OAuth credentials and states it reads local OAuth tokens to authenticate, but it does not declare any tool scope or permissions boundary in the manifest. That mismatch can cause the agent to invoke a credential-accessing capability without clear user-visible restriction, increasing the risk of unintended secret access or misuse if the skill is triggered inappropriately.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation conditions are very broad: any request to generate an image or create visual content may invoke this skill. Because the skill uses internal APIs and local OAuth credentials, accidental or overly eager invocation expands the chance of unnecessary credential use, unintended internal API access, and execution in contexts where a safer or less privileged image workflow would be preferable.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code intentionally forges client identity headers, and the inline comment explicitly says the version bump is meant to bypass deprecation checks. This is a form of protocol/identity spoofing that can evade intended server-side gating, violate least-privilege expectations, and create risk that the skill accesses an internal API under false pretenses.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The script reads a local auth profile and uses an OAuth bearer token with only a generic 'Loading credentials' message, giving the user little visibility that sensitive credentials are being consumed. In an agent skill context, implicit credential use is more dangerous because users may invoke the tool for image generation without realizing it accesses internal tokens from disk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.