Back to skill

Security audit

WorkRally 图片生成(SkillPay)

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed paid image-generation skill that sends prompts and optional user-provided reference images to WorkRally after user confirmation and payment authorization.

Install only if you are comfortable using WorkRally and WeixinPay for paid image generation. Each generation is disclosed as 0.36 yuan per call, requires user authorization, and may send your prompt plus any reference images you provide to WorkRally for processing.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The guidance fixes the error-response shape to use a Chinese msg field ("<中文消息>"), which reflects a specific language requirement in natural-language-facing content. The file does not indicate that this Chinese-only behavior is optional, user-selected, or justified as a region-specific constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The instruction says on-image text should be placed in Chinese quotation marks, which imposes a specific locale/style requirement regardless of the user's preferred language or typography conventions. This is a natural-language policy concern because the file does not present this as optional or limited to Chinese-language requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

L18 明确给出面向用户的固定中文提示“WorkRally图片生成 0.36 元/次,是否使用?”,整篇流程示例也默认中文交互。根据规则,若技能强制特定语言而未提供用户选择或明确的地域性理由,属于自然语言政策风险。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all user-facing instructions and pricing details only in Chinese. Under the policy, forcing a specific language without user opt-in or a documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.