Back to skill

Security audit

AI图像生成-免费版

Security checks across malware telemetry and agentic risk

Overview

This appears to be an image-generation skill, but its trigger language is much broader than image generation and could send unrelated prompts to an external API.

Review this before installing. Use it only for explicit image-generation requests, avoid confidential or regulated prompt text, verify the external API provider and missing generation script, and keep the API key out of source-controlled files.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Context-Inappropriate Capability

Low
Confidence
91% confidence
Finding
The trigger condition is so broad that an agent may invoke this skill for unrelated AI or orchestration tasks, despite the skill exposing exec and write capabilities. In agent ecosystems, overbroad matching increases the chance of unintended tool execution, data exposure to an external API, or user prompts being routed into a skill outside its intended domain.

Vague Triggers

High
Confidence
95% confidence
Finding
This is a true security-relevant quality issue because overly broad triggers can cause the agent to select a skill with exec/write permissions for many unrelated tasks. In the context of an external API-backed skill, accidental invocation can leak prompts or contextual data to third parties and expand the operational surface far beyond simple image generation.

Vague Triggers

High
Confidence
93% confidence
Finding
The top-level description includes vague guidance to use the skill for general AI model calls, intelligent dialogue, agent orchestration, and LLM applications, which can bias selection engines toward this skill outside its real purpose. Because the skill advertises exec/read/write tooling and external network use, misselection materially raises the risk of unintended command execution workflows and external data transmission.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The documentation notes API key handling but does not clearly warn that user prompts and related content are sent to an external image API endpoint. In an agent context, users may supply sensitive business, personal, or proprietary text, and omission of a disclosure increases the risk of unintentional data exfiltration to a third-party service.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.