Back to skill

Security audit

AI图像提示词-免费版

Security checks across malware telemetry and agentic risk

Overview

This appears to be a simple image-prompt helper, but it asks for broader command and file-writing authority than its own instructions justify.

Review this skill before installing. It does not show exfiltration or destructive code, but it should not need command execution or broad file-writing permission to help draft image prompts. Prefer a version whose trigger is limited to image-prompt workflows and whose tools are limited to read or no tools unless saving prompts is clearly scoped.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Intent-Code Divergence

High
Confidence
95% confidence
Finding
The skill claims it is a pure Markdown skill that does not require exec, yet the manifest grants exec and write and the document includes command-execution examples. This mismatch can mislead users and reviewers into trusting a broader capability set than necessary, increasing the chance of unintended command execution or file modification in an otherwise low-risk prompt-authoring workflow.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
Granting write capability to a prompt-crafting skill is unnecessary based on the stated purpose and expands the attack surface beyond prompt generation. A skill with unjustified write access could alter local files, save unexpected content, or be repurposed through prompt injection or operator confusion to modify data unrelated to image prompting.

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The skill is presented as an AI image prompt tool, but the trigger text broadens usage to marketing copy, writing, title optimization, and general content creation. This scope drift can cause the agent to invoke the skill in contexts outside its reviewed purpose, increasing the risk of misuse, unexpected outputs, or inappropriate tool access under a misleading label.

Vague Triggers

High
Confidence
94% confidence
Finding
An overly broad trigger condition makes the skill eligible for activation in many unrelated writing tasks, despite its narrow advertised function. In an agent environment, this increases the likelihood of unnecessary invocation of a skill that has elevated capabilities such as exec/write, making the mismatch materially more dangerous than a simple wording issue.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.