Back to skill

Security audit

豆包图片生成-免费版

Security checks across malware telemetry and agentic risk

Overview

This skill is mainly an image-generation helper, but its instructions also claim broad automation, file, API, and command capabilities beyond that purpose.

Review this skill before installing. It appears intended to drive a browser-based Doubao image-generation workflow and save the chosen image, but its broad trigger and generic command/file/API claims could lead an agent to use it outside that narrow purpose. Use it only for explicit Doubao image-generation tasks, avoid granting unnecessary file or command authority where your platform allows scoping, and confirm any save location before files are copied.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The manifest and description present this as a narrowly scoped image-generation skill, but the text broadens usage to generic LLM calls, agent orchestration, automation workflows, and other unrelated activities. This scope mismatch is dangerous because broad activation criteria and inflated capability claims can cause the agent to invoke a higher-privilege skill in contexts users did not intend, increasing the chance of unnecessary command execution or browser-based actions.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The free edition is documented as not supporting batch automation, yet later sections advertise generic automation, file processing, API integration, command execution, and information retrieval. These contradictory claims can mislead an agent into treating the skill as a general-purpose automation tool with exec/read/browser privileges, which materially expands the attack surface beyond simple image generation.

Intent-Code Divergence

High
Confidence
96% confidence
Finding
The document explicitly says workflow automation is unsupported, but later labels the skill as MD+EXEC and describes automation-oriented core functions. In a skill with execution-capable tools, this contradiction makes the context more dangerous because the agent may follow the broader automation framing and run commands or browser actions outside the narrow user-approved image task.

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
Claiming multi-format file reading/parsing/writing as a core function materially exceeds the narrowly documented image-generation workflow. In combination with read/exec/browser tooling, this broadens perceived authority to inspect or manipulate local files unrelated to the user’s image request, which can lead to overreach and data exposure.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger language is overly broad, covering AI model calls, intelligent dialogue, agent orchestration, enterprise teams, and automation workflows, far beyond image generation. Overbroad triggers are dangerous because they can cause unintended skill activation in unrelated contexts, leading the agent to use exec/browser/file capabilities when a narrower, safer skill should have been selected.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation guidance uses generic creative and design scenarios without precise boundaries, making it easy for the skill to match a wide range of unrelated requests. In this context, ambiguity is risky because the skill has privileged tools and local-write behavior, so accidental invocation can produce unnecessary browsing, command execution, or file operations.

Missing User Warnings

Low
Confidence
84% confidence
Finding
The skill instructs the agent to download images and copy them to local directories, but it does not prominently require a user-facing disclosure or confirmation for local file writes. This is risky because users may not expect files to be persisted or copied beyond temporary storage, especially in an automation-capable skill.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.