Back to skill

Security audit

豆包图片生成-专业版

Security checks across malware telemetry and agentic risk

Overview

The skill is mainly an image-generation guide, but it asks for broad file, API, and command authority with loose automation scoping that users should review before installing.

Review before installing. Use it only in a dedicated image-generation workspace, provide a scoped API key through environment variables, and check any Python commands or file output paths before allowing the agent to run them.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The skill is presented as a specialized image-generation tool, but later advertises generic file handling, API integration, and command execution. That mismatch expands the apparent authority of the skill beyond its stated purpose and can cause users or orchestrators to invoke it in overly powerful contexts, increasing the risk of unintended shell or file actions.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The invocation guidance uses broad 'use when efficiency/automation/batch processing/workflow optimization' language without concrete boundaries. This can cause the agent to select the skill for many unrelated tasks, potentially granting read/write/exec capabilities in situations where a narrower, safer skill should have been used.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill documentation describes file writing, external API use, and command execution but does not prominently warn about side effects such as modifying files, sending data off-host, or running system commands. In an agent setting, omission of these warnings can lead to unsafe invocation and insufficient user consent for actions with security and privacy consequences.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.