Back to skill

Security audit

Grok图片生成-免费版

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its image-generation purpose, but it combines broad trigger wording with browser and desktop automation that can use a logged-in Grok session and write files locally.

Install only if you are comfortable with an agent opening Grok in your browser, using your logged-in Grok session, issuing desktop mouse/keyboard commands, and creating files in your Downloads folder. Invoke it only for explicit image-generation tasks and review any proposed desktop-agent or shell command before it runs.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The skill is presented as a narrowly scoped image-generation tool, but later claims generic file processing, API integration, command execution, and information retrieval capabilities. This scope expansion can mislead users and orchestrators into granting or invoking broader behaviors than necessary, increasing the chance of unintended command execution or data access.

Vague Triggers

High
Confidence
88% confidence
Finding
The top-level description uses broad activation language such as improving efficiency, automation, batch processing, and workflow optimization, which is vague enough to trigger the skill in many unrelated contexts. Because the skill can drive a browser and local desktop actions, overbroad invocation criteria increase the risk of unintended execution and local file-saving behavior without clear user intent.

Vague Triggers

High
Confidence
90% confidence
Finding
The trigger conditions section remains ambiguous and does not define strict activation constraints, despite the skill performing browser automation and saving files locally. This can cause accidental routing of general productivity or workflow requests into a skill that manipulates a logged-in browser session and local filesystem state.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill automates saving generated images to local storage via desktop interactions, but the description does not prominently warn users that files will be written to the local Downloads directory. Lack of disclosure can lead to surprising file creation, privacy issues on shared systems, and unsafe operation in environments where desktop automation should be tightly controlled.

Static analysis

No suspicious patterns detected.