Back to skill

Security audit

Mj Gallery

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its stated image-gallery purpose, but it should be reviewed because it automatically publishes a public gallery and does not require safe escaping of user-derived text in the HTML.

Review before installing if prompts or generated images may contain private, confidential, or proprietary material. Use only with non-sensitive content unless the skill is updated to require publication consent, escape all HTML fields, and offer cleanup or local-only behavior.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:110
Finding

Stored HTML Injection in the Public Image Gallery

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 25 and 58, with vulnerable template substitutions at lines 110-118
Vulnerability Type: Stored HTML injection with potential cross-site scripting
Risk Level: High

Vulnerable Code

markdown
4. **必须部署画廊**:使用 deploy 工具部署 `/workspace/mj_gallery/`,返回可公开访问的网页链接
markdown
Step 5: 更新画廊 index.html
  - 生成新条目加入画廊(最新在前)
  - 最多保留最近 20 条记录
html
<div class="card">
  <a href="{serial}.webp" target="_blank">
    <img src="{serial}.webp" alt="{prompt摘要}">
  </a>
  <div class="info">
    <p class="prompt">{prompt中文摘要}</p>
    <p class="meta">任务: {serial} · MJ 6.1 · {aspect_ratio} · {时间}</p>
  </div>
</div>

Technical Analysis

The skill requires an agent to place prompt summaries derived from user input directly into two distinct HTML contexts:

  • An attribute context: alt="{prompt摘要}"
  • An element-text context: <p class="prompt">{prompt中文摘要}</p>

The instructions do not require context-sensitive HTML encoding, sanitization, or validation before generating index.html. An attacker-controlled summary containing quotation marks or HTML metacharacters can therefore terminate the intended attribute or element and inject arbitrary markup. If active HTML attributes or script-capable elements are accepted by the deployment platform, this becomes stored cross-site scripting.

The risk is persistent because the generated record is retained in the gallery, and its exposure is broadened by the mandatory deployment to a publicly accessible URL.

Attack Path

  1. An attacker requests an image using a prompt containing an HTML payload, such as a string intended to close the alt attribute or the prompt paragraph.
  2. The skill translates or summarizes the prompt but preserves enough attacker-controlled markup to form a payload.
  3. The resulting summary is interpolated into alt="{prompt摘要}" or `

    {prompt中文摘 ...[truncated 1064 chars]

Remediation
View remediation

Remediation Suggestions

  1. Apply context-sensitive HTML encoding to every dynamic value:
    • Encode &, ", ', <, and > before inserting data into attributes.
    • Encode &, <, and > before inserting data into element text.
  2. Prefer a template engine with automatic escaping or safe DOM APIs using textContent and setAttribute rather than string concatenation.
  3. Treat translated and summarized prompts as untrusted input; translation or summarization is not a security boundary.
  4. Validate serial against a strict allowlist, such as digits only, before using it in paths or URLs.
  5. Add a restrictive Content Security Policy that disallows inline scripts and event handlers, while recognizing that CSP is defense in depth rather than a substitute for output encoding.
  6. Add regression tests with payloads targeting both contexts, including:
    text
    "><img src=x onerror=alert(1)>
    </p><img src=x onerror=alert(1)><p>
    
  7. Require explicit user approval before public deployment when gallery metadata contains user-supplied content.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill automatically deploys a public gallery containing generated images and prompt-derived summaries, but the description does not clearly warn users that their content will be publicly accessible. This creates a privacy and data exposure risk, especially if prompts contain sensitive personal, confidential, or proprietary information that gets embedded into the gallery metadata or visible page content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The rule states that prompts must uniformly use English and that Chinese prompts will be internally translated before submission. This imposes a language constraint without offering the user a choice or documenting an opt-in, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.