Back to skill

Security audit

Yq Image Creator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent image-generation helper with disclosed image, form, and limited search tool use, and no executable payload or hidden privileged behavior.

Safe to install for image-generation workflows. Expect uploaded reference images to be analyzed by the configured image tools, and expect occasional web searches for public city, landmark, or brand details when the prompt needs them.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
83% confidence
Finding
The skill explicitly allows `web_search` to infer brand or city information, but it does not require notifying the user that an external lookup may occur. This can create an unexpected data-flow boundary where user-provided brand, location, or request context is sent to external search services without informed consent, increasing privacy and transparency risk.

Static analysis

No suspicious patterns detected.