Back to skill

Security audit

USA零生图技能

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent image-generation tool, but it needs Review because it can send API keys and user images to arbitrary or unencrypted endpoints.

Install only if you trust usa0.top and the publisher. Use a dedicated, revocable, quota-limited API key, avoid --base-url unless you fully trust the destination, do not use HTTP endpoints, and do not provide sensitive local files or private-network image URLs. Windows users should know the key is saved persistently as their user USA_API_KEY environment variable.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
generate.py:429
Finding

API Credentials and User Data Can Be Sent to Arbitrary or Plaintext Endpoints

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
generate.py:480
Finding

Unrestricted Image URL Fetching Enables Server-Side Request Forgery

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
generate.py:3
Finding

Automatically Installed Dependencies Are Not Reproducibly Pinned

Content
View full analysis
=3.10" # dependencies = [ # "customtkinter>=5.2.2", # "requests>=2.28.0", # ] # /// ``` ### Technical Analysis The script metadata permits any future version of `customtkinter` and `requests` that satisfies the lower-bound constraints. The Skill documentation directs the agent to execute the script through `uv run`, which can automatically resolve and install these packages. There is no exact version pin, committed lockfile, package hash, or registry restriction in the audited project. Consequently, the source code reviewed during this audit does not fully determine the code that will execute during a later installation. This is a supply-chain hardening weakness rather than evidence that the currently named packages are malicious. Exploitation requires a package repository, dependency release, account, or package-resolution source to become compromised or untrusted. ### Attack Path 1. A user or agent runs `uv run generate.py` as directed by the Skill. 2. `uv` resolves packages from its configured registry at execution time. 3. A newly published, compromised, or malicious package release satisfies the broad `>=` constraint. 4. The package is installed into the generated environment. 5. Package code executes when imported or used by the script with the privileges of the current user. ### Impact Assessment A compromised dependency can potentially execute arbitrary Python code with the current user's privileges. Depending on the malicious package behavior, this could expose: - Environment variables, including `USA_API_KEY`. - Files readable by the current user. - Prompts and reference images processed by the Skill. - Network access available to the host. - Files and directories writable by the current user. No current depe ...[truncated 139 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill instructs the agent to access environment variables, read and write files, install or repair tooling, invoke local scripts, and make network requests, but it does not declare any explicit tool scope or permissions. This creates a capability/consent mismatch: a host may expose broader powers than users realize, and the skill’s behavior includes sensitive actions such as handling API-key setup and sending prompts/images to a third-party service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language strings in Chinese for errors, help text, prompts, and status output, and does not provide any user opt-in or alternative locale. Under the policy rule, forcing a specific language without choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The script sends prompts, optional input images, and the Authorization bearer token to a remote service, and it also permits overriding --base-url to any HTTP/HTTPS endpoint. In the skill context, this is dangerous because users may be prompted to enter and persist a third-party API key and then unknowingly transmit that credential and their image data to an arbitrary server if the base URL is changed or the provider is untrusted/compromised.

Content

Scanner excerpt · generate.py (reported line 560)May include surrounding context.

python
response = requests.post(url, data=form_fields, files=files, headers=headers, timeout=(30, 300))
        else:
            url = f"{args.base_url}/v1/images/generations"
            response = requests.post(url, json=common_fields, headers=headers, timeout=(30, 300))
        response.raise_for_status()
    except ImageGenerationError:
        raise

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
README.md:11

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:120