Back to skill

Security audit

illo

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed image-generation skill with expected network/API/CLI use and local configuration, and I found no hidden exfiltration, destructive behavior, or deceptive persistence.

Install only if you want this agent to generate images through local subscription CLIs or OpenRouter. Run key setup yourself, do not paste API keys in chat, expect generated prompts/reference images to be sent to the selected image backend, and prefer managed or pinned installs over the generic npx fallback. Review community character packs before installing or updating them, especially from custom repositories.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (50)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill also embeds installer and maintenance logic, including SHA-256 verification and automatic redownload of corrupted assets from remote URLs, which is materially different from a simple illustration generator. Even if intended for reliability, hidden updater/repair behavior introduces supply-chain and network-fetch risk that users may not expect from the skill description alone.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill also embeds installer and maintenance logic, including SHA-256 verification and automatic redownload of corrupted assets from remote URLs, which is materially different from a simple illustration generator. Even if intended for reliability, hidden updater/repair behavior introduces supply-chain and network-fetch risk that users may not expect from the skill description alone.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

md
| **Blog / brand / site-matched art** | A named or custom palette, or derive the palette from one dominant color (`references/palettes.md`). |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 201)May include surrounding context.

md
| **Blog / brand / site-matched art** | A named or custom palette, or derive the palette from one dominant color (`references/palettes.md`). |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 510)May include surrounding context.

md
| **Blog / brand / site-matched art** | A named or custom palette, or derive the palette from one dominant color (`references/palettes.md`). |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

md
absolute path of the directory this `SKILL.md` was loaded from (it contains

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 196)May include surrounding context.

md
- `references/visual-style.md` — riso, the house default look: the risograph technique, line language, paper/ink, hard do/don'ts.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 502)May include surrounding context.

md
- `references/visual-style.md` — riso, the house default look: the risograph technique, line language, paper/ink, hard do/don'ts.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 198)May include surrounding context.

md
- `references/character.md` — the character rules (the load-bearing test, anti-complexity guardrails, value-follows-palette, the **interaction model** — declare

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 388)May include surrounding context.

md
- `references/character.md` — the character rules (the load-bearing test, anti-complexity guardrails, value-follows-palette, the **interaction model** — declare

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 447)May include surrounding context.

md
- `references/character.md` — the character rules (the load-bearing test, anti-complexity guardrails, value-follows-palette, the **interaction model** — declare

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 454)May include surrounding context.

md
- `references/character.md` — the character rules (the load-bearing test, anti-complexity guardrails, value-follows-palette, the **interaction model** — declare

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 461)May include surrounding context.

md
- `references/character.md` — the character rules (the load-bearing test, anti-complexity guardrails, value-follows-palette, the **interaction model** — declare

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 464)May include surrounding context.

md
- `references/character.md` — the character rules (the load-bearing test, anti-complexity guardrails, value-follows-palette, the **interaction model** — declare

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 501)May include surrounding context.

md
- `references/character.md` — the character rules (the load-bearing test, anti-complexity guardrails, value-follows-palette, the **interaction model** — declare

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · references/composition.md (reported line 151)May include surrounding context.

md
intention — not a closed synonym list, and not a keyword scan of "flow"
or "workflow". After the type locks, do not rotate it. The ban on
boxes-and-diamonds / Visio / title-legend-grid formality is a **look**
constraint: produce labeled stages in the pack's look; do not refuse the
word flowchart.

Override precedence (highest wins):

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · references/cutout.md (reported line 156)May include surrounding context.

md
transparency. If the keyed result shows fringe or an opaque fallback, re-roll
the screen render or route to Codex/OpenRouter.

**Codex backend** — omit manual background/output instructions. The engine asks
gpt-image-2 for a real transparent PNG and preserves clean native alpha. Native
output still needs QA: re-roll an opaque result, cropped figure, or edge halo.
Use `--chroma green|magenta` only to force the compatibility path when native

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 165)May include surrounding context.

environment setup script, devcontainer postCreateCommand, a CI step):

bash
mkdir -p ~/.config/illo
printf 'apiKey: "%s"\n' "$OPENROUTER_API_KEY" > ~/.config/illo/config.yaml
chmod 600 ~/.config/illo/config.yaml

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 167)May include surrounding context.

bash
mkdir -p ~/.config/illo
printf 'apiKey: "%s"\n' "$OPENROUTER_API_KEY" > ~/.config/illo/config.yaml
chmod 600 ~/.config/illo/config.yaml

The key stays in the platform's secret store; each fresh workspace gets

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill requests broad capabilities via shell-driven workflows, file access, network use, config management, and external CLIs, yet declares no explicit tool/permission scope. That creates an over-privileged execution surface where a host agent may grant more authority than is necessary, increasing the blast radius if the skill is misused, modified, or invoked in an unexpected context.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 112)May include surrounding context.

md
assets, so `$SKILL_DIR` only has to be right enough to launch `illo.py` and to
point `--ref` at the bundled character sheet.

Write the block **flatten-safe** — some hosts (Codex observed) collapse a fenced
block to one line, turning a newline into a space. Terminate the assignment with
`;` (`SKILL_DIR="…";` — without it, a flattened `SKILL_DIR="…" python3 "$SKILL_DIR/…"`
becomes an env-prefix whose `$SKILL_DIR` expands to empty **before** the assignment

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 112)May include surrounding context.

md
assets, so `$SKILL_DIR` only has to be right enough to launch `illo.py` and to
point `--ref` at the bundled character sheet.

Write the block **flatten-safe** — some hosts (Codex observed) collapse a fenced
block to one line, turning a newline into a space. Terminate the assignment with
`;` (`SKILL_DIR="...";` — without it, a flattened `SKILL_DIR="..." python3 "$SKILL_DIR/..."`
becomes an env-prefix whose `$SKILL_DIR` expands to empty **before** the assignment

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 719)May include surrounding context.

md
- **Grok Bot native sessions:** deliver the file returned by Grok Bot's
  built-in image tool inline/as an attachment in chat, and include its saved
  file path in the same role that engine renders use `.path`. The returned
  file is the original for this transport; do not ask the user to configure
  OpenRouter just to retrieve it.
- **Muse native sessions:** deliver the file returned by your native image
  tool as a `sandbox://workspace/...` link in chat, and include its saved

Static analysis

No suspicious patterns detected.