Back to skill

Security audit

Action Figure Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to do its advertised image-generation job, but it handles an API token in an unsafe and partly inconsistent way that users should review before installing.

Review before installing. Use this only with non-sensitive prompts and image references, prefer a pinned or trusted installer path, and avoid putting a real Neta token directly on the command line until the skill supports reading NETA_TOKEN from the environment or another safer secret source.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
actionfigure.js:3
Finding

API Token Exposed Through Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: actionfigure.js:3-14, SKILL.md:11-20, README.md:57-63
Vulnerability Type: API credential exposure through process arguments
Risk Level: Medium

Vulnerable Code

actionfigure.js:3-14:

javascript
// --- Argument parsing ---
const args = process.argv.slice(2);
let prompt = null;
let size = "portrait";
let tokenFlag = null;
let refUuid = null;

for (let i = 0; i < args.length; i++) {
  if (args[i] === "--size" && args[i + 1]) {
    size = args[++i];
  } else if (args[i] === "--token" && args[i + 1]) {
    tokenFlag = args[++i];

SKILL.md:11-20:

bash
export NETA_TOKEN=your_token_here
node <script> "your prompt" --token "$NETA_TOKEN"
bash
node actionfigure.js "your description here" --token YOUR_TOKEN

README.md:57-63:

markdown
This skill requires a Neta API token (free trial available at <https://www.neta.art/open/>).

Pass it via the `--token` flag:

```bash
node <script> "your prompt" --token YOUR_TOKEN
text

### Technical Analysis

The implementation obtains the API token exclusively from `process.argv`. Command-line arguments are commonly exposed through operating-system process inspection interfaces for at least the lifetime of the process. Depending on the operating system and process isolation settings, another local user or process may be able to inspect the command line and recover the token.

The documented example using a literal `YOUR_TOKEN` value also encourages users to type a credential directly into a shell command. In that usage pattern, the command may remain in shell history. Although the Skill metadata declares a `NETA_TOKEN` environment variable, `actionfigure.js` does not read `process.env.NETA_TOKEN`; the environment variable is expanded and passed back into the process argument list by the documented command.

The token is subsequently
...[truncated 1364 chars]
Remediation
View remediation

Remediation Suggestions

  1. Read the token from process.env.NETA_TOKEN by default:

    javascript
    const TOKEN = process.env.NETA_TOKEN || tokenFlag;
    
  2. Update all usage examples to avoid putting credentials on the command line:

    bash
    export NETA_TOKEN="your-token"
    node actionfigure.js "your prompt"
    
  3. Prefer credential injection through a secrets manager in CI and hosted environments.

  4. If --token is retained for compatibility, explicitly warn that it may expose the token through process listings and shell history.

  5. Optionally support reading the token from a protected file or standard input without echo.

  6. Ensure errors and diagnostic logs never print the request headers or token.

  7. Recommend rotating the token if it has previously been entered literally into shell history or exposed in process logs.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:31
Finding

Unpinned Package Executed by Documented npx Installation Command

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:31-35, README.md:10-14
Vulnerability Type: Unpinned third-party installer and supply-chain exposure
Risk Level: Medium

Vulnerable Code

SKILL.md:31-35:

markdown
## Install
```bash
npx skills add TomCarranzaem/action-figure-skill
text

`README.md:10-14`:

```markdown
**Via npx skills:**
```bash
npx skills add TomCarranzaem/action-figure-skill
text

### Technical Analysis

The documented installation command invokes `npx skills` without specifying a reviewed package version or integrity value. If the package is not already available locally, `npx` can retrieve the currently resolved release and execute its command-line entry point.

Consequently, the code executed during installation is not fixed to the version reviewed with this project. A future compromised or malicious release of the `skills` package, a compromised publisher account, or unsafe package-registry resolution could change the effective installer behavior without modifying this repository.

No malicious dependency or currently compromised package was identified in the audited files. The finding concerns the unsafe, mutable execution path recommended by the documentation.

### Attack Path

1. An attacker compromises the upstream package, its publisher account, or another relevant package publication channel.
2. The attacker publishes a modified release containing malicious installation behavior.
3. A user follows the documented unversioned `npx skills add ...` command.
4. Package resolution selects and downloads the attacker-controlled release.
5. `npx` executes the downloaded package under the user's account.
6. The malicious package can perform actions available to that user, such as reading user-accessible files, modifying configuration, stealing environment credentials, or installing additional software.

Exploitation depends on compromise or malicious modif
...[truncated 724 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the installer to a specifically reviewed version:

    bash
    npx skills@REVIEWED_VERSION add TomCarranzaem/action-figure-skill
    
  2. Where supported, verify package integrity, provenance, or signatures before execution.

  3. Document the expected registry and official package publisher to reduce dependency-confusion and spoofing risks.

  4. Prefer a trusted, already installed version of the installer rather than downloading executable code at invocation time.

  5. Use a lockfile or equivalent immutable dependency mechanism for automated installation workflows.

  6. Run installation with least privilege and without unrelated secrets in the environment.

  7. Periodically review the pinned installer version and update it only after inspecting the new release.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

A description-behavior mismatch is especially dangerous in an agent skill because users and orchestrators rely on the manifest to decide whether to trust and invoke it. If the code actually calls a different external service, supports undeclared reference-based image editing, and requires an auth token without proper disclosure, it can exfiltrate prompts or assets to an unexpected third party and perform actions outside the user's informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README prominently states that prompts and optional reference image UUIDs are sent to a third-party image generation API, but it does not clearly warn users that their inputs will leave the local environment. Users may unknowingly transmit sensitive prompts, identifiers, or proprietary creative material to an external service, creating privacy, confidentiality, and compliance risks.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

The README instructs users to install and execute a remote skill via npx skills without pinning a specific version. That allows the fetched package or dependency resolution to change over time, which can expose users to a supply-chain attack or unexpected code execution if the upstream package is modified or compromised.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

This second unpinned npx skills reference again encourages execution of remotely retrieved code without constraining the version. Repeated examples normalize unsafe installation practices and increase the likelihood that users will run whatever current package is served, including potentially malicious updates.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill declares only tools: Bash and does not explicitly scope or disclose its network access, even though its stated function depends on calling an external API and handling an auth token. This can mislead reviewers and users about the skill's real capabilities, increasing the chance of unintended data egress or execution in environments that would have rejected it if network use were declared.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger guidance is broad enough that an agent may invoke the skill for loosely related image-generation requests without clear user intent or awareness that external API calls and token use are involved. In agent environments, vague invocation boundaries increase the risk of accidental data sharing and unexpected third-party requests.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
83% confidence
Finding

Using npx skills add TomCarranzaem/action-figure-skill without a pinned version allows whatever package or referenced content is current at install time to be fetched and executed. That creates a supply-chain risk where a later malicious or compromised update could change the installed skill behavior without the user realizing it.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · actionfigure.js (reported line 73)May include surrounding context.

js
// --- Submit job ---
async function main() {
  const makeRes = await fetch("https://api.talesofai.com/v3/make_image", {
    method: "POST",
    headers: HEADERS,
    body: JSON.stringify(body),

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · actionfigure.js (reported line 73)May include surrounding context.

js
// --- Submit job ---
async function main() {
  const makeRes = await fetch("https://api.talesofai.com/v3/make_image", {
    method: "POST",
    headers: HEADERS,
    body: JSON.stringify(body),

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · actionfigure.js (reported line 102)May include surrounding context.

js
// --- Submit job ---
async function main() {
  const makeRes = await fetch("https://api.talesofai.com/v3/make_image", {
    method: "POST",
    headers: HEADERS,
    body: JSON.stringify(body),

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This JavaScript code sends the user-supplied prompt and authentication token to an external API via HTTP requests. While the behavior is visible in code, there is no confirmation prompt, user-facing notice, or explanatory comment/docstring warning that prompt content and identifiers will be transmitted off-system.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.