Back to skill

Security audit

视觉素材美工虾

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed image-generation helper with some overstated capabilities and optional cloud/API use, but no evidence of hidden, destructive, or exfiltrating behavior.

Install only if you are comfortable with a Chinese-language image-generation workflow. Treat local generation as the privacy-preferred mode; when using DALL-E 3, prompts are sent to OpenAI, and any Feishu upload should be an explicit user-selected action. Expect some advertised features to be incomplete.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

整体主用途基本一致,确实是视觉素材/图片生成工具,且支持海报、封面、数字人背景等场景,也有prompt拼接与模板能力。但声明中若干核心能力与支持范围被夸大:代码没有实现结构化JSON输入解析,只接受CLI参数;没有任何后期处理逻辑;没有飞书云盘上传能力;注释声称支持文心一格,但实际代码路径中不存在对应实现。因此描述不能准确代表实际行为,属于能力声明与实现不一致的情况。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill instructs use of local scripts, local workspace output, and optional Feishu cloud upload, but it does not declare any explicit tool scope or permissions boundaries. This creates an authorization and transparency gap: an agent may invoke filesystem, environment, or network-capable operations without a clearly constrained allowlist, increasing the risk of unintended data access or exfiltration.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad everyday terms like '设计', '封面', and '配图', which can cause the skill to activate in contexts where the user did not intend image generation or local/cloud output. Over-broad activation raises the chance of unintended tool use, accidental processing of sensitive prompts, and surprise file creation or upload workflows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill mentions optional upload to Feishu cloud storage but does not prominently warn users in the main description that generated content may leave the local environment. This weakens informed consent and can lead to accidental disclosure of sensitive or proprietary visual materials if users assume output remains local.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Line L019 explicitly instructs use of "中文[标题文字]" in the poster template, which is a natural-language locale requirement. Because the file does not state that the templates are China-specific or offer an alternative language option, this can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module title and top-level description force a specific language/locale in user-facing natural language. Under the policy, language constraints should either be optional for the user or clearly documented as region-specific and justified, which is not present here.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest mentions AI model invocation, so remote image generation can be within scope, but the implementation also reads OPENAI_API_KEY from the ambient environment. Accessing credentials from environment state is a separate capability that is not described in the manifest text and can matter for developer intent and deployment trust.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This markdown file contains user-facing guidance exclusively in Chinese and does not mention whether other languages are supported or whether Chinese is an intentional user-selected locale. Under the policy rule, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The manifest describes a visual-content generator whose core flow is prompt optimization, model invocation, post-processing, and output. While model invocation itself is expected, directly reading runtime environment configuration such as workspace paths from OPENCLAW_WORKSPACE expands capability into ambient environment access that is not explicitly part of the stated purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The manifest supports AI model invocation, but does not state that the actual model can be selected through ambient environment configuration. This creates hidden operational behavior beyond the user-facing prompt/template functionality described by the skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.