T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/replicate_cli.js:91- Finding
Unrestricted Local File Read and Upload to Replicate
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill performs the advertised cloud image-editing workflow, but it gives user-controlled paths and URLs enough reach to upload arbitrary readable files, fetch internal URLs, or overwrite writable files.
Review before installing. Use only non-sensitive images you are authorized to send to Replicate/SeedVR2, avoid private business interiors or identifiable people without consent, do not pass arbitrary local paths or internal URLs, and run it in a sandbox limited to dedicated input and output folders.
scripts/replicate_cli.js:91Unrestricted Local File Read and Upload to Replicate
scripts/replicate_cli.js:73Server-Side Request Forgery Through Unrestricted Image URLs
scripts/replicate_cli.js:174Arbitrary File Overwrite Through Unrestricted Output Path
The skill clearly relies on environment secrets (REPLICATE_API_TOKEN) and network access to remote services and URLs, yet it declares no explicit tool scope or permission boundaries. This can cause the agent runtime to grant broader-than-necessary capabilities by default, making secret access and outbound requests insufficiently constrained in a workflow that accepts user-influenced URLs and file paths.
The skill instructs users to send local scene images and optional model image URLs to third-party services (Replicate and SeedVR2) and to write generated outputs locally, but it provides no explicit privacy notice, consent requirement, or data-handling warning. Because the content involves real-world store scenes and person images, users may unknowingly transmit sensitive personal, commercial, or copyrighted material to external processors.
The hard-coded Replicate API endpoint confirms that image data is intentionally sent to an external service. In an image-processing skill focused on local-life/store photography and model compositing, this is particularly sensitive because photos may contain biometric data, identifiable interiors, branding, or customer information.
quality: 'low',
}
const res = await fetch('https://api.replicate.com/v1/models/openai/gpt-image-2/predictions', {
method: 'POST',
headers: { 'Content-Type': 'application/json', Authorization: `Bearer ${token}` },
body: JSON.stringify({ input }),
The hard-coded Replicate API endpoint confirms that image data is intentionally sent to an external service. In an image-processing skill focused on local-life/store photography and model compositing, this is particularly sensitive because photos may contain biometric data, identifiable interiors, branding, or customer information.
quality: 'low',
}
const res = await fetch('https://api.replicate.com/v1/models/openai/gpt-image-2/predictions', {
method: 'POST',
headers: { 'Content-Type': 'application/json', Authorization: `Bearer ${token}` },
body: JSON.stringify({ input }),
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
}
async function getPrediction(id, token) {
const res = await fetch(`https://api.replicate.com/v1/predictions/${id}`, {
headers: { Authorization: `Bearer ${token}` },
})
if (!res.ok) {
The endpoint usage at this line represents an external processing step for upscaling and therefore a genuine data-transfer risk in this skill. Because the skill defaults to using remote template URLs and accepts remote/user-supplied inputs, the overall workflow increases the likelihood that personal or copyrighted imagery is transmitted to third parties without strong provenance or privacy controls.
}
async function createUpscalePrediction(token, mediaUrl) {
const res = await fetch('https://api.replicate.com/v1/predictions', {
method: 'POST',
headers: { 'Content-Type': 'application/json', Authorization: `Bearer ${token}` },
body: JSON.stringify({
The endpoint usage at this line represents an external processing step for upscaling and therefore a genuine data-transfer risk in this skill. Because the skill defaults to using remote template URLs and accepts remote/user-supplied inputs, the overall workflow increases the likelihood that personal or copyrighted imagery is transmitted to third parties without strong provenance or privacy controls.
}
async function createUpscalePrediction(token, mediaUrl) {
const res = await fetch('https://api.replicate.com/v1/predictions', {
method: 'POST',
headers: { 'Content-Type': 'application/json', Authorization: `Bearer ${token}` },
body: JSON.stringify({
The embedded default prompt is entirely in Chinese and imposes a specific language/locale choice by default. There is no indication that the skill is region-specific, nor any option disclosure that language can be chosen by the user before this default is applied.
The script defines a default prompt entirely in Chinese, which implicitly forces a specific language/locale when the user does not supply their own prompt. The file does not present this as an opt-in or document a justified region-specific constraint.
The script automatically chooses an output file path under the skill directory and passes it to the downstream CLI for writing. While it prints the output path later, there is no explicit warning, confirmation, or comment/docstring disclosing that the command will create a new file on disk.
Detected: suspicious.env_credential_access, suspicious.potential_exfiltration