Back to skill

Security audit

Mflux Image Router

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a local image-generation router, but it also teaches use of broader fleet APIs outside its stated image purpose.

Install only if you are comfortable running ollama-herd and mflux from current package releases, starting a local fleet router on port 11435, and exposing the documented local fleet APIs. Treat the non-image API examples as broader capability than the skill name suggests, and avoid sending sensitive text, audio, or prompts through them unless you intend that use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:24
Finding

Unpinned Third-Party Package Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 24–27
Vulnerability Type: Unpinned and unverified third-party dependencies
Risk Level: Medium

bash
pip install ollama-herd
herd                        # start the mflux image generation router (port 11435)
herd-node                   # start on each device running mflux
uv tool install mflux       # install mflux on devices for image generation

Technical Analysis

The installation instructions retrieve ollama-herd, mflux, and their transitive dependencies without version constraints, lockfiles, or package hash verification. Consequently, the installed code may differ from the version reviewed when this Skill was published.

Package installation can run package-controlled build or installation logic, while later invocation of herd, herd-node, or mflux executes the downloaded application code. Although these dependencies are necessary for the declared image-generation functionality and the document references corresponding PyPI and GitHub pages, those references do not provide cryptographic integrity or reproducible dependency resolution.

This creates supply-chain exposure if a package publisher account, package repository, release artifact, or transitive dependency is compromised. The audit found no evidence that the named packages are currently malicious or that the Skill intentionally uses a typosquatted source.

Attack Path

  1. An attacker compromises a package publisher account, upstream dependency, package repository, or future package release.
  2. The attacker publishes a modified version containing malicious installation or runtime logic.
  3. A user follows the Skill instructions and runs pip install ollama-herd or uv tool install mflux.
  4. The package manager resolves the latest available release and its transitive dependencies without validating them against reviewed hashes.
  5. Malicious code executes during installat ...[truncated 746 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin each direct dependency to a specific reviewed version, for example ollama-herd==<reviewed-version> and mflux==<reviewed-version>.
  2. Use a lockfile or hash-verified requirements file that constrains transitive dependencies as well as direct dependencies.
  3. Require package hashes where supported, such as pip install --require-hashes -r requirements.txt.
  4. Document the trusted package index explicitly and disable unintended fallback indexes to reduce dependency-confusion risk.
  5. Recommend installation in a dedicated virtual environment or isolated tool environment under an unprivileged user account.
  6. Review and update pinned versions through a controlled dependency-update process that includes provenance, vulnerability, and integrity checks.
  7. Avoid administrator or sudo installation unless separately justified and documented.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (13)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 137)May include surrounding context.

Track per-project mflux image generation in the dashboard:

bash
curl -o mflux_output.png http://localhost:11435/api/generate-image \
  -H "Content-Type: application/json" \
  -d '{
    "model": "z-image-turbo",

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Although not literally script fetching, this finding still points to documentation for an unrelated internal embeddings endpoint within an image-router skill. That increases the chance an agent will invoke additional internal services and transmit user data outside the expected scope, which is the real security concern here.

Content

Scanner excerpt · SKILL.md (reported line 166)May include surrounding context.

Embeddings

bash
curl http://localhost:11435/api/embeddings \
  -d '{"model":"nomic-embed-text","prompt":"search query"}'

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 177)May include surrounding context.

curl -s http://localhost:11435/dashboard/api/image-stats | python3 -m json.tool

Fleet health (includes mflux image generation activity)

curl -s http://localhost:11435/dashboard/api/health | python3 -m json.tool

text

Dashboard at `http://localhost:11435/dashboard` — mflux image generation queues show with [IMAGE] badge.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

Enable mflux image generation:

bash
curl -X POST http://localhost:11435/dashboard/api/settings \
  -H "Content-Type: application/json" \
  -d '{"image_generation": true}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

Generate an image with mflux

curl — mflux image generation

bash
# mflux image generation via fleet router

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

md
def mflux_generate_image(prompt, mflux_output_path="mflux_output.png", width=1024, height=1024):
    """Generate an image using mflux image generation via the fleet router."""
    mflux_resp = httpx.post(
        "http://localhost:11435/api/generate-image",
        json={
            "model": "z-image-turbo",

Internal Network Request

Medium
Category
Server-Side Request Forgery
Confidence
70% confidence
Finding

Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

md
def mflux_generate_image(prompt, mflux_output_path="mflux_output.png", width=1024, height=1024):
    """Generate an image using mflux image generation via the fleet router."""
    mflux_resp = httpx.post(
        "http://localhost:11435/api/generate-image",
        json={
            "model": "z-image-turbo",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

javascript
async function mfluxGenerateImage(prompt, width = 1024, height = 1024) {
  // mflux image generation via fleet router
  const mflux_resp = await fetch("http://localhost:11435/api/generate-image", {
    method: "POST",
    headers: { "Content-Type": "application/json" },
    body: JSON.stringify({

Internal Network Request

Medium
Category
Server-Side Request Forgery
Confidence
70% confidence
Finding

Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

javascript
async function mfluxGenerateImage(prompt, width = 1024, height = 1024) {
  // mflux image generation via fleet router
  const mflux_resp = await fetch("http://localhost:11435/api/generate-image", {
    method: "POST",
    headers: { "Content-Type": "application/json" },
    body: JSON.stringify({

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 137)May include surrounding context.

Track per-project mflux image generation in the dashboard:

bash
curl -o mflux_output.png http://localhost:11435/api/generate-image \
  -H "Content-Type: application/json" \
  -d '{
    "model": "z-image-turbo",

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill is presented as an mflux image router, but it also documents access to unrelated fleet APIs for chat completions, speech-to-text, and embeddings. That capability expansion increases attack surface and can induce an agent to use broader internal services than the user or manifest would reasonably expect, undermining least-privilege and enabling unintended data access or compute use.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Including guidance for non-image-generation APIs inside an image-generation skill is context-inappropriate and can steer an agent into invoking services outside the declared purpose. In an agent setting, that mismatch is dangerous because capability confusion can bypass operator expectations and lead to unauthorized internal API usage.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The embeddings example exposes an additional internal API unrelated to the skill's declared purpose, encouraging agents to send arbitrary text to another service on the fleet. In context, the problem is not mere transmission but undocumented capability expansion that can result in unintended data flow to internal inference systems.

Content

Scanner excerpt · SKILL.md (reported line 166)May include surrounding context.

Embeddings

bash
curl http://localhost:11435/api/embeddings \
  -d '{"model":"nomic-embed-text","prompt":"search query"}'

Static analysis

No suspicious patterns detected.