Back to skill

Security audit

Image Generator

Security checks for vulnerabilities and agentic risk

Overview

The skill largely does image generation as advertised, but it needs review because it may send an unrelated generic API credential along with prompts or images to SiliconFlow.

Review before installing. Use only a dedicated SILICONFLOW_API_KEY for this skill, avoid running it in sessions where a generic API_KEY contains another service's token, and do not pass sensitive prompts or private image paths unless you are comfortable uploading that content to SiliconFlow.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/img2img.py:18
Finding

Generic API Key Fallback May Disclose an Unrelated Credential

Content
View full analysis

Vulnerability Details

File Location: scripts/img2img.py, lines 18–21 and 72–76
Vulnerability Type: Improper credential selection and unintended secret disclosure
Risk Level: Medium

Vulnerable Code

python
for name in ('SILICONFLOW_API_KEY', 'API_KEY'):
    v = os.environ.get(name)
    if v:
        return v
python
headers = {
    'Authorization': f'Bearer {load_key()}',
    'Content-Type': 'application/json',
}
resp = requests.post(API_URL, headers=headers, json=payload, timeout=180)

The same credential-selection flaw also appears in scripts/txt2img.py, lines 17–20 and 55–59.

Technical Analysis

The script first looks for the provider-specific SILICONFLOW_API_KEY environment variable, but it then falls back to the generic API_KEY variable. A generic variable does not establish that the credential belongs to SiliconFlow. It may contain a token for an unrelated provider or internal service.

When SILICONFLOW_API_KEY is absent and API_KEY is present, the script automatically places that value in an HTTP Authorization header and transmits it to the fixed SiliconFlow endpoint:

text
https://api.siliconflow.cn/v1/images/generations

This violates least-privilege and explicit-secret-selection principles. The scripts should only access credentials specifically designated for their declared service. HTTPS protects the credential in transit but does not prevent disclosure to the unintended recipient.

The Base64 handling in scripts/img2img.py is not itself a vulnerability. It serializes an explicitly selected reference image into a data URL for the documented image-to-image API request.

Attack Path

  1. An Agent, automation environment, or user session exposes an unrelated credential through the generic API_KEY environment variable.
  2. The provider-specific SILICONFLOW_API_KEY variable is not set.
  3. The user or Agent invokes scripts/img2img.py with a prompt and reference image.
  4. load_key() sel ...[truncated 859 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the generic API_KEY fallback from both scripts:
python
key = os.environ.get('SILICONFLOW_API_KEY')
if key:
    return key
  1. Accept only credentials explicitly associated with SiliconFlow, such as SILICONFLOW_API_KEY or a validated siliconflow.apiKey configuration entry.

  2. Fail closed with a clear error when the provider-specific credential is unavailable rather than guessing that another secret is compatible.

  3. Avoid sourcing credentials from unrelated configuration sections. In particular, do not reuse a memory-search credential solely because its base URL contains a provider domain; use a dedicated image-generation credential entry.

  4. Update both scripts consistently and add tests confirming that:

    • SILICONFLOW_API_KEY is accepted.
    • A standalone generic API_KEY is rejected.
    • Missing provider-specific credentials terminate execution before any network request.
    • Credentials are never printed in normal output or error messages.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/txt2img.py:17
Finding

Generic API Key Fallback May Disclose an Unrelated Credential

Content
View full analysis

Vulnerability Details

File Location: scripts/txt2img.py, lines 17–20 and 55–59
Vulnerability Type: Improper credential selection and unintended secret disclosure
Risk Level: Medium

Vulnerable Code

python
for name in ('SILICONFLOW_API_KEY', 'API_KEY'):
    v = os.environ.get(name)
    if v:
        return v
python
headers = {
    'Authorization': f'Bearer {load_key()}',
    'Content-Type': 'application/json',
}
resp = requests.post(API_URL, headers=headers, json=payload, timeout=180)

Technical Analysis

The generic API_KEY fallback does not verify that the selected secret belongs to SiliconFlow. If SILICONFLOW_API_KEY is absent, any credential stored under API_KEY is used as a bearer token and sent to the fixed SiliconFlow image-generation endpoint. This creates an unintended credential-disclosure channel and exceeds the minimum access required by the text-to-image function.

Attack Path

  1. An unrelated service credential is available in the process environment as API_KEY.
  2. SILICONFLOW_API_KEY is unset.
  3. The script is invoked for text-to-image generation.
  4. load_key() returns the unrelated credential.
  5. The script transmits it to SiliconFlow in the Authorization header.

Impact Assessment

The complete unrelated token may be disclosed. Any subsequent harm is bounded by that token's permissions but could include unauthorized service access, data exposure, quota consumption, or financial loss. No local code execution, persistence, or privilege escalation was identified.

Remediation
View remediation

Remediation Suggestions

Remove support for the generic API_KEY variable and require SILICONFLOW_API_KEY or a dedicated, validated SiliconFlow configuration field. Ensure credential resolution fails before making a network request when no provider-specific key is available. Add regression tests proving that unrelated generic credentials are never selected or transmitted.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill also omits that it reads API credentials from environment variables and local OpenClaw configuration files. Undeclared access to env/config is sensitive because these sources often contain secrets, and users may not expect a nominal image-generation skill to inspect local configuration material.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding

The skill also omits that it reads API credentials from environment variables and local OpenClaw configuration files. Undeclared access to env/config is sensitive because these sources often contain secrets, and users may not expect a nominal image-generation skill to inspect local configuration material.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill documents capabilities that require environment access, local file reads, and outbound network calls, but it does not declare any corresponding tool scope or permissions. This creates an authorization and transparency gap: a caller or platform may invoke the skill without realizing it can access local secrets/configuration and transmit data externally.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

md
Use this skill when you want to:
- turn prompts into social covers, posters, or concept visuals
- create image variations from an existing reference image
- keep the workflow on the correct image-generation endpoint and model

## Quick Start

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation explains API key setup and returning raw responses but does not warn that prompts and reference images are transmitted to a third-party SiliconFlow service. This is a real privacy and data-handling issue because users may submit sensitive creative briefs or local images without informed consent about external sharing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code loads an API key from local environment/configuration and sends user-supplied image content to a third-party service, but there is no built-in consent, warning, or policy check before transmission. In a skill context, this can cause users or calling agents to unknowingly exfiltrate local images or sensitive prompts to a remote provider using locally discovered credentials.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script retrieves credentials not only from dedicated SiliconFlow configuration but also from an unrelated agents.defaults.memorySearch.remote section if its baseUrl contains siliconflow.cn. This broad credential harvesting exceeds the stated image-generation purpose and can unintentionally repurpose secrets configured for another subsystem, violating least-privilege and increasing the chance of cross-feature secret misuse.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This line performs the actual outbound transmission of prompt data and image data to the SiliconFlow API. While expected for an image-generation skill, it is still a true data-exfiltration boundary because any local file resolved by image_path is encoded and sent off-host, which is dangerous if callers can supply sensitive files or are not clearly informed.

Content

Scanner excerpt · scripts/img2img.py (reported line 78)May include surrounding context.

python
'Authorization': f'Bearer {load_key()}',
        'Content-Type': 'application/json',
    }
    resp = requests.post(API_URL, headers=headers, json=payload, timeout=180)
    try:
        data = resp.json()
    except Exception:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/img2img.py (reported line 12)May include surrounding context.

python
pathlib.Path('E:/openclaw/.openclaw/openclaw.json'),
    pathlib.Path('E:/openclaw/.openclaw/openclaw.json'),
]
API_URL = 'https://api.siliconflow.cn/v1/images/generations'
MODEL = 'Kwai-Kolors/Kolors'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/txt2img.py (reported line 11)May include surrounding context.

python
pathlib.Path('E:/openclaw/.openclaw/openclaw.json'),
    pathlib.Path('E:/openclaw/.openclaw/openclaw.json'),
]
API_URL = 'https://api.siliconflow.cn/v1/images/generations'
MODEL = 'Kwai-Kolors/Kolors'

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script retrieves credentials not only from a dedicated SILICONFLOW_API_KEY variable but also from a generic API_KEY variable and an unrelated memorySearch.remote config section. This overbroad credential sourcing can cause unintended secret reuse, allowing the skill to transmit a different service's API key to SiliconFlow and violating least-privilege expectations.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/txt2img.py (reported line 61)May include surrounding context.

python
'Authorization': f'Bearer {load_key()}',
        'Content-Type': 'application/json',
    }
    resp = requests.post(API_URL, headers=headers, json=payload, timeout=180)
    try:
        data = resp.json()
    except Exception:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script sends user-supplied prompts along with an authenticated request to a third-party API, but the file contains no disclosure, consent, or guardrail indicating that prompt contents leave the local environment. If users provide sensitive business data or personal information in prompts, that data is externally transmitted without an explicit warning at the skill level.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The description says to use the skill when users ask "生成配图/做海报/文生图/图生图," making part of the activation guidance language-specific. Although the file is bilingual overall, this trigger guidance does not explicitly offer equivalent user-language choice at that point, which may create a locale bias in invocation behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.