Back to skill

Security audit

使用火山引擎豆包模型生成图片。 通过火山引擎豆包图片生成 API 创建图片。支持自定义提示词、尺寸、模型等参数。 ## 环境变量 - VOLCENGINE_IMAGE_API_KEY - 豆包 API Key(必填) ## 使用方式 生图:一只可爱的小猫 ## 支持的尺寸 1024x1024, 1280x720, 720x1280, 1024x768, 768x1024

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to generate images as advertised, but it needs review because it automatically downloads external content to a hard-coded local path with weak safeguards.

Install only if you are comfortable sending prompts and API-key-authenticated requests to Volcengine. Review or change the script before use so downloads have timeouts, size and content checks, validated image hosts, and a user-chosen output directory instead of the hard-coded C:/Users/zcf path. Do not include secrets, private data, or regulated content in prompts.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate.py:52
Finding

Unrestricted and Unbounded Download from an API-Controlled URL

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (9)

Tainted flow: 'headers' from os.environ.get (line 35, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/generate.py (reported line 50)May include surrounding context.

python
print(f"正在生成: {prompt}")
    print(f"模型: {model}, 尺寸: {size}")
    
    response = requests.post(API_BASE_URL, headers=headers, json=payload)
    
    if response.status_code != 200:
        print(f"错误: {response.status_code}")

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill appears to use environment variables and network access, but the manifest does not declare any tool scope such as permissions or allowed-tools. This weakens transparency and policy enforcement, making it easier for a skill to access secrets and exfiltrate user-provided content to an external service without clear user-facing declaration.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The invocation example and description are broad enough that normal conversational text about generating an image could trigger the skill without clear boundaries. Over-broad triggers can cause unintended activation, sending user prompts to a third-party API and producing side effects such as API usage costs and local file creation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill documentation describes image generation but does not clearly warn that prompts are transmitted to an external image-generation API. Users may unknowingly send sensitive or regulated data off-platform, creating privacy, confidentiality, and compliance risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file contains natural-language descriptions, help text, and runtime messages exclusively in Chinese, including the module docstring and CLI-facing strings. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/generate.py (reported line 50)May include surrounding context.

python
print(f"正在生成: {prompt}")
    print(f"模型: {model}, 尺寸: {size}")
    
    response = requests.post(API_BASE_URL, headers=headers, json=payload)
    
    if response.status_code != 200:
        print(f"错误: {response.status_code}")

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description says it generates images via an API, but the code also automatically downloads remote content and writes it locally without making that side effect explicit to the user. This expands the trust boundary from API interaction to filesystem modification and remote content retrieval, which can surprise users and create unnecessary local persistence of untrusted data.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Writing files to a hard-coded user-specific path is unsafe because it assumes a particular host layout and silently persists data outside the caller's chosen workspace. In agent or shared environments, this can cause unintended data placement, privacy issues, or overwrite/conflict risks, especially since the downloaded file originates from a remote URL.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

Although the output section mentions saving images to downloads/images, the skill description does not prominently warn that generated files are automatically written to local storage. This can surprise users, create data residue on disk, and expose generated content to other local users or processes.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.