Back to skill

Security audit

GPT Image 2 图生图

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a disclosed AI image-generation helper, but its result download code can let remote task metadata write files outside the chosen output folder.

Review this before installing. Use it only with a trusted AI Hive account and authorized reference images, prefer a dedicated output directory, avoid sensitive working directories, and consider fixing filename sanitization before routine use. Store the API key only if you are comfortable with a local config file at `~/.ai-hive/config.json`.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/imagegen.py:358
Finding

Path Traversal Through Untrusted Task Metadata During Result Download

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:70
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis
``` ### Technical Analysis The installation instructions retrieve the latest available release of `requests` and its transitive dependencies without version constraints or integrity hashes. Although `requests` is a legitimate package and the documentation does not use a misspelled package name or an explicitly untrusted index, the unpinned command makes installation non-reproducible. Future releases or altered transitive dependency resolution can introduce incompatible behavior or newly compromised components without changes to the audited project. Because Python packages can execute installation or build logic, compromise of the selected package release or package index can result in code execution during installation. ### Attack Path 1. A user follows the documented installation command. 2. `pip3` resolves the newest available `requests` release and transitive dependencies from its configured package index. 3. A future compromised release, compromised dependency, or compromised package index provides malicious package content. 4. Package installation or later import executes the supplied code with the privileges of the user running `pip3` or the Skill. This path depends on an upstream supply-chain compromise or unsafe local package-index configuration; no malicious dependency is embedded in the audited repository. ### Impact Assessment If dependency resolution returns a malicious package, it can execute code with the privileges of the installing user. Depending on those privileges, consequences may include: - Reading user-accessible files and environment variables. - Acces ...[truncated 365 chars]
Remediation
View remediation
--hash=sha256: ``` 3. Install with hash verification: ```bash python3 -m pip install --require-hashes -r requirements.txt ``` 4. Use an isolated virtual environment rather than the system Python installation. 5. Periodically review and deliberately update pinned versions after vulnerability and compatibility testing. 6. Document the expected package index and avoid untrusted extra indexes. ]]>
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill invokes a local Python script that performs network access, file reads/writes, environment usage, and shell execution, but the manifest does not declare any tool scope or permissions boundaries. This weakens least-privilege guarantees and makes it easier for an agent runtime or reviewer to underestimate the skill's capabilities, increasing the chance of unintended file access, outbound requests, or credential handling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill’s natural-language description, headings, instructions, and examples are entirely in Chinese, which effectively imposes a specific language on users. The file does not indicate that Chinese is optional, nor does it offer an alternative locale or language choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

This markdown file contains user-facing natural-language content only in Chinese, which can constitute a language/locale policy violation if users are not given an opt-in or alternative language. Nothing in the file indicates that the skill is region-specific or that language selection is optional.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The sample API key placeholder uses Chinese text ('请替换为你的APIKey'), which imposes a specific language in user-facing configuration content. The file does not offer a language choice or explain that the skill is intentionally region- or locale-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.