Back to skill

Security audit

Snap Illustrator

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its image-generation purpose, but it persists proxy settings in the skill itself and can use stored credentials without clear current-session consent.

Review before installing. Use it only with Markdown content you are comfortable sending to third-party image services, avoid storing proxy settings in SKILL.md, remove or disable plaintext config-token use, and require safe argument-array execution plus explicit confirmation for any file or provider changes.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:59
Finding

Shell Command Injection Through Unescaped Prompt, Output Path, and Proxy Values

Content
View full analysis
/images/img_name.jpg" ``` The proxy workflow similarly instructs the Agent to interpolate a user-provided proxy value: ```bash HTTPS_PROXY="" HTTP_PROXY="" node /path/to/skills/snap-illustrator/scripts/generate.mjs --prompt "..." --output "..." ``` The surrounding instructions direct the Agent to persist and reuse the supplied value: ```yaml metadata: openclaw: requires: env: - HF_TOKEN bins: - node http_proxy: "http://127.0.0.1:7890" ``` ```bash HTTPS_PROXY="" HTTP_PROXY="" node /path/to/skills/snap-illustrator/scripts/generate.mjs --prompt "..." --output "..." ``` ### Technical Analysis The Skill instructs the Agent to construct a shell command by interpolating three values that are not guaranteed to be trusted: 1. An image prompt derived from user-controlled Markdown content. 2. An output path derived from the user's workspace. 3. A proxy URL supplied directly by the user. Placing these values inside double quotes does not make them safe for shell execution. POSIX-compatible shells still evaluate command substitution expressions such as `$(command)` and backticks inside double-quoted strings. Embedded quotation marks can also terminate the intended argument and introduce shell operators or additional commands. The Node.js script itself parses an argument array and does not require shell interpretation. Consequently, invoking it through a command string introduces an unnecessary attack surface and exceeds the minimum execution mechanism needed for image generation. ### Attack Path 1. An attacker s ...[truncated 1526 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/generate.mjs:72
Finding

Undeclared Plaintext Hugging Face Token Access From the User Home Directory

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (12)

Self-Modification

High
Category
Rogue Agent
Confidence
98% confidence
Finding

The skill explicitly instructs the agent to modify its own SKILL.md to add persistent proxy metadata. Self-modification is dangerous because it changes future behavior of the tool, creates a durable configuration side effect outside the user's content, and opens the door to unauthorized or hard-to-audit alterations of the skill definition.

Content

Scanner excerpt · SKILL.md (reported line 96)May include surrounding context.

HTTPS_PROXY="<proxy_url>" HTTP_PROXY="<proxy_url>" node /path/to/skills/snap-illustrator/scripts/generate.mjs --prompt "..." --output "..."

text

**Recording the proxy for future use**: Update this SKILL.md file by appending the user's proxy setting to the frontmatter metadata section, so it can be reused automatically in subsequent runs:

```yaml
metadata:

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill advertises a zero-configuration experience but later instructs modification of SKILL.md to persist proxy configuration. That mismatch can mislead users about what the skill changes on disk and lowers informed consent around persistent configuration writes.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

md
**Default to Zero-Config Experience**:
1. By default, utilize the included Node.js script to run via the unauthenticated `Pollinations.ai` API. This process is **completely zero-config** and requires NO API tokens from the user.
2. As long as images generate successfully, DO NOT ask the user to configure any tokens. Let the user experience an instant, frictionless image insertion.
3. **ONLY IF** the Node.js script throws an exception or logs `PLEASE_ASK_USER_FOR_TOKEN`, indicating the free unauthenticated service is rate-limited or unavailable, should you proactively ask the user: "The free generation service is currently busy. Do you have a HuggingFace Token you could provide to continue?"
4. If the user provides a HuggingFace Token, instruct them to set it as an environment variable (e.g., `export HF_TOKEN="<your_token>"` in their `~/.zshrc` or `~/.bash_profile`), or temporarily use the token to run the script. AI agents should NOT permanently save tokens to disk unless explicitly requested by the user.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow states that image generation prompts must be 'English-only', which imposes a language policy on the user. There is no opt-in, alternative language choice, or documented region-specific reason for the restriction.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

Locating the script: This SKILL.md file is your reference — scripts/generate.mjs lives in the same directory as this file. You already know the absolute path to this SKILL.md (it was provided to you when the skill was loaded). Strip the filename to get the skill root directory, then append scripts/generate.mjs.

For example, if this skill file is at /path/to/skills/snap-illustrator/SKILL.md, then run:

bash
node /path/to/skills/snap-illustrator/scripts/generate.mjs --prompt "Your English Prompt Here" --output "<workspace>/images/img_name.jpg"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill directs the agent to modify the original markdown file and later also suggests modifying SKILL.md, but it does not require an explicit warning about these writes at the point of execution. Silent or insufficiently disclosed file edits can surprise users, damage content, or alter tool behavior beyond the task they intended.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill asks the user to disclose proxy configuration and then persist it without a clear privacy or security warning. Proxy addresses may be sensitive operational details, and storing them in the skill broadens exposure and can affect future executions without fresh consent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs the agent to collect a user-provided HTTP proxy and persist it for future reuse, even though proxy persistence is not necessary to illustrate markdown articles. Proxy endpoints can reveal sensitive network topology or route future traffic through infrastructure the user did not intend to store in the skill, creating an avoidable privacy and configuration integrity risk.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Persisting a user-provided proxy address into the skill file creates durable storage of sensitive network configuration and causes future runs to inherit it automatically. This can unintentionally leak internal infrastructure details, create cross-session behavior changes, and make later executions depend on stale or attacker-influenced routing.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
84% confidence
Finding

The instruction to automatically reuse the proxy in subsequent executions without asking again removes a fresh consent checkpoint for a sensitive networking setting. Automatic reuse can route later requests through infrastructure the user did not intend for new tasks and compounds the risk introduced by persistence.

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

http_proxy: "http://127.0.0.1:7890" # ← add proxy here

text

And in all subsequent script executions within this session, automatically prepend `HTTPS_PROXY="<proxy_url>" HTTP_PROXY="<proxy_url>"` to the command without asking the user again.

### Issue 4: All Services Unavailable

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script sends the full user-provided prompt to a third-party image-generation service (Pollinations) over the network without any explicit consent, warning, or privacy notice at the point of use. If prompts contain sensitive article content, internal drafts, proprietary data, or personal information, that data is disclosed externally by default.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

On Pollinations failure, the script automatically checks for HF_TOKEN in the environment and sends the prompt to HuggingFace without explicit user approval for that fallback path. This creates an additional undisclosed external disclosure path and may unexpectedly use ambient credentials present in the environment, increasing the chance of accidental data exfiltration.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/generate.mjs:79