Back to skill

Security audit

Ai Image Generator

Security checks for vulnerabilities and agentic risk

Overview

This is a simple Chinese-language AI image-generation skill description with no hidden execution, persistence, or destructive behavior found.

Before installing, use a virtual environment, pin dependency versions if possible, protect the API key, and avoid submitting confidential prompts or private images unless external API processing is acceptable.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:31
Finding

Unpinned Third-Party Python Dependencies

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 31
Vulnerability Type: Unpinned third-party dependencies
Risk Level: Medium

bash
pip install openai pillow

Technical Analysis

The installation command retrieves the latest available versions of the openai and pillow packages without version constraints or integrity hashes. Consequently, installations are not reproducible and may automatically consume a future compromised, malicious, or incompatible package release.

Python packages and their transitive dependencies can execute package-controlled code during installation or when imported at runtime. Although the referenced package names are legitimate and no malicious package is included in the audited project, the unrestricted dependency resolution creates a supply-chain exposure.

Attack Path

  1. An attacker compromises one of the named packages, a transitive dependency, or its distribution account.
  2. The attacker publishes a malicious release under a version accepted by the unrestricted installation command.
  3. A user follows the documented command after that release becomes available.
  4. pip downloads and installs the affected release.
  5. Malicious installation or runtime code executes under the installing user's account.

This attack path is conditional upon upstream supply-chain compromise; the audited file does not itself host or retrieve a known malicious dependency.

Impact Assessment

A compromised dependency could execute arbitrary code with the privileges of the user running pip or the resulting application. Potential effects include reading or modifying files accessible to that account, stealing application credentials such as API keys, tampering with generated content, and making unauthorized network requests. If installation is performed by a privileged account, the impact could extend to system-wide resources.

Remediation
View remediation

Remediation Suggestions

  • Pin every direct dependency to a reviewed, exact version.
  • Generate and commit a lock file that also constrains transitive dependencies.
  • Use cryptographic hashes, such as a hash-locked requirements file installed with pip --require-hashes.
  • Regularly scan dependencies for known vulnerabilities and review updates before changing pinned versions.
  • Install dependencies from the official Python Package Index or a controlled internal mirror.
  • Perform installation and execution inside an isolated virtual environment or container using a non-privileged account.
  • Document the tested Python and dependency versions so installations remain reproducible.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

SQP-3 applies to natural-language policy issues in all file types, including markdown. The file is entirely in Chinese and does not indicate any user opt-in, alternative language support, or justified locale restriction, which may conflict with a policy requiring language choice rather than forcing a specific language.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This is a markdown file, so SQP-2 applies to missing user warnings in the skill description. The document says users can upload reference images and perform image editing, but it does not disclose that user-provided images may be transmitted to an external API or processed by third-party services, which is relevant to user privacy and data handling.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.