Back to skill

Security audit

tokenrouter-image-generator

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to perform the advertised TokenRouter image generation, but it uses and recommends risky API-key handling that users should review before installing.

Install only if you are comfortable sending prompts and selected images to TokenRouter. Prefer a session-scoped environment variable or protected secret store for the API key; avoid pasting keys into chat, passing them on the command line, or storing them permanently in shell startup files unless you understand the exposure risk. Use a revocable, limited key if available.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:62
Finding

API Key Exposure Through Chat and Command-Line Arguments

Content
View full analysis
dict[str, str]: headers = { "Authorization": f"Bearer {api_key}", "Content-Type": "application/json", } ``` ### Technical Analysis API credentials should not be entered into conversational channels or supplied through process command-line arguments. A key pasted into chat may be retained in conversation history, agent traces, telemetry, backups, or execution logs. When supplied through `--api-key`, it may also be visible in shell history, process listings, command auditing, diagnostic output, or orchestration logs. The credential is legitimately required to authenticate with TokenRouter, but exposing it thr ...[truncated 1948 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises commands that use environment variables, read local configuration files, write output files, and call an external network API, but it declares no explicit tool scope or permission boundaries. That omission increases the chance an agent can invoke broader capabilities than intended without clear review or consent controls.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

Generate new image:

bash
# Ensure outbound directory exists first
mkdir -p ~/.openclaw/media/outbound

uv run ~/.openclaw/workspace/skills/pbd-tokenrouter-image-generator/scripts/generate_image.py \
  --prompt "your image description" \

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

This section instructs the user to create a persistent API key and either paste it into chat or store it in shell startup files, both of which increase secret exposure and longevity. Persisting long-lived credentials in broadly readable or routinely sourced locations expands the blast radius if the host or account is later compromised.

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

md
- After login, navigate to the **API Keys** section
   - Find the **API Keys** menu in the sidebar/navigation
   - Click **API Keys** to enter the key management page
   - Create a new API key and copy it
4. Once the user has the key, offer two options:
   - **Option A — Provide the key directly to the agent:** The user can paste the key in the chat, and the agent passes it to the script via `--api-key`. This is the quickest way to get started — no environment setup needed.
   - **Option B — Configure as environment variable (persistent):**

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly tells users to paste an API key into chat, which can expose the credential to conversation logs, model providers, downstream tooling, or other agents with transcript access. A live API key is a reusable secret, so disclosure can enable unauthorized API use, billing abuse, and account compromise.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Encouraging direct submission of credentials through chat normalizes unsafe secret handling and creates an immediate path for secret disclosure. Because the agent then passes the key on the command line, the exposure can extend beyond chat logs into shell history or process inspection depending on execution environment.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 110)May include surrounding context.

md
- Preflight:
  - `command -v uv`
  - **API key check (CRITICAL):** The script will try `--api-key`, then `PBD_TOKENROUTER_API_KEY`, then auto-read from `~/.openclaw/openclaw.json` (tokenrouter provider). If all fail, **STOP** and guide the user to https://www.tokenrouter.com to register and get a TokenRouter API key (see "If no API key is found" section above)
  - `test -d ~/.openclaw/media/outbound || mkdir -p ~/.openclaw/media/outbound`
  - If editing: `test -f "path/to/input.png"`

- Common failures:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/generate_image.py (reported line 23)May include surrounding context.

python
from urllib import error, request


TOKENROUTER_URL = "https://api.tokenrouter.com/v1/chat/completions"
ASPECT_RATIO_CHOICES = ["1:1", "2:3", "3:2", "3:4", "4:3", "4:5", "5:4", "9:16", "16:9", "21:9"]
IMAGE_SIZE_CHOICES = ["1K", "2K", "4K"]

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script silently falls back to reading API keys from the agent-wide ~/.openclaw/openclaw.json provider configuration, expanding its credential access beyond the explicitly declared CLI flag and environment variable inputs. In an agent skill context, this increases secret exposure and violates least-privilege expectations because a user invoking image generation may not realize the skill can harvest broader stored credentials and transmit them to an external service.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.