Back to skill

Security audit

Infographic Image

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it advertises: it turns provided content into Chinese infographic prompts/images using DashScope and saves the results locally.

Install only if you want a Chinese-focused DashScope workflow. Do not pass confidential documents unless you are comfortable sending their contents to DashScope, and choose output paths carefully because the script writes generated prompt/image files locally.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate_infographic.py:396
Finding

Unvalidated Remote URL Allows Unrestricted Network Requests and Arbitrary Content Downloads

Content
View full analysis
Optional[str]: if isinstance(node, str): if node.startswith("http://") or node.startswith("https://"): return node return None if isinstance(node, list): for item in node: url = deep_find_first_url(item) if url: return url return None if isinstance(node, dict): for key, value in node.items(): if "url" in key.lower() and isinstance(value, str): if value.startswith("http://") or value.startswith("https://"): return value url = deep_find_first_url(value) if url: return url return None ``` ```python def download_file(url: str, output_path: Path, timeout: int = 120) -> None: req = request.Request(url=url, method="GET") try: with request.urlopen(req, timeout=timeout) as resp: data = resp.read() except Exception as exc: raise RuntimeError(f"failed to download image: {exc}") from exc output_path.write_bytes(data) ``` ### Technical Analysis The script recursively accepts the first string beginning with `http://` or `https://` anywhere in the image-generation service response. It does not verify that the URL belongs to an expected DashScope or Alibaba image-storage domain. The selected URL is passed directly to `urllib.request.urlopen()`, which may follow redirects. The implementation does not: - Require HTTPS. - Restrict destination hostnames. - reject loopback, private, link-local, or cloud metadata addresses. - Revalidate destinations after redirects or DNS resolution. - Verify that the response is an image. - Vali ...[truncated 2326 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (25)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

md
使用 `scripts/generate_infographic.py` 将任意输入内容压缩为稳定的中文视觉生图提示词,再调用 DashScope 默认模型 `qwen-image-2.0-pro` 出图并下载到本地。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

md
使用 `scripts/generate_infographic.py` 将任意输入内容压缩为稳定的中文视觉生图提示词,再调用 DashScope 默认模型 `qwen-image-2.0-pro` 出图并下载到本地。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

md
使用 `scripts/generate_infographic.py` 将任意输入内容压缩为稳定的中文视觉生图提示词,再调用 DashScope 默认模型 `qwen-image-2.0-pro` 出图并下载到本地。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

md
使用 `scripts/generate_infographic.py` 将任意输入内容压缩为稳定的中文视觉生图提示词,再调用 DashScope 默认模型 `qwen-image-2.0-pro` 出图并下载到本地。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

md
使用 `scripts/generate_infographic.py` 将任意输入内容压缩为稳定的中文视觉生图提示词,再调用 DashScope 默认模型 `qwen-image-2.0-pro` 出图并下载到本地。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

md
2. 模板级规则放在 `references/meta-prompt*.md`,不要把长规则堆回 `SKILL.md`。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill invokes a Python script that uses environment variables, reads local files, writes outputs locally, and sends content to DashScope, but the manifest does not declare any tool scope or permissions boundaries. This creates an authorization and transparency gap: an agent may expose file, network, or write capabilities more broadly than a user expects when invoking what appears to be a simple image-generation skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description says the skill '稳定转换成中文视觉生图提示词', which indicates a fixed Chinese-language output behavior. The file does not mention any user opt-in, language selection, or justification for restricting output to Chinese, which conflicts with the policy against forcing a specific language without user choice.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The description uses broad trigger phrases like turning arbitrary text, reports, notes, or documents into images, which can match many ordinary user requests and cause the skill to activate in contexts where the user did not intend external transmission or file output. In this skill, over-broad matching is more risky because activation may lead to reading local files and sending their contents to a third-party model service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The markdown does not clearly warn that input text or files are transmitted to DashScope and that generated prompts/images are saved to local storage. This is dangerous because users may supply sensitive documents under the assumption processing is local, leading to unintended disclosure to a third party and persistent local artifacts containing sensitive content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill description and default prompt hard-code Chinese output without indicating that this is optional or user-selectable. This is not a classic security bug, but it can cause user intent mismatch and may lead to accidental transmission or transformation of content into an unexpected language, which can reduce transparency and increase the risk of misleading outputs in multilingual environments.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The default invocation text is broad enough to match many ordinary user requests about topics, articles, reports, or notes, which can cause the skill to activate without clear user intent. Because this skill can transform user content and optionally render images, overly permissive activation boundaries increase the chance of unexpected tool use, unintended data disclosure to downstream model providers, or confusing behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file explicitly requires that all visible text in the generated infographic be Simplified Chinese. This is a natural-language locale restriction, and the document does not provide user opt-in, alternatives, or a region-specific justification for enforcing that language choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction '必须提取中文内容' enforces a specific language regardless of user preference. This is a natural-language policy concern because the file requires Chinese output throughout and does not provide any language-selection mechanism or documented justification for the locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The prompt explicitly requires transforming content into a Chinese visual prompt, which forces a specific language regardless of user preference. This is a natural-language policy concern because the file does not provide any opt-in, fallback, or justification for restricting output to Chinese.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

These lines require Chinese content extraction and specify Chinese character-length constraints for all generated elements, reinforcing a mandatory language policy. Because no alternative language path or explicit user choice is offered, the file enforces a locale/language constraint that may violate organizational language-choice expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file explicitly requires converting documents into Chinese infographic prompts, which forces a specific language regardless of user preference. This is a natural-language policy issue because the skill does not provide any option to select another language or obtain user opt-in for the locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The protocol requires extracting Chinese titles and descriptions and producing a complete Chinese prompt, reinforcing a fixed-language mandate. Because no alternative language path or opt-in is described, this conflicts with the policy against forcing a locale without user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The final output requirement states that image_generation_prompt must be a full Chinese prompt, making the locale restriction mandatory at response time. This is a policy violation unless the skill is clearly documented as a justified Chinese-only regional tool or offers user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Line L09 states a language-specific requirement using '中文要求', directing that titles and body text should prioritize readability in Chinese. This imposes a locale/language constraint in natural language without indicating that users may choose another language or that the restriction is limited to a justified region-specific context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Line L09 states that comic titles, chapter titles, and story text must be in Chinese, which imposes a specific language requirement. Under the policy, forcing a locale or language without user opt-in is a natural-language policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains natural-language instructions that default output to a Chinese visual-note style and explicitly requires titles, labels, and explanatory text to be clear in Chinese. That creates a language policy constraint without user opt-in or a documented region-specific justification, which matches the policy-violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file instructs the style in Chinese only ("采用白色磁吸会议板书风格"), which imposes a specific language/locale presentation without offering the user a choice or opt-in. The policy for this audit flags natural-language locale constraints when they are mandatory and not documented as optional or region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Line L08 states that all Chinese must be written on specific visual elements, which implies a mandatory Chinese-language requirement in the skill's output style. This is a natural-language locale policy constraint without any user opt-in or justification for why Chinese is required.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file description explicitly states it generates Chinese visual prompts, and later prompt-building logic reinforces a mandatory Chinese-only workflow. This is a natural-language locale restriction with no visible user choice or justification for why the skill must operate only in Chinese.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.