Back to skill

Security audit

hd-txt2img-v2L

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Hidream text-to-image API helper, but users should avoid putting real API tokens directly in command-line arguments.

Install only if you are comfortable sending prompts and an API token to Hidream. Prefer setting HIDREAM_AUTHORIZATION through a protected environment or secret manager, avoid putting real tokens in shell commands, rotate any token previously pasted into history, and use a limited-scope token where the provider supports it.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:33
Finding

Bearer Token Exposure Through Command-Line Arguments

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Tainted flow: 'headers' from os.getenv (line 92, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/generate_image.py (reported line 100)May include surrounding context.

python
gen_task_url = f"{DEFAULT_ENDPOINT}/api-pub/gw/v3/image/txt2img/async"
    get_task_result_url = gen_task_url + "/results"

    submit_resp = requests.post(gen_task_url, json=payload, headers=headers, timeout=30)
    if submit_resp.status_code != 200:
        raise RuntimeError(f"http error: {submit_resp.status_code} {submit_resp.text}")
    resp_json = submit_resp.json()

Tainted flow: 'headers' from os.getenv (line 92, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/generate_image.py (reported line 111)May include surrounding context.

python
start = time.time()
    while True:
        print(f"Query Task result ...")
        query_resp = requests.get(
            get_task_result_url,
            params={"task_id": task_id},
            headers=headers,

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill enables code behavior that uses environment access and network calls, but the manifest does not declare any tool scope or permission boundaries. This increases the chance that an agent or reviewer will underestimate the skill's capabilities, leading to overbroad execution in contexts where network or secret access should have been explicitly approved.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation instructs users to pass an authorization token directly on the command line, which can leak via shell history, process listings, audit logs, CI logs, and terminal recordings. Because this token authorizes access to a remote image-generation API, exposure could enable unauthorized API use, quota abuse, or access under the user's identity.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/generate_image.py (reported line 100)May include surrounding context.

python
gen_task_url = f"{DEFAULT_ENDPOINT}/api-pub/gw/v3/image/txt2img/async"
    get_task_result_url = gen_task_url + "/results"

    submit_resp = requests.post(gen_task_url, json=payload, headers=headers, timeout=30)
    if submit_resp.status_code != 200:
        raise RuntimeError(f"http error: {submit_resp.status_code} {submit_resp.text}")
    resp_json = submit_resp.json()

Tainted flow: 'task_id' from requests.post (line 106, network input) → requests.get (network output)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/generate_image.py (reported line 111)May include surrounding context.

python
start = time.time()
    while True:
        print(f"Query Task result ...")
        query_resp = requests.get(
            get_task_result_url,
            params={"task_id": task_id},
            headers=headers,

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
73% confidence
Finding

The only user-facing prompt example is written in Chinese, which implicitly steers usage toward a specific language without stating that other languages are supported or that Chinese is required. This can conflict with language/locale policy expectations when no opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code includes a hard-coded Chinese message literal ("生成失败") in user-visible output. The file provides no language selection or documented locale constraint, so it enforces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.