Back to skill

Security audit

Zhy Article Illustrator

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its article-illustration purpose, but it silently defaults to a hard-coded third-party image relay that can receive article content, reference images, and API keys.

Review before installing. Use only trusted official or self-controlled image endpoints, explicitly set IMAGE_BASE_URL or XIAOMI_BASE_URL instead of relying on defaults, avoid passing API keys with --api-key, and do not run it on confidential drafts or private reference images unless you accept transmission to the configured provider and optional Qiniu upload destination.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/image-gen.ts:213
Finding

Undocumented Default Relay Exposes API Credentials and User Content

Content
View full analysis
= { png: "image/png", jpg: "image/jpeg", jpeg: "image/jpeg", webp: "image/webp", }; const mimeType = mimeMap[ext] ?? "image/png"; const data = refData.toString("base64"); if (provider === "xiaomi") { return { inline_data: { mime_type: mimeType, data, }, }; } return { inlineData: { mimeType, da ...[truncated 3812 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/illustrate-article.ts:360
Finding

API Keys Are Accepted and Forwarded Through Process Command-Line Arguments

Content
View full analysis
= {}): Promise<{ stdout: string; stderr: string; code: number }> { return new Promise((resolvePromise, reject) => { const child = spawn(process.execPath, [scriptPath, ...args], { stdio: ["ignore", "pipe", "pipe"], env: { ...process.env, ...extraEnv }, }); ``` The secret is forwarded to `image-gen.ts` as another process argument: ```ts if (args.apiKey) { cmdArgs.push("--api-key", args.apiKey); } ``` The child process reads it from its argument vector: ```ts case "--api-key": apiKey = argv[++i] ?? null; break; ``` ### Technical Analysis Secrets supplied as command-line arguments can be exposed through: - Operating-system process listings. - Process inspection interfaces. - Shell history. - CI/CD job logs. - Endpoint monitoring and audit telemetry. - Crash reports and diagnostic tooling. - Wrapper scripts that record executed commands. The orchestration script further increases exposure by forwarding the same key to a child process. This creates a second process argument vector containing the credential and extends the period during which local observers or monitoring tools may capture it. Using `spawn` without a shell prevents conventional shell metacharacter injection, so this is not a command-injection vulnerability. The weakness is specifically the unsafe transport and handling of sensitive credentials. ### Attack Pa ...[truncated 1191 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (37)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 28)May include surrounding context.

请先复制:

bash
cp .env.example .env

然后按你的实际通道填写。

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The code’s core function is image generation via external APIs and writing the resulting image to a local file. While that partially overlaps with 'illustrating' content, the declared description emphasizes a broader article publishing workflow: Markdown article illustration, structured prompt planning, optional Qiniu upload, and insertion of image references. None of those workflow features appear in this code. Instead, the code only accepts prompt/output arguments, optionally reads a prompt file or reference image, calls Google/Xiaomi/OpenAI image APIs, and saves output. It also performs undeclared external network calls and reads API credentials from .env, which are important operational capabilities not reflected in the declared permissions. Therefore the description materially overstates and mischaracterizes what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The core of the description is partially accurate: the script does plan visuals for a Markdown article, creates a visual bible, outline, and structured prompts, and targets high-finish editorial imagery. However, two material declared capabilities are absent in the code. First, there is no Qiniu upload implementation at all—no HTTP calls, SDK use, or upload path beyond a parsed config field. Second, the script does not insert image references into the Markdown article or any publishing workflow; it only writes planning artifacts and prompt markdown files locally. Because these are substantive workflow capabilities explicitly named in the description, the description overstates what the code actually does.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 222)May include surrounding context.

md
node scripts/illustrate-article.ts --article <article.md>

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 359)May include surrounding context.

md
node scripts/illustrate-article.ts --article <article.md>

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 242)May include surrounding context.

md
bun run scripts/qiniu-upload.ts --file <本地路径> --key <远程路径>

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 358)May include surrounding context.

md
- 可使用 `bun run scripts/plan-illustrations.ts --article <article.md>` 自动生成 `visual-bible.md`、`outline.md` 和 `prompts/`

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

The script allows external model/provider selection and also supports overriding the base URL, including a non-official default Xiaomi-compatible endpoint elsewhere in the file. In this skill context, prompts may contain unpublished article content and reference images, so sending them to alternate providers or proxy endpoints can expose sensitive material and API credentials to third parties.

Content

Scanner excerpt · scripts/image-gen.ts (reported line 9)May include surrounding context.

ts
*   bun run scripts/image-gen.ts -p "prompt" -o out.png
 *   bun run scripts/image-gen.ts --prompt-file p.md -o out.png --ar 16:9
 *   bun run scripts/image-gen.ts -p "text" -o out.png --ref src.png
 *   bun run scripts/image-gen.ts -p "text" -o out.png --provider xiaomi --model gemini-3.1-flash-image-preview
 *
 * 环境变量从技能根目录 .env 读取:
 *   IMAGE_PROVIDER / IMAGE_MODEL / IMAGE_BASE_URL / IMAGE_API_KEY / IMAGE_SIZE

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/image-gen.ts (reported line 11)May include surrounding context.

ts
*   bun run scripts/image-gen.ts -p "text" -o out.png --ref src.png
 *   bun run scripts/image-gen.ts -p "text" -o out.png --provider xiaomi --model gemini-3.1-flash-image-preview
 *
 * 环境变量从技能根目录 .env 读取:
 *   IMAGE_PROVIDER / IMAGE_MODEL / IMAGE_BASE_URL / IMAGE_API_KEY / IMAGE_SIZE
 *   XIAOMI_API_KEY / XIAOMI_BASE_URL / XIAOMI_IMAGE_SIZE
 *   GEMINI_API_KEY / GOOGLE_API_KEY

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/qiniu-upload.ts (reported line 13)May include surrounding context.

ts
*   bun run scripts/image-gen.ts -p "text" -o out.png --ref src.png
 *   bun run scripts/image-gen.ts -p "text" -o out.png --provider xiaomi --model gemini-3.1-flash-image-preview
 *
 * 环境变量从技能根目录 .env 读取:
 *   IMAGE_PROVIDER / IMAGE_MODEL / IMAGE_BASE_URL / IMAGE_API_KEY / IMAGE_SIZE
 *   XIAOMI_API_KEY / XIAOMI_BASE_URL / XIAOMI_IMAGE_SIZE
 *   GEMINI_API_KEY / GOOGLE_API_KEY

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/qiniu-upload.ts (reported line 66)May include surrounding context.

ts
*   bun run scripts/image-gen.ts -p "text" -o out.png --ref src.png
 *   bun run scripts/image-gen.ts -p "text" -o out.png --provider xiaomi --model gemini-3.1-flash-image-preview
 *
 * 环境变量从技能根目录 .env 读取:
 *   IMAGE_PROVIDER / IMAGE_MODEL / IMAGE_BASE_URL / IMAGE_API_KEY / IMAGE_SIZE
 *   XIAOMI_API_KEY / XIAOMI_BASE_URL / XIAOMI_IMAGE_SIZE
 *   GEMINI_API_KEY / GOOGLE_API_KEY

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/image-gen.ts (reported line 51)May include surrounding context.

ts
}

function loadEnv(): void {
  const envPath = resolve(process.cwd(), ".env");
  if (!existsSync(envPath)) return;

  const lines = readFileSync(envPath, "utf-8").split("\n");

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/qiniu-upload.ts (reported line 67)May include surrounding context.

ts
}

function loadEnv(): void {
  const envPath = resolve(process.cwd(), ".env");
  if (!existsSync(envPath)) return;

  const lines = readFileSync(envPath, "utf-8").split("\n");

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README explicitly describes optional cloud upload to Qiniu and use of external image-generation providers, but it does not clearly warn users that article content, prompts, and generated assets may be transmitted to third-party services. In a content-publishing workflow, this can expose unpublished or sensitive material and create privacy/compliance risks if users assume processing is local.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill explicitly describes reading environment variables and making outbound requests to image-generation providers and optionally to Qiniu, but it declares no permissions or allowed-tools scope. That creates an authorization and transparency gap: a caller cannot easily tell that the skill may access secrets and send data off-box, which increases the chance of unintended secret use or unreviewed network exfiltration.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Multiple instructions require image text to default to Simplified Chinese and restrict English to a whitelist, which constitutes a language policy constraint. While text_language exists as an input, the natural-language instructions repeatedly prescribe Chinese as mandatory behavior rather than presenting language selection as a neutral user-controlled option.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The required prompt layers explicitly state that all visible text must use Simplified Chinese except whitelisted English terms. This is a hardcoded locale requirement in natural-language instructions and does not clearly defer to user preference or present an opt-in choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill supports uploading generated assets to Qiniu/CDN and also sends prompts derived from article content to external image providers, but it does not prominently warn that article-derived content may leave the local environment. Users may unknowingly transmit confidential draft content, proprietary terminology, or sensitive contextual data to third-party services.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file states the default image text language is zh-CN and recommends that value, which imposes a specific locale in the skill's documented behavior. The documentation does not clearly offer user choice or frame the locale as an opt-in, region-specific requirement.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The documentation encourages configuring external image endpoints and API keys, including relay or compatible services, but does not warn that article content, prompts, and possibly embedded data may be transmitted to third-party infrastructure. In a content-generation skill, this can lead to unintended data disclosure, credential misuse, or routing sensitive material through untrusted endpoints, especially when users copy example settings into real projects without understanding the trust boundary.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

These lines state that image text should default to Simplified Chinese and restrict English to a whitelist. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation unless the constraint is clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This section requires all visible text to use Simplified Chinese and forbids non-whitelisted English UI text. Because the file does not provide user choice or a clearly documented regional limitation, this is a language/locale policy issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

When the --upload flag is used, the script sends generated image files to a remote Qiniu service and then rewrites article image references to use returned remote URLs. Although upload is opt-in, the code provides no explicit warning, confirmation, or prominent disclosure at execution time about external data transfer, which can cause accidental exfiltration of sensitive article-derived content in publishing workflows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code sends user-supplied prompts, optional reference image data, and API credentials to external services via HTTP requests. Although the file contains usage comments and error output, it does not provide a clear user-facing warning or disclosure that prompt contents and image inputs will be sent to third-party providers.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/illustrate-article.ts:220

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/image-gen.ts:62

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/qiniu-upload.ts:70