CtrlK
BlogDocsLog inGet started
Tessl Logo

huashu-image-upload

文章配图一键生成并上传图床,自动插入Markdown链接。当用户提到"配图"、"插图"、"上传图片"、"文章配图"时使用。

72

Quality

88%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Low

Low-risk findings.

1 low severity finding. Worth noting, but not necessarily harmful.

Low

W011: Third-party content exposure detected (indirect prompt injection risk).

What this means

The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.

Why it was flagged

该Skill在“Step 2/4”里会对“公共领域作品(Wikimedia Commons)”与“免费图库(Unsplash/Pexels)”执行WebFetch检索/获取图片并随后把图片URL喂给`/tools/upload_image.py`上传到ImgBB,因此会读取第三方网站上可被外部作者投递的文本/元数据以构造图片选择与描述(并非仅限选择固定、预先知名的条目)。

Report incorrect finding
Repository
alchaincyf/huashu-skills
Audited
Security analysis
Snyk

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.