migu-ai-creative-photo
使用 Node.js 标准库实现咪咕旅游照片合成服务,存在 User-Agent 伪装异常和 --insecure 跳过证书验证选项,但无明确恶意行为证据
152.0.0.0 Why this conclusion was reached
1/4 dimensions flaggedDeclared resources and inferred behavior are broadly aligned.
1 high-risk artifacts or egress signals were extracted.
There is no explicit malicious chain in the report.
Dependency information is incomplete, so supply-chain confidence stays limited.
What drove the risk score up
Chrome/152.0.0.0 版本号格式异常,line 19: 'Chrome/152.0.0.0 Mobile Safari/537.36'
支持 --insecure 跳过 TLS 证书验证,可能被用于中间人攻击
--save-token-stdin 允许写入 secrets/plan_multi_token.txt
Most important evidence
User-Agent 版本号格式异常
User-Agent 中 Chrome 版本号 '152.0.0.0' 格式不符合正常 Chrome 版本号规范(应为 152.0.xxx.x),可能用于绕过基于版本检测的过滤规则
scripts/migu_ai_creative_photo_client.mjs:19 支持跳过 TLS 证书验证
--insecure 选项允许通过 rejectUnauthorized: false 跳过 HTTPS 证书验证,存在中间人攻击风险
scripts/migu_ai_creative_photo_client.mjs:53 Token 保存命令支持外部输入
--save-token-stdin 从 stdin 读取 JWT 并写入本地文件,属于正常功能但存在被滥用可能
scripts/migu_ai_creative_photo_client.mjs:133 Declared capability vs actual capability
SKILL.md:59-62, migu_ai_creative_photo_client.mjs:134 SKILL.md:30, migu_ai_creative_photo_client.mjs:88-97 migu_ai_creative_photo_client.mjs:75-79 Suspicious artifacts and egress
152.0.0.0 scripts/migu_ai_creative_photo_client.mjs:19
https://gulangyu.migudm.cn SKILL.md:30
https://gulangyu.migudm.cn/multi-city-trip-agent/ scripts/migu_ai_creative_photo_client.mjs:15
Dependencies and supply chain
There are no structured dependency warnings.
File composition
scripts/migu_ai_creative_photo_client.mjs SKILL.md