Back to skill

Security audit

Pinterest

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a Pinterest browsing helper, but it also installs an unpinned package at runtime and uses Pinterest account tokens with limited safety guidance.

Review this skill before installing. Only use it where Pinterest browsing, external image sending, and read-only Pinterest account access are intended. Treat PINTEREST_ACCESS_TOKEN and app secrets as sensitive, avoid pasting them into chats or shared logs, and prefer a controlled environment with httpx preinstalled from pinned dependencies rather than allowing the skill to install packages during execution.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
scripts/pinterest_api.py:15
Finding

Unpinned Dependency Is Automatically Downloaded and Installed at Runtime

Content
View full analysis

Vulnerability Details

File Location: scripts/pinterest_api.py, lines 15-21
Vulnerability Type: Runtime installation of an unpinned third-party dependency
Risk Level: Medium

Vulnerable code:

python
try:
    import httpx
except ImportError:
    print("Installing httpx...")
    import subprocess
    subprocess.check_call([sys.executable, "-m", "pip", "install", "httpx", "-q"])
    import httpx

Technical Analysis

When httpx is unavailable, the script invokes pip to download and install the package without specifying an audited version, cryptographic hash, or trusted package index. Package installation executes package-controlled build and installation logic within the privileges of the Python process.

Consequently, the code executed by the skill can change independently of the reviewed project. Although httpx is a legitimate package, a compromised upstream release, compromised or attacker-controlled Python package index, poisoned package mirror, or unsafe local pip configuration could cause malicious package code to be installed and executed.

The use of an argument array rather than a shell command prevents conventional shell injection at this call site, but it does not address the dependency supply-chain risk.

Attack Path

  1. The skill is executed in an environment where httpx is not already installed.
  2. An attacker compromises the configured package source or causes pip to use an attacker-controlled index or mirror. A malicious upstream release would create the same risk.
  3. The import raises ImportError, entering the automatic installation branch.
  4. The script executes python -m pip install httpx -q without a version or hash constraint.
  5. pip downloads the attacker-controlled distribution and runs any applicable build or installation code.
  6. The script imports the installed package, allowing malicious module initialization code to execute again.

...[truncated 609 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove automatic package installation from application runtime. If httpx is missing, terminate with a clear dependency error.
  • Declare dependencies in a dedicated dependency manifest and lock file.
  • Pin httpx and all transitive dependencies to reviewed versions.
  • Require cryptographic hashes during installation, such as with a hash-locked requirements file and pip install --require-hashes.
  • Install dependencies during a controlled build or deployment stage from an explicitly configured trusted index.
  • Run the skill in a least-privileged virtual environment or isolated container.
  • Perform dependency vulnerability and provenance scanning in CI, and update pinned versions through a reviewed process.

A safer runtime pattern is:

python
try:
    import httpx
except ImportError as exc:
    raise RuntimeError(
        "Missing required dependency 'httpx'; install the project's locked dependencies."
    ) from exc
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (23)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill description promises direct image sending via Telegram/messaging, but the documented behavior also includes URL transformation, screenshots of third-party pages, and OAuth-based board and pin enumeration that go beyond the stated purpose. This mismatch undermines informed consent and review, because operators may approve a simple image-browsing skill while it also accesses authenticated Pinterest content and transmits captured content externally.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/oauth-setup.md (reported line 16)May include surrounding context.

md
- For local testing: `http://localhost:8000/callback`
- For production: your actual callback URL

## 3. Get Access Token

### Option A: OAuth Playground (Quick Testing)

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

This step specifically instructs the user to copy the access token, which creates a realistic pathway for accidental disclosure if copied into insecure notes, shells, screenshots, or shared channels. While not malicious, it is unsafe documentation because the token can enable unauthorized use of the user's Pinterest account within the granted scopes.

Content

Scanner excerpt · references/oauth-setup.md (reported line 23)May include surrounding context.

md
1. Go to https://developers.pinterest.com/tools/access_token/
2. Select scopes: `boards:read`, `pins:read`
3. Click "Generate token"
4. Copy the access token

### Option B: Full OAuth Flow

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/oauth-setup.md (reported line 65)May include surrounding context.

md
## Token Expiration

- Access tokens expire after 30 days
- Refresh tokens can be used to get new access tokens
- Store refresh tokens securely

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/oauth-setup.md (reported line 66)May include surrounding context.

md
## Token Expiration

- Access tokens expire after 30 days
- Refresh tokens can be used to get new access tokens
- Store refresh tokens securely

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/pinterest_api.py (reported line 29)May include surrounding context.

python
def get_access_token() -> Optional[str]:
    """Get Pinterest access token from environment."""
    return os.environ.get("PINTEREST_ACCESS_TOKEN")

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill invokes browser navigation, message sending, shell commands, and environment-based OAuth flows, yet declares no explicit tool scope or permission boundaries. That increases the chance the agent can use broader capabilities than users or reviewers expect, making misuse of network, shell, or secrets access harder to constrain or audit.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The frontmatter description is broad enough to trigger on many generic image- or inspiration-related requests without narrowing when this skill should be used. Over-broad activation can cause the agent to browse third-party sites and send external media in contexts where the user did not specifically ask for Pinterest or for image transmission.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The main summary repeats a very broad operational scope—search, browse, and share images—without guardrails for user consent, content boundaries, or platform specificity. In practice, this can lead to unnecessary acquisition and forwarding of third-party content, increasing privacy, copyright, and content-safety risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill instructs the agent to send third-party Pinterest-hosted images directly to the user, but provides no warning or policy checks for copyright, tracking, unsafe content, or privacy implications. Because it actively forwards external media rather than only sharing links, the skill materially increases the chance of redistributing unreviewed content or exposing users to content they did not explicitly consent to receive.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The screenshot workflow tells the agent to capture a Pinterest page and transmit the resulting file, but omits any warning that screenshots may include page metadata, usernames, recommendations, or other incidental content not intended for sharing. If used on authenticated or personalized pages, this can leak private or account-linked information to the user or another recipient.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation explicitly endorses a web-scraping fallback for broader Pinterest search, but provides no warning about terms-of-service violations, account bans, IP blocking, privacy implications, or the need for user consent and legal review. In a skill that fetches and sends Pinterest content to users, this normalizes a non-API data acquisition path that can expose operators and users to compliance and account-risk issues.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The setup guide instructs users to obtain and handle an App Secret and later tokens, but it does not explicitly warn that these credentials grant account or application access and must never be shared or committed. In documentation intended for developers, omission of basic secret-handling guidance materially increases the risk of accidental leakage through screenshots, logs, shell history, or source control.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instructions explicitly tell users to copy an access token and later export it without stating that the token provides authenticated access to Pinterest resources. That omission can lead users to treat the token like a harmless string, increasing the chance of credential disclosure and unauthorized API use.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Installing a Python package at runtime is unrelated to the core Pinterest search/browsing task and introduces a code-fetch-and-execute capability during normal use. In a skill context, this is dangerous because it silently alters the host environment and increases exposure to dependency confusion or package repository compromise.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script performs a pip install automatically and without any user confirmation, creating an implicit software installation path during ordinary skill execution. This is risky because users and hosting systems do not get a chance to review or approve the environment change, and the install pulls executable third-party code into the runtime.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
97% confidence
Finding

The script executes pip at runtime to install a dependency, which gives the skill code permission to modify the local Python environment and pull executable code from an external package index during execution. This expands the trust boundary beyond Pinterest functionality and can lead to supply-chain compromise, unauthorized environment changes, or unexpected code execution if package sources are tampered with.

Content

Scanner excerpt · scripts/pinterest_api.py (reported line 20)May include surrounding context.

python
except ImportError:
    print("Installing httpx...")
    import subprocess
    subprocess.check_call([sys.executable, "-m", "pip", "install", "httpx", "-q"])
    import httpx

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 5)May include surrounding context.

md
import httpx


PINTEREST_API_BASE = "https://api.pinterest.com/v5"
PINTEREST_WEB_BASE = "https://www.pinterest.com"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/oauth-setup.md (reported line 39)May include surrounding context.

md
import httpx


PINTEREST_API_BASE = "https://api.pinterest.com/v5"
PINTEREST_WEB_BASE = "https://www.pinterest.com"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/pinterest_api.py (reported line 24)May include surrounding context.

python
import httpx


PINTEREST_API_BASE = "https://api.pinterest.com/v5"
PINTEREST_WEB_BASE = "https://www.pinterest.com"

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The function labeled as searching pins via the official API ignores the query and instead returns the authenticated user's pins. This mismatch is dangerous because callers may believe they are performing harmless public search while actually accessing private or account-scoped data tied to the user's token.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill exposes commands to list the authenticated user's boards and board pins, which exceeds the stated scope of searching/browsing public Pinterest content and getting pin details. This scope expansion can cause unauthorized access to user-associated content and increases privacy risk if an agent invokes these commands without clear user intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The request header hard-codes "Accept-Language: en-US,en;q=0.9", which imposes a specific language/locale preference. This is a natural-language policy concern because the skill does not provide opt-in, configurability, or justification for forcing English.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.