Back to skill

Security audit

Photo Index With LLM

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent photo search tool, but its handling of local LLM endpoints and auto-loaded configuration can expose private photos without the consent controls users are told to expect.

Review this before installing. Use it only with a verified loopback local model endpoint such as localhost or 127.0.0.1, inspect any .env file it may auto-load, and avoid scanning sensitive photos until endpoint validation and remote-consent handling are fixed. Expect a local, unencrypted SQLite index containing photo paths and descriptions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
skill.py:635
Finding

Configurable External Endpoints Can Bypass Remote Upload and Consent Controls

Content
View full analysis

Vulnerability Details

File Location: skill.py:482-495, skill.py:498-537, skill.py:550-567, and skill.py:635-660
Vulnerability Type: Improper trust classification of configurable network endpoints
Risk Level: Medium

Vulnerable Code

python
class VLClient:
    """VL model client"""
    
    def __init__(self, endpoint: str, model: str, api_key: str = "", 
                 max_tokens: int = 2048, timeout: int = 120,
                 is_remote: bool = False, require_confirm: bool = True):
        self.endpoint = endpoint.rstrip("/")
        self.model = model
        self.api_key = api_key
        self.max_tokens = max_tokens
        self.timeout = timeout
        self.is_remote = is_remote
        self.require_confirm = require_confirm
        self.confirmed = False
        
        self.headers = {"Content-Type": "application/json"}
        if api_key:
            self.headers["Authorization"] = f"Bearer {api_key}"
python
def analyze_image(self, image_path: str, prompt: str) -> dict:
    # Privacy protection: remote transmission requires confirmation
    if self.is_remote and self.require_confirm and not self.confirmed:
        print(f"\n⚠️  Privacy warning: using a remote model sends the photo to a third-party server", file=sys.stderr)
        print(f"   Destination server: {self.endpoint}", file=sys.stderr)
        print(f"   The photo may be stored or analyzed by the third party", file=sys.stderr)
        print(f"   Consider using a local model for sensitive photographs", file=sys.stderr)
        
        # Reject remote transfer in non-interactive mode
        if not sys.stdin.isatty():
            raise PermissionError(
                "Remote transmission requires user confirmation, but the current mode is non-interactive.\n"
                "Set REQUIRE_REMOTE_CONFIRM=false in configuration to disable this check."
            )
        
 
...[truncated 5914 chars]
Remediation
View remediation

Remediation Suggestions

  1. Parse endpoints using urllib.parse.urlsplit() and permit only explicitly supported schemes.
  2. For a client classified as local, require a loopback destination such as 127.0.0.1, ::1, or a hostname that resolves exclusively to loopback addresses.
  3. Do not classify trust based on the configuration field name. Derive whether consent is required from the validated network destination.
  4. Treat all non-loopback destinations as remote and enforce PRIVACY_MODE, ALLOW_REMOTE_UPLOAD, and REQUIRE_REMOTE_CONFIRM.
  5. Disable automatic redirects with allow_redirects=False, or validate every redirect target before sending sensitive request data.
  6. Reject URLs containing embedded credentials, unsupported schemes, ambiguous host representations, or untrusted ports where appropriate.
  7. Consider an explicit destination allowlist and display the normalized destination before obtaining consent.
  8. Preserve confirmation in non-interactive Agent use through an explicit per-invocation authorization mechanism rather than silently disabling it.
  9. Add security tests for:
    • Public hosts supplied through LOCAL_LLM_ENDPOINT
    • IPv4 and IPv6 loopback addresses
    • Hostnames resolving to non-loopback addresses
    • Redirects from local to external destinations
    • DNS rebinding and mixed-address DNS responses
    • Non-interactive invocation
    • Each privacy-mode and upload-permission combination

T08 · Insecure Dependencies

Note
Location
requirements.txt:4
Finding

Open-Ended Dependency Constraint Weakens Build Reproducibility

Content
View full analysis

Vulnerability Details

File Location: requirements.txt:4 and skill.yaml:27-28
Vulnerability Type: Unpinned third-party dependency
Risk Level: Low

Vulnerable Code

text
# Photo Search Skill standalone dependencies

# HTTP requests
requests>=2.31.0
yaml
dependencies:
  - requests>=2.31.0

Technical Analysis

The dependency declaration accepts version 2.31.0 and every later release. It does not provide an upper bound, lock file, or package hashes. Consequently, installations performed at different times may resolve to different and previously unaudited versions.

The package name is legitimate and no dependency confusion or typosquatting was identified. The risk arises from non-reproducible dependency resolution: a compromised, malicious, or behaviorally incompatible future release satisfying the range could be installed without a project change.

Because requests implements the Skill's sensitive image and API-key network path, unexpected changes to its request, redirect, proxy, or TLS behavior would affect a security-sensitive component.

Attack Path

  1. A user or automated deployment installs the project dependencies.
  2. The package resolver selects the newest available requests release satisfying requests>=2.31.0.
  3. That release has not necessarily been reviewed or tested by the Skill author.
  4. If the selected release or its dependency chain is compromised, malicious code can execute during installation or import under the installing user's privileges.
  5. A malicious runtime component could access the photographs, API authorization headers, network requests, or other files available to the Skill process.

Impact Assessment

Exploitation depends on a compromised or vulnerable future package release and is therefore less direct than the endpoint-validation issue. If it occurs, package code runs with the same privileges as the Python process.

Po ...[truncated 397 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin requests and its transitive dependencies to versions reviewed and tested by the project.
  2. Generate and commit a lock file appropriate for the deployment workflow.
  3. Use hash-verified installation, such as a requirements file generated with hashes and installed using pip --require-hashes.
  4. Update dependencies through a controlled review process that includes vulnerability scanning and regression testing.
  5. Rebuild and periodically refresh pins so that reproducibility does not prevent timely security updates.
  6. Document the supported installation procedure and ensure metadata and requirements use the same locked dependency set.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (60)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CROSS_PLATFORM.md (reported line 62)May include surrounding context.

md
- ✅ 所有代码都在 skill.py 内

2. **自动配置加载**
   - ✅ 自动查找主项目的 .env 文件
   - ✅ 如果找不到,使用内置默认配置
   - ✅ 不需要设置环境变量

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CROSS_PLATFORM.md (reported line 68)May include surrounding context.

md
- ✅ 所有代码都在 skill.py 内

2. **自动配置加载**
   - ✅ 自动查找主项目的 .env 文件
   - ✅ 如果找不到,使用内置默认配置
   - ✅ 不需要设置环境变量

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CROSS_PLATFORM.md (reported line 250)May include surrounding context.

md
- ✅ 所有代码都在 skill.py 内

2. **自动配置加载**
   - ✅ 自动查找主项目的 .env 文件
   - ✅ 如果找不到,使用内置默认配置
   - ✅ 不需要设置环境变量

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · INDEPENDENCE.md (reported line 32)May include surrounding context.

md
- ✅ 所有代码都在 skill.py 内

2. **自动配置加载**
   - ✅ 自动查找主项目的 .env 文件
   - ✅ 如果找不到,使用内置默认配置
   - ✅ 不需要设置环境变量

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · PRIVACY.md (reported line 155)May include surrounding context.

md
- ✅ 所有代码都在 skill.py 内

2. **自动配置加载**
   - ✅ 自动查找主项目的 .env 文件
   - ✅ 如果找不到,使用内置默认配置
   - ✅ 不需要设置环境变量

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · PRIVACY.md (reported line 159)May include surrounding context.

md
- ✅ 所有代码都在 skill.py 内

2. **自动配置加载**
   - ✅ 自动查找主项目的 .env 文件
   - ✅ 如果找不到,使用内置默认配置
   - ✅ 不需要设置环境变量

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · PRIVACY.md (reported line 240)May include surrounding context.

md
- ✅ 所有代码都在 skill.py 内

2. **自动配置加载**
   - ✅ 自动查找主项目的 .env 文件
   - ✅ 如果找不到,使用内置默认配置
   - ✅ 不需要设置环境变量

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · PRIVACY.md (reported line 261)May include surrounding context.

md
- ✅ 所有代码都在 skill.py 内

2. **自动配置加载**
   - ✅ 自动查找主项目的 .env 文件
   - ✅ 如果找不到,使用内置默认配置
   - ✅ 不需要设置环境变量

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · PRIVACY.md (reported line 285)May include surrounding context.

md
- ✅ 所有代码都在 skill.py 内

2. **自动配置加载**
   - ✅ 自动查找主项目的 .env 文件
   - ✅ 如果找不到,使用内置默认配置
   - ✅ 不需要设置环境变量

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · PRIVACY_GUIDE.md (reported line 39)May include surrounding context.

md
- ✅ 所有代码都在 skill.py 内

2. **自动配置加载**
   - ✅ 自动查找主项目的 .env 文件
   - ✅ 如果找不到,使用内置默认配置
   - ✅ 不需要设置环境变量

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · PRIVACY_GUIDE.md (reported line 70)May include surrounding context.

md
- ✅ 所有代码都在 skill.py 内

2. **自动配置加载**
   - ✅ 自动查找主项目的 .env 文件
   - ✅ 如果找不到,使用内置默认配置
   - ✅ 不需要设置环境变量

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · PRIVACY_GUIDE.md (reported line 111)May include surrounding context.

md
- ✅ 所有代码都在 skill.py 内

2. **自动配置加载**
   - ✅ 自动查找主项目的 .env 文件
   - ✅ 如果找不到,使用内置默认配置
   - ✅ 不需要设置环境变量

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · PRIVACY_GUIDE.md (reported line 115)May include surrounding context.

md
- ✅ 所有代码都在 skill.py 内

2. **自动配置加载**
   - ✅ 自动查找主项目的 .env 文件
   - ✅ 如果找不到,使用内置默认配置
   - ✅ 不需要设置环境变量

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · PRIVACY_GUIDE.md (reported line 122)May include surrounding context.

md
- ✅ 所有代码都在 skill.py 内

2. **自动配置加载**
   - ✅ 自动查找主项目的 .env 文件
   - ✅ 如果找不到,使用内置默认配置
   - ✅ 不需要设置环境变量

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skill.py (reported line 92)May include surrounding context.

python
- ✅ 所有代码都在 skill.py 内

2. **自动配置加载**
   - ✅ 自动查找主项目的 .env 文件
   - ✅ 如果找不到,使用内置默认配置
   - ✅ 不需要设置环境变量

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skill.py (reported line 128)May include surrounding context.

python
- ✅ 所有代码都在 skill.py 内

2. **自动配置加载**
   - ✅ 自动查找主项目的 .env 文件
   - ✅ 如果找不到,使用内置默认配置
   - ✅ 不需要设置环境变量

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skill.yaml (reported line 49)May include surrounding context.

yaml
- ✅ 所有代码都在 skill.py 内

2. **自动配置加载**
   - ✅ 自动查找主项目的 .env 文件
   - ✅ 如果找不到,使用内置默认配置
   - ✅ 不需要设置环境变量

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · PRIVACY_GUIDE.md (reported line 131)May include surrounding context.

bash
# 删除不需要的索引
rm data/photo_index.db

# 清理日志
rm logs/*.log

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · PRIVACY_GUIDE.md (reported line 164)May include surrounding context.

bash
# 删除不需要的索引
rm data/photo_index.db

# 清理日志
rm logs/*.log

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · PRIVACY_GUIDE.md (reported line 134)May include surrounding context.

rm data/photo_index.db

清理日志

rm logs/*.log

text

### 4. 使用本地模型

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 428)May include surrounding context.

md
- 查看文档:`SKILL.md`(本文件)

Credential Access

High
Category
Privilege Escalation
Confidence
72% confidence
Finding

Automatically searching for a project root and loading a discovered .env file broadens trust to filesystem locations outside the skill itself. In multi-user or untrusted directory contexts, this can cause the skill to ingest attacker-controlled endpoints or API keys, potentially redirecting image uploads to malicious services or altering security settings silently.

Content

Scanner excerpt · skill.py (reported line 96)May include surrounding context.

python
if config_path:
            self._load_env_file(config_path)
        else:
            # 尝试查找主项目的 .env
            project_root = self._find_project_root()
            if project_root:
                env_file = project_root / ".env"

Credential Access

High
Category
Privilege Escalation
Confidence
72% confidence
Finding

Constructing and loading 'project_root/.env' after heuristic project-root discovery creates a configuration injection risk, because whoever controls that directory can influence remote API endpoints, upload permissions, and credential values. Given this skill can transmit full photos externally, untrusted configuration materially increases danger.

Content

Scanner excerpt · skill.py (reported line 99)May include surrounding context.

python
# 尝试查找主项目的 .env
            project_root = self._find_project_root()
            if project_root:
                env_file = project_root / ".env"
                if env_file.exists():
                    self._load_env_file(str(env_file))

Credential Access

High
Category
Privilege Escalation
Confidence
74% confidence
Finding

Walking parent directories at startup to locate the first .env file allows ambient filesystem state to control security-sensitive behavior. An attacker who can place or influence a parent-directory .env may redirect outbound traffic, disable confirmation safeguards, or supply credentials, leading to silent exfiltration of analyzed photos.

Content

Scanner excerpt · skill.py (reported line 862)May include surrounding context.

python
config_path = None
    
    for parent in current.parents:
        env_file = parent / ".env"
        if env_file.exists():
            config_path = str(env_file)
            break

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file presents all usage, installation, and safety-related guidance exclusively in Chinese. Under the policy, forcing a specific language without user opt-in or a documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.