T09 · Insecure Skill Coding Practices
- Location
scripts/tiny_compress.py:172- Finding
Unvalidated Server-Controlled Download URL Enables SSRF and Unsafe File Replacement
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This image-compression skill mostly does what it claims, but it uploads images to third-party servers and has file/network safety gaps that users should review before installing.
Install only if you are comfortable sending selected images to TinyPNG/Tinify servers. Avoid using it on sensitive or regulated images, avoid --overwrite unless you have backups, and prefer running it with limited filesystem and network access until download URL validation, overwrite confirmation, and dependency pinning are added.
scripts/tiny_compress.py:172Unvalidated Server-Controlled Download URL Enables SSRF and Unsafe File Replacement
SKILL.md:12Unpinned Third-Party Dependency Produces a Non-Reproducible Supply Chain
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
When user explicitly wants to replace original files:
python "{SKILL_DIR}/scripts/tiny_compress.py" compress "<file>" --overwrite
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
|-----------|-------------|---------|
| `--output-dir <dir>` | Output directory | Same dir with `_compressed` suffix |
| `--server cn\|global` | Server selection | `global` |
| `--overwrite` | Overwrite original files | `false` |
| `--recursive` | Recurse into subdirectories (compress-dir only) | `false` |
**How it works:**
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
|-----------|-------------|---------|
| `--output-dir <dir>` | Output directory | Same dir with `_compressed` suffix |
| `--server cn\|global` | Server selection | `global` |
| `--overwrite` | Overwrite original files | `false` |
| `--recursive` | Recurse into subdirectories (compress-dir only) | `false` |
**How it works:**
The skill clearly performs outbound network operations to tinypng.com/tinify.cn, but the manifest does not declare any explicit tool scope or permissions for network access. This weakens governance and review controls because an agent may invoke a network-capable skill without the expected permission metadata or user-visible disclosure boundaries.
The tool's core behavior uploads user-supplied image data to third-party TinyPNG/Tinify servers, but it does not provide a clear privacy/data-transfer warning in the CLI help or runtime output. This can cause users to unintentionally transmit sensitive images off-host, which is especially risky because the skill advertises 'no API key required' and free web API usage, encouraging casual use without data-handling scrutiny.
Overwrite mode enables destructive replacement of the original image without a confirmation prompt or backup mechanism. If used on the wrong files or if the remote service returns unexpected output, the user can permanently lose original data, making this a real safety issue even though it is locally triggered rather than attacker-controlled.
The script transmits raw image bytes to a remote server at the point of compression without any runtime disclosure or consent gate. In the context of a local utility that may be run on arbitrary directories, this increases the risk of accidental exfiltration of private or regulated image content.
The module docstring and argparse help text document the supported commands and options, but the code also checks for a --json flag and emits machine-readable JSON output. This is not merely missing internal detail: it presents an undocumented user-visible interface that contradicts the documented CLI surface.
No suspicious patterns detected.