Back to skill

Security audit

ImageCompress

Security checks for vulnerabilities and agentic risk

Overview

This image-compression skill mostly does what it claims, but it uploads images to third-party servers and has file/network safety gaps that users should review before installing.

Install only if you are comfortable sending selected images to TinyPNG/Tinify servers. Avoid using it on sensitive or regulated images, avoid --overwrite unless you have backups, and prefer running it with limited filesystem and network access until download URL validation, overwrite confirmation, and dependency pinning are added.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/tiny_compress.py:172
Finding

Unvalidated Server-Controlled Download URL Enables SSRF and Unsafe File Replacement

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:12
Finding

Unpinned Third-Party Dependency Produces a Non-Reproducible Supply Chain

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

4. Overwrite Mode

When user explicitly wants to replace original files:

bash
python "{SKILL_DIR}/scripts/tiny_compress.py" compress "<file>" --overwrite

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · SKILL.md (reported line 101)May include surrounding context.

md
|-----------|-------------|---------|
| `--output-dir <dir>` | Output directory | Same dir with `_compressed` suffix |
| `--server cn\|global` | Server selection | `global` |
| `--overwrite` | Overwrite original files | `false` |
| `--recursive` | Recurse into subdirectories (compress-dir only) | `false` |

**How it works:**

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · scripts/tiny_compress.py (reported line 251)May include surrounding context.

python
|-----------|-------------|---------|
| `--output-dir <dir>` | Output directory | Same dir with `_compressed` suffix |
| `--server cn\|global` | Server selection | `global` |
| `--overwrite` | Overwrite original files | `false` |
| `--recursive` | Recurse into subdirectories (compress-dir only) | `false` |

**How it works:**

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill clearly performs outbound network operations to tinypng.com/tinify.cn, but the manifest does not declare any explicit tool scope or permissions for network access. This weakens governance and review controls because an agent may invoke a network-capable skill without the expected permission metadata or user-visible disclosure boundaries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The tool's core behavior uploads user-supplied image data to third-party TinyPNG/Tinify servers, but it does not provide a clear privacy/data-transfer warning in the CLI help or runtime output. This can cause users to unintentionally transmit sensitive images off-host, which is especially risky because the skill advertises 'no API key required' and free web API usage, encouraging casual use without data-handling scrutiny.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Overwrite mode enables destructive replacement of the original image without a confirmation prompt or backup mechanism. If used on the wrong files or if the remote service returns unexpected output, the user can permanently lose original data, making this a real safety issue even though it is locally triggered rather than attacker-controlled.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script transmits raw image bytes to a remote server at the point of compression without any runtime disclosure or consent gate. In the context of a local utility that may be run on arbitrary directories, this increases the risk of accidental exfiltration of private or regulated image content.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The module docstring and argparse help text document the supported commands and options, but the code also checks for a --json flag and emits machine-readable JSON output. This is not merely missing internal detail: it presents an undocumented user-visible interface that contradicts the documented CLI surface.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.