Back to skill

Security audit

z-card-image

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent local image-rendering skill, but it weakens browser isolation while rendering user-controlled content and allows broad local file paths, so it needs review before installation.

Install only if you are comfortable with local Python scripts launching Chrome with the browser sandbox disabled. Render trusted text and Markdown, keep output paths inside the workspace, avoid passing sensitive local files as icons or input files, and consider running it in a container or low-privilege environment.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (26)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/templates/x-like-posts.html (reported line 5)May include surrounding context.

html
<html>
<head>
<meta charset="UTF-8">
<!--
  Template: x-like-posts
  Width: 900px
  Height: dynamic

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/templates/x-like-posts.html (reported line 5)May include surrounding context.

html
<html>
<head>
<meta charset="UTF-8">
<!--
  Template: x-like-posts
  Width: 900px
  Height: dynamic

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill description and all user-facing instructions are written only in Chinese, and the examples hard-code Chinese platform/footer text such as '公众号' and '小红书'. For a generally named image-generation skill, this constitutes a language/locale constraint without any stated opt-in or justification for being China-specific.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill invokes shell commands and reads local reference files, but it does not declare any explicit tool scope or permissions boundary. This increases the chance that an agent runtime will grant broader-than-necessary capabilities, making misuse of shell execution or file access harder to constrain or audit.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger language is broad enough that many generic 'post-like' or social-content requests may route into this skill unintentionally. Over-broad invocation can cause the agent to read files and write outputs when the user did not clearly request image rendering, increasing the risk of unexpected file operations or misuse of user-provided paths.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The template comments describe usage and parameters in Chinese, and the styling explicitly prioritizes a Chinese font stack. This indicates a locale-specific assumption, but the file does not present any user opt-in, language selection, or justification that the template is intentionally region-specific.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The document first states that the LLM must pre-compute pagination and should not rely on the script for mechanical splitting. Later, lines L62-L66 describe script-side pagination rules as if the script performs segmentation automatically, which directly conflicts with the earlier instruction about responsibility for page splitting.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

该 markdown 明确规定“当前模板按 Asia/Shanghai (UTC+8) 展示时间”,属于强制特定地区/时区展示的语言/locale 约束。文档中未提供用户选择时区的方式,也未说明这是仅适用于特定地区场景,因此符合自然语言政策中的 locale 选择缺失问题。

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest describes a skill for generating card, cover, and social post images, but the implementation depends on launching external executables via subprocess: Chrome/Chromium for rendering and ffmpeg for cropping. While rendering images is in-scope, arbitrary subprocess execution is a broader capability than the stated purpose and is not explicitly justified by the manifest text.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script launches Chrome with --no-sandbox while rendering dynamically generated HTML that includes user-controlled text and file references. Disabling the browser sandbox weakens isolation, so any browser-side exploit or unsafe local-resource interaction would run with fewer protections than normal, increasing host compromise risk in environments where this skill processes untrusted input.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/render_article.py (reported line 174)May include surrounding context.

python
f"--window-size={w},{window_h}",
        f"file://{tmp_html}",
    ]
    result = subprocess.run(cmd, capture_output=True)
    if result.returncode != 0:
        sys.exit(f"Chrome failed:\n{result.stderr.decode()}")

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/render_card.py (reported line 148)May include surrounding context.

python
f"--window-size={w},{window_h}",
        f"file://{tmp_html}",
    ]
    result = subprocess.run(cmd, capture_output=True)
    if result.returncode != 0:
        sys.exit(f"Chrome failed:\n{result.stderr.decode()}")

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/render_x_like_posts.py (reported line 286)May include surrounding context.

python
f"--window-size={w},{window_h}",
        f"file://{tmp_html}",
    ]
    result = subprocess.run(cmd, capture_output=True)
    if result.returncode != 0:
        sys.exit(f"Chrome failed:\n{result.stderr.decode()}")

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/render_card.py (reported line 169)May include surrounding context.

python
"1",
            str(out),
        ]
        crop_result = subprocess.run(crop_cmd, capture_output=True)
        screenshot_path.unlink(missing_ok=True)
        if crop_result.returncode != 0:
            sys.exit(f"ffmpeg crop failed:\n{crop_result.stderr.decode()}")

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code hard-codes Asia/Shanghai and the label UTC+8, and later converts all parsed timestamps into that timezone for output. This creates a natural-language locale policy issue because users are not given any choice or notice that dates will be rendered in a fixed locale-specific timezone.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill explicitly allows output to user-specified absolute or relative paths, yet it does not clearly warn users that rendering will write PNG files to disk. Without an explicit notice and path constraints, the agent may overwrite unintended files or place artifacts in sensitive locations, especially when combined with broad shell/file capabilities.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The rule maps user mentions like '小红书配图' or '小绿书' to presets, but it does not define how exact the match must be or what to do with near matches, mixed intents, or unrelated mentions. This ambiguity can lead to accidental preset selection during ordinary conversation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The natural-language comments and example UI text specify Chinese usage and Chinese default labels such as the bottom tip examples, which suggests the template is intended to render a fixed locale experience. There is no indication in the file that users can choose another language or that the Chinese-only constraint is explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The template metadata comment uses Chinese-only labels such as "用途" and parameter descriptions, which imposes a specific language context without any indication that this skill is region-specific or that users can choose locale. Under the policy, language constraints should be opt-in or clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This HTML template includes natural-language comments and parameter descriptions in Chinese, and the file does not indicate that the locale is optional or region-specific. Under the policy rule, forcing a specific language without user opt-in can be a language/locale policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

该文件整体以中文规定模板文案与使用方式,并在示例中默认生成中文封面文字,但没有说明这是可选的语言设置,也未提供用户语言偏好选择。根据规则,若技能强制特定语言而无用户选择或明确合理的区域限定,属于自然语言策略风险。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
71% confidence
Finding

L05 states that rendering will additionally call ffmpeg for precise top cropping, but the only documented render command is a direct python3 .../render_card.py invocation with no mention of ffmpeg arguments or step. While this may happen internally, the documentation as written creates an intent/behavior inconsistency about what the command itself does.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The applicability section activates on phrases like “公众号文章封面图” and “微信公众号头图 / 封面长图”, plus a broader condition of needing one image split into left and right sections. It does not provide negative examples or clearer scope boundaries, which could cause the template to be selected in adjacent design requests where the user did not intend this specific format.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The example command at L35 supplies --footer "made by Jinx", suggesting the footer can be set through input, while the parameter table at L49 states the template actually always shows a fixed made by Jinx value. This is a direct documentation-level contradiction about whether the argument has any effect.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

Natural-language strings in the module docstring and argument help text force a specific language for all users. The file does not indicate that this is a China-specific or Chinese-only skill, nor does it offer an opt-in or alternative locale.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.