Back to skill

Security audit

photo-editor

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward photo/image generation guide that uses a disclosed external API, with a privacy documentation gap users should keep in mind.

Before using this skill, treat submitted prompts and uploaded images as data shared with the external DeepNLP/Craftsman service. Avoid confidential images or proprietary prompts unless you are comfortable with that provider's handling and any workspace/share links it creates.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill explicitly instructs users to send prompts, uploaded reference images, and session metadata to external services (`agent.deepnlp.org` and linked workspace domains) without a clear privacy or data-handling warning. In an agent ecosystem, users may provide sensitive images or proprietary prompts, so inadequate disclosure can cause unintended exfiltration of confidential content to third-party infrastructure.

Static analysis

No suspicious patterns detected.