Back to skill

Security audit

Image To Relief Stl

Security checks for vulnerabilities and agentic risk

Overview

The skill does the advertised image-to-STL conversion, but its wrapper has a real code-execution bug in the optional preview path and installs unpinned packages at runtime.

Use this only in a constrained environment and avoid --preview-svg for files whose names or paths may be attacker-controlled. Expect first use to download Python packages into a cache virtualenv unless dependencies are pre-provisioned. Prefer a fixed version with the preview heredoc bug patched and dependencies pinned or vendored.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/image_to_relief.sh:80
Finding

Arbitrary Python Code Execution Through an Injected Input Filename

Content
View full analysis
10 and (r,g,b) != bg: mask.putpixel((x,y), 0) mask.save("$TMPDIR/preview.pbm") PY ``` ### Technical Analysis The optional SVG preview implementation embeds the attacker-controllable `$IN` value directly into Python source code inside an unquoted heredoc. Shell quoting used when initially assigning `IN="$1"` does not protect the value when it is subsequently inserted into generated Python code. Because the heredoc delimiter is unquoted, the shell expands `$IN` before passing the script to Python. A filename containing quotation marks, newlines, comment characters, or Python expressions can terminate the intended string literal and introduce arbitrary Python statements. For example, a malicious argument can be constructed so that the generated source is conceptually transformed into: ```python img = Image.open("legitimate-file.png") __import__("os").system("attacker-command") #").convert('RGBA') ``` The injected code is executed by the virtual-environment Python interpreter with the same operating-system privileges as the user or Agent invoking the Skill. The vulnerable path is reached only when the optional `--preview-svg` feature is requested. ### Attack Path 1. An attacker creates or supplies an image path containing Python syntax, including a quote and newline characters. 2. The attacker causes the Skill or an orchestrating Agent to invoke `image_to_relief.sh` with that path as its first argument. 3. The invocation includes `--preview-svg`, causing execution ...[truncated 1317 chars]
Remediation
View remediation
10 and (r, g, b) != bg: mask.putpixel((x, y), 0) mask.save(output_path) PY ``` Additional hardening measures: 1. Retain shell quoting around all path arguments passed to external commands. 2. Validate that the input path refers to an expected regular image file where the deployment model permits such restrictions. 3. Avoid dynamically constructing executable source from user-controlled values. 4. Add regression tests using filenames containing quotes, newlines, spaces, shell metacharacters, and Python syntax. 5. Run image processing in a restricted execution environment when processing files or paths supplied by untrusted parties. ]]>

T08 · Insecure Dependencies

Warning
Location
scripts/image_to_relief.sh:53
Finding

Unpinned Third-Party Packages Installed at Runtime

Content
View full analysis
/dev/null "$VENV/bin/pip" install pillow >/dev/null fi ``` ### Technical Analysis On first execution, the wrapper creates a virtual environment and downloads the latest available versions of `pip` and `pillow`. Neither package is pinned to a reviewed version, and no package hashes are verified. This makes execution dependent on mutable external package-index state. The code ultimately executed by the Skill can therefore differ from the code present when the project was audited. Upgrading `pip` at runtime further expands the supply-chain attack surface and is not necessary for the image conversion operation. Python package installation may execute package build logic or install executable modules. If the configured package index, mirror, DNS path, proxy, package account, or upstream release is compromised, malicious package content can execute or later be imported with the invoking user's privileges. This finding does not establish that the current official `Pillow` or `pip` packages are malicious. The vulnerability is the absence of version locking and integrity verification in an automatic runtime installation path. ### Attack Path 1. The Skill runs on a system where the cache-based virtual environment does not yet exist or where its Python executable has been removed. 2. The wrapper creates a new virtual environment. 3. It contacts the configured Python package index to upgrade `pip` without a version or hash constraint. 4. It then retrieves `pillow`, also without a version or hash constraint. 5. A compromised upstream release, package-index account, mirror, proxy, or local package-index configuration supplies hostile package content. 6. Package insta ...[truncated 958 chars]
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill advertises executable workflow steps that write output files (for example generating an STL and optional preview) but does not declare any explicit tool scope such as permissions or allowed-tools. In an agent environment, missing scope declarations can cause overbroad file-write capability, making it easier for the skill to write to unintended locations or operate without clear sandboxing expectations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This wrapper performs runtime package installation with pip when the virtual environment is missing, which gives the skill outbound package-management capability and causes execution to depend on remote package retrieval and the current package index state. Even though the installed package is only Pillow and there is no obvious command injection here, this expands the attack surface through supply-chain risk, non-deterministic builds, and unexpected network access in a skill that otherwise appears to be a local image-to-STL conversion pipeline.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.