Back to skill

Security audit

Photo Cinematic Editor

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent local photo editor, but its install instructions can modify system Python and should be reviewed before installation.

Install only in a virtual environment or other isolated Python environment, preferably with pinned dependency versions. Avoid running the auxiliary scripts without explicit input and output paths unless you intend to use their hardcoded OpenClaw media/workspace defaults.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:57
Finding

Unpinned Dependencies Installed into the System Python Environment

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 57-59
Vulnerability Type: Unpinned third-party dependencies and unsafe system-level package installation
Risk Level: Medium

Vulnerable Code

bash
pip3 install Pillow numpy pillow-heif --break-system-packages

Technical Analysis

The documented installation command installs Pillow, numpy, and pillow-heif without fixed versions or package hashes. Consequently, the exact code installed depends on the package releases available when the command is executed rather than on versions reviewed with this project.

The --break-system-packages option bypasses protections intended to prevent pip from modifying an externally managed system Python installation. This can overwrite or conflict with operating-system-managed packages and expands the effect of a dependency compromise beyond an isolated project environment.

Attack Path

  1. An attacker compromises a listed package, a package maintainer account, or the relevant distribution channel.
  2. The attacker publishes a malicious release under one of the dependency names.
  3. A user follows the installation command in SKILL.md.
  4. Because no versions or hashes are pinned, pip resolves and downloads the malicious release.
  5. Malicious installation or runtime code executes with the privileges of the user running pip.
  6. Because the command targets system Python, the compromised package may also affect other applications that use the same Python environment.

Impact Assessment

Successful exploitation can execute attacker-controlled code with the invoking user's privileges. This may permit access to that user's files, environment variables, application data, and network capabilities. If the command is run by an administrator or through privilege elevation, the impact may extend to system-wide code execution and modification.

Even without a malicious dependency, modifying system Python can ...[truncated 227 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove --break-system-packages and install dependencies in a dedicated virtual environment:
    bash
    python3 -m venv .venv
    . .venv/bin/activate
    python3 -m pip install --require-hashes -r requirements.txt
    
  • Pin every dependency and transitive dependency to a reviewed version.
  • Record cryptographic hashes in the requirements file and enforce them with --require-hashes.
  • Periodically review and update pinned dependencies after security testing.
  • Use a trusted package index explicitly where appropriate and prohibit unreviewed supplemental indexes.
  • Run the image-processing scripts as an unprivileged user with access limited to the required input and output directories.
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill advertises a broad, keyword-driven trigger set covering many generic photo-editing terms, which can cause the agent to invoke this skill for loosely related requests the user did not intend to route here. This increases the chance of inappropriate tool selection, unnecessary file processing, or surprising behavior, especially because the skill operates on user-supplied images and supports automatic pipelines.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/cinematic_v2.py (reported line 27)May include surrounding context.

python
# Convert to float
    arr = img_arr.astype(np.float32) / 255.0
    
    # Create a blurred version (large radius) for local contrast
    h, w = arr.shape[:2]
    # Downscale then upscale for performance on large images
    scale = min(1.0, 2000 / max(h, w))

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code file contains multiple user-facing print messages in Chinese, such as status and error output, but provides no option for the user to select a language. That creates a natural-language locale policy issue because the skill effectively forces a specific language without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The description explicitly defines trigger keywords only in Chinese, which can imply a language-specific activation policy without offering a user choice or clarifying that other languages are also supported. This is a natural-language locale constraint in the manifest text and is not documented as an opt-in or region-specific limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code emits user-facing status text such as "读取图片" and "尺寸" in a single fixed language. The policy requires avoiding forced language or locale constraints unless the user is given a choice or the limitation is clearly justified, which is not present here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.