Back to skill

Security audit

IceCube Digital Human

Security checks for vulnerabilities and agentic risk

Overview

This is a non-executable guide for creating digital humans, with expected biometric upload guidance and basic consent rules, but users should treat voice and face data carefully.

Before installing, understand that this guide may lead you to upload voice, photo, or video samples to third-party cloning platforms. Use only your own likeness or material you are authorized to use, check each vendor's retention and privacy terms, and clearly label generated content as AI-created.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This section instructs users to upload voice samples, photos, and videos to third-party cloning platforms but does not clearly warn that these are sensitive biometric identifiers with significant privacy, retention, and misuse risks. In a skill specifically designed to create digital humans, omission of strong warnings and consent checks materially increases the chance of unauthorized cloning, irreversible data exposure, and downstream fraud or impersonation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description triggers on broad terms like '数字人', 'digital human', 'AI 分身', and '虚拟主播' without defining safe boundaries or requiring verification of lawful, consent-based use. Because the skill centers on voice and avatar cloning, an overly broad trigger can cause it to activate in impersonation, deception, or privacy-sensitive contexts where the user has not demonstrated authorization.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.