Alibaba Super Resolution

Security checks across malware telemetry and agentic risk

Overview

This appears to be a coherent Alibaba Cloud video enhancement skill, but users should understand that videos and credentials are involved before using it.

Install only if you trust the publisher and are comfortable sending selected videos to Alibaba Cloud for processing. Use least-privilege Alibaba Cloud credentials, avoid sensitive videos unless authorized, and prefer pinned dependency versions in controlled environments.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Lp3

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding
The skill clearly requires environment credentials, network access, and file writes, but it does not declare permissions for those capabilities. This creates a transparency and governance gap: users or the platform may invoke a skill that can access secrets, upload content to a third-party cloud service, and write output files without an explicit permission model.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The README explicitly promotes uploading local video files to Alibaba Cloud but does not disclose that user content leaves the local environment and is transmitted to a third-party cloud provider. In a media-processing skill, this omission can cause users to submit sensitive or copyrighted videos without understanding privacy, retention, jurisdiction, or compliance implications.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The documentation instructs users to configure cloud credentials and upload/download video content, but it does not disclose that videos may be transmitted to Alibaba Cloud or explain the associated privacy, confidentiality, and data residency risks. This is especially important because videos may contain sensitive personal, proprietary, or regulated content, and users are not warned before sending that data to a third-party processor.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The tool reads the entire local video and submits it to Alibaba Cloud, but it does not provide an explicit consent or privacy warning at the point of upload. This can cause unintended exfiltration of potentially sensitive media to a third-party service, especially in agent contexts where users may assume processing is local.

Unpinned Dependencies

Low
Category
Supply Chain
Content
requests>=2.31.0
alibabacloud_tea_openapi>=0.3.0
alibabacloud_tea_util>=0.3.0
alibabacloud_videoenhan20200320>=1.1.0
Confidence
97% confidence
Finding
requests>=2.31.0

Unpinned Dependencies

Low
Category
Supply Chain
Content
requests>=2.31.0
alibabacloud_tea_openapi>=0.3.0
alibabacloud_tea_util>=0.3.0
alibabacloud_videoenhan20200320>=1.1.0
Confidence
96% confidence
Finding
alibabacloud_tea_openapi>=0.3.0

Unpinned Dependencies

Low
Category
Supply Chain
Content
requests>=2.31.0
alibabacloud_tea_openapi>=0.3.0
alibabacloud_tea_util>=0.3.0
alibabacloud_videoenhan20200320>=1.1.0
Confidence
96% confidence
Finding
alibabacloud_tea_util>=0.3.0

Unpinned Dependencies

Low
Category
Supply Chain
Content
requests>=2.31.0
alibabacloud_tea_openapi>=0.3.0
alibabacloud_tea_util>=0.3.0
alibabacloud_videoenhan20200320>=1.1.0
Confidence
96% confidence
Finding
alibabacloud_videoenhan20200320>=1.1.0

Known Vulnerable Dependency: requests — 10 advisory(ies): CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +7 more

High
Category
Supply Chain
Confidence
90% confidence
Finding
requests

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal