Back to skill

Security audit

The Scribble Thing

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent image-to-animation integration that discloses uploads, retention, tokens, pricing, and user-controlled deletion.

Before installing, be comfortable that your uploaded artwork will be sent to the external Scribble Thing service and retained for the current period reported by that service. Only use images you have rights to process, and treat private management links or unlock codes as sensitive because they grant access to an animation.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The manifest advertises destructive capabilities ('delete') alongside create/download operations without any user-facing warning, confirmation requirement, or indication of scope boundaries. In an agentic setting, this increases the risk of accidental or prompt-induced deletion of user assets, especially if the agent treats deletion as routine cleanup.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.