Back to skill

Security audit

goods-images

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its advertised e-commerce image workflow, but it automatically installs an unpinned package and stores user product images in a shared temporary folder.

Review before installing in shared, sensitive, or production environments. Use it only where automatic package installation is acceptable, product images are not confidential, and generated product depictions will be manually checked for accuracy before publication.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:161
Finding

Unpinned Runtime Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 161–165
Vulnerability Type: Unpinned third-party package installation at runtime
Risk Level: Medium

Vulnerable Code Snippet:

markdown
#### Option 1 (preferred): `run_command` + Python PIL

Test the environment first:
```bash
python3 -c "from PIL import Image; print('ok')" 2>/dev/null || pip install Pillow -q

Technical Analysis

If the Pillow import fails, the Skill instructs the agent to install Pillow dynamically from the package index configured for pip. The dependency is not pinned to a reviewed version, verified against a cryptographic hash, resolved through a lock file, or restricted to an explicitly approved package repository.

As a result, installation behavior depends on mutable external package-index state and local pip configuration. A compromised package release, compromised repository, or attacker-controlled package index or mirror could supply malicious installation artifacts. Package installation and subsequent imports may execute attacker-controlled Python code with the privileges of the agent process.

The quiet option (-q) also reduces installation output, making repository changes or unexpected dependency resolution less visible during execution.

Attack Path

  1. Pillow is absent or deliberately made unavailable in the runtime environment.
  2. The initial python3 import command exits unsuccessfully.
  3. The shell executes pip install Pillow -q through the || branch.
  4. pip resolves the package using the environment's configured index and mirror settings.
  5. A compromised release, repository, mirror, or hostile index supplies a malicious distribution.
  6. Malicious code executes during package installation or when the installed package is imported.
  7. The code gains access to resources available to the agent process.

Impact Assessment

Successful exploitation could permit arbitrary code ...[truncated 512 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove automatic dependency installation from the Skill workflow.
  2. Declare Pillow as a preinstalled dependency in a reviewed deployment image or controlled environment specification.
  3. Pin Pillow to a reviewed exact version rather than resolving the latest available release.
  4. Use a lock file with cryptographic hashes and enforce installation with pip install --require-hashes.
  5. Restrict package resolution to an approved, authenticated repository or internal mirror.
  6. Install dependencies during a controlled build phase rather than while processing user requests.
  7. Run dependency installation and image processing in a sandboxed, least-privilege environment without unnecessary secrets or filesystem access.
  8. If Pillow is unavailable at runtime, use the documented no-install fallback instead of modifying the environment automatically.
  9. Preserve and review package-manager logs rather than suppressing relevant installation output with -q.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

The skill includes a shell deletion command and normalizes direct run_command use for filesystem mutation. Even though the specific command targets a fixed file, embedding destructive shell operations in skill instructions increases the chance of unsafe tool use, path mistakes, or future parameterization that could delete unintended files in the execution environment.

Content

Scanner excerpt · SKILL.md (reported line 305)May include surrounding context.

⚠️ 执行完成后删除中间产物:

bash
rm -f /tmp/product-details/overlay.py

方案 2(降级):generate_image 直接生成

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description says the skill triggers on broad keywords like “商品图”, “产品图”, “电商图”, “轮播图”, and “主图”. Several of these terms are generic and could appear in ordinary conversations about images or marketing assets, without clearly indicating this specific 14-image e-commerce generation workflow.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The core principle says the product image, including patterns, text, logo, and color, must not be changed and that outputs are layout/packaging based on the original image. However, later instructions direct repeated generate_image calls for model shots, lifestyle scenes, and feature pages, which can synthesize altered depictions rather than purely compositing the original asset. This is an active contradiction between stated intent and the documented implementation approach.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The core instructions prioritize Chinese text rendering, and the rest of the skill mandates Chinese titles, labels, and overlays throughout the output templates. This imposes a specific language/locale by default without stating that users may choose another language or that the scope is limited to Chinese-only use cases.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The activation bullets cover any case where a user uploads a product image or mentions broad commerce-image keywords, but they do not define when the skill should not run. Without explicit exclusions or a narrower scope, the skill may activate for general product-photo editing or analysis requests that are not intended to generate this full output set.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs writing user-derived images and intermediates to /tmp/product-details/ without clearly surfacing that local storage is used and that artifacts may persist. In shared or less-isolated runtimes, temporary files can be read by other processes, retained longer than expected, or mishandled, creating confidentiality and data-governance risk for uploaded product images and generated assets.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.