Back to skill

Security audit

CamScanner Remove Image Watermark

Security checks for vulnerabilities and agentic risk

Overview

This skill openly removes watermarks and stamps from images, but it lacks clear limits to prevent misuse on copyrighted or official documents.

Install only if you will use it on images you own or are authorized to edit, and only after confirming uploads to CamScanner's servers are acceptable. Avoid using it on copyrighted third-party images, IDs, contracts, certificates, signatures, seals, official records, or any document where a mark indicates authenticity or provenance.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger text is overly broad because it activates not only on explicit phrases like 'remove watermark' but also whenever a user merely has an image with a watermark that 'needs to be removed.' That increases the chance of accidental or over-eager invocation for ambiguous requests and funnels users into a capability that is commonly associated with copyright circumvention and document tampering.

Natural-Language Policy Violations

High
Confidence
98% confidence
Finding
The skill explicitly promotes removal of watermarks, stamps, and logos without any authorization, ownership, or rights verification. In context, this enables misuse for copyright circumvention, falsification of documents, and removal of provenance or authenticity markings, making the skill materially more dangerous than a generic image-processing tool.

Static analysis

No suspicious patterns detected.