Back to skill

Security audit

PixelMagic-PhotoLogic-9z

Security checks for vulnerabilities and agentic risk

Overview

This image-editing skill mostly matches its stated purpose, but it has insufficiently constrained local file writes that could place output or preset files outside the intended folders.

Review before installing. Use only simple output and preset names, avoid processing untrusted images, and install ImageMagick from a trusted source with current security patches. The package does not show exfiltration or persistence, but its path validation should be fixed before broad or automated use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/editor.py:276
Finding

Output Path Traversal Through Unvalidated Output Name

Content
View full analysis
Remediation
View remediation
str: if not re.fullmatch(r"[A-Za-z0-9_-]+", output_name): raise ValueError("Invalid output name") final_dir = (Path(self.work_dir) / "final").resolve() destination = (final_dir / f"{output_name}_final.jpg").resolve() if destination.parent != final_dir: raise ValueError("Output path escapes the final directory") if destination.exists(): raise FileExistsError(f"Output already exists: {destination}") return str(destination) ``` Use this function instead of constructing the destination directly with unvalidated caller input. If callers need to select an output directory, expose that as a separate parameter and enforce an explicit directory policy. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/editor.py:338
Finding

Arbitrary JSON File Write Through Unvalidated Preset Name

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description promises substantial image-processing functionality, but the supplied code chunk contains only a placeholder comment in init.py. Based on the provided code, none of the claimed capabilities can be verified or observed. This is a material mismatch between the declared purpose and the actual behavior of the supplied code chunk.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill instructs the agent to read and write local files and run shell commands (for ImageMagick processing) but does not declare any explicit tool scope or allowed-tools boundary. In an agent runtime, this weakens least-privilege controls and can let the skill operate with broader filesystem or command execution access than reviewers and policy expect.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest description and the full user-facing guidance are written entirely in Chinese, and the workflow examples instruct the agent to communicate completion messages in Chinese. This imposes a specific language/locale on users without opt-in or documented regional justification, which matches the language policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest text forces a specific language/locale in the user-facing description, which can violate language choice policy when no opt-in or alternative is provided. There is no indication elsewhere in the file that users can select their preferred language or that the Chinese-only description is required for a justified region-specific use case.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The module docstring and all user-facing CLI/help text are written exclusively in Chinese, which imposes a specific language on users without any opt-in or fallback. Under the stated policy, language constraints should either be optional or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/editor.py (reported line 26)May include surrounding context.

python
"""查找 magick 命令"""
        # 尝试直接调用
        try:
            result = subprocess.run(
                ['magick', '-version'],
                capture_output=True,
                text=True,

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/editor.py (reported line 63)May include surrounding context.

python
elif sys.platform == 'darwin':
            return "brew install imagemagick"
        else:
            return "sudo apt-get install imagemagick"
    
    def run_magick(self, args: List[str]) -> Tuple[bool, str]:
        """运行 magick 命令"""

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
82% confidence
Finding

This subprocess call executes ImageMagick on attacker-controlled image files and dynamically assembled arguments. Although it avoids shell injection by using a list, it still delegates parsing of untrusted files to a historically high-risk image-processing toolchain; malformed images or dangerous coders/delegates in ImageMagick can lead to file read/write, SSRF, or even code execution depending on policy and version.

Content

Scanner excerpt · scripts/editor.py (reported line 72)May include surrounding context.

python
cmd = [self.magick_path] + args
        try:
            result = subprocess.run(
                cmd,
                capture_output=True,
                text=True,

Static analysis

No suspicious patterns detected.