Back to skill

Security audit

Image To 3d

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent image-to-3D purpose, but it asks agents to run mutable remote code and globally install mutable skill content without enough pinning or validation.

Review before installing. Only use this in a sandboxed agent environment with access limited to the intended image and token, prefer pinned package versions or verified commits, and do not let the agent execute returned command strings unless you can inspect and approve the exact command.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:30
Finding

Execution of an Unpinned npm Package Using the Mutable latest Tag

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:42
Finding

Unpinned Global Skill Installation from Mutable Third-Party Sources

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Warning
Location
SKILL.md:28
Finding

Execution of a Command Dynamically Supplied by a Hosted Service

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The skill instructs agents to execute an npm package via npx -y image-skill@latest, which fetches and runs the latest published code at execution time rather than a reviewed, immutable version. If the package is compromised, hijacked, or updated with malicious behavior, an agent could execute attacker-controlled code in its environment, making this a supply-chain execution risk rather than a harmless documentation issue.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The main runtime command again uses npx -y image-skill@latest, causing live retrieval and execution of whatever code is currently published under that package name. Because this command is the one intended for actual media creation and likely to be run by agents, compromise of the package could lead to arbitrary code execution, token theft, or manipulation of generated assets and billing flow.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The installation guidance uses npx skills add ... without pinning the skills package version, so the agent may execute an unreviewed package version at install time. While this is somewhat less directly dangerous than the primary runtime package if skills is well-known, it still introduces a supply-chain path for arbitrary code execution during setup.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

This alternate install command also invokes npx skills without a pinned version, creating the same setup-time supply-chain risk. An attacker who can influence the published package or dependency chain could cause arbitrary code execution when an agent follows the skill's installation instructions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.