Back to skill

Security audit

Table Image

Security checks for vulnerabilities and agentic risk

Overview

This table-image skill mostly matches its purpose, but it downloads and caches unverified emoji artwork from a live CDN and processes it through a flagged image library.

Review before installing. The skill does not show credential theft, destructive behavior, or hidden agent-control instructions, but it should pin or vendor emoji assets, validate downloaded SVGs, add network limits, disclose the cache behavior, and update/pin Sharp to a reviewed non-vulnerable version before broad use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
scripts/emoji.mjs:55
Finding

Mutable and Unverified Remote Emoji Assets

Content
View full analysis
{ const doFetch = (url, redirects = 0) => { if (redirects > 5) return reject(new Error('Too many redirects')); https.get(url, (res) => { if (res.statusCode >= 300 && res.statusCode < 400 && res.headers.location) { return doFetch(res.headers.location, redirects + 1); } if (res.statusCode !== 200) return reject(new Error(`HTTP ${res.statusCode}`)); let data = ''; res.on('data', chunk => data += chunk); res.on('end', () => resolve(data)); }).on('error', reject); }; doFetch(url); }); } /** * Get Twemoji SVG content for an emoji (with local caching) */ export async function getEmojiSvg(emoji) { const cp = emojiToCodepoint(emoji); // Check cache first if (!existsSync(CACHE_DIR)) mkdirSync(CACHE_DIR, { recursive: true }); const cachePath = join(CACHE_DIR, `${cp}.svg`); if (existsSync(cachePath)) { return readFileSync(cachePath, 'utf8'); } // Fetch from Twemoji CDN const url = `https://cdn.jsdelivr.net/gh/twitter/twemoji@latest/assets/svg/${cp}.svg`; try { const svg = await fetchUrl(url); writeFileSync(cachePath, svg); return svg; } catch (e) { // Fallback: return null (will render as text) return null; } } ``` ### Technical Analysis The emoji renderer downloads SVG files from a third-party CDN using the mutable `twemoji@latest` reference. Consequently, the effective asset content can change after the Skill has been reviewed or installed. The download process has the following weaknesses: - The Twemoji dependency is not pinned to an immutable version or commit. - Downloaded S ...[truncated 2367 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Known Vulnerable Dependency: sharp==0.33.5 — 2 advisory(ies): GHSA-f88m-g3jw-g9cj (sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-); GHSA-rgj7-g3m4-5g8c (sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545)

High
Category
Supply Chain
Confidence
96% confidence
Finding

This is a true dependency risk: the lockfile pins sharp to 0.33.5, and the provided advisory indicates known inherited vulnerabilities in bundled image-processing components such as libvips/libheif. Because this skill generates images from input data, it likely processes attacker-influenced content or rendering parameters, which increases the chance that a crafted input could trigger memory corruption, denial of service, or other native-code exploitation in the image stack.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: sharp==0.33.5 — 2 advisory(ies): GHSA-f88m-g3jw-g9cj (sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-); GHSA-rgj7-g3m4-5g8c (sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545)

High
Category
Supply Chain
Confidence
99% confidence
Finding

The package resolves to sharp 0.33.5, which is reported to inherit vulnerabilities from bundled/native image libraries such as libvips and libheif. In a skill whose purpose is generating images from table data, image-processing code is central functionality, so vulnerable native parsers can expose the system to crashes, denial of service, or potentially memory-safety issues if attacker-controlled image input is ever processed.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes generating clean table images with styling features, but this helper reaches out to a remote Twemoji CDN and writes fetched assets into a local cache directory. While emoji rendering can support image generation, the manifest does not indicate any network dependency or asset downloading behavior, so the implemented behavior exceeds the stated description.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This file uses HTTPS requests to fetch emoji SVGs from jsDelivr, introducing external network access into a skill presented as a table-image generator with no mention of remote services. Generating table images does not inherently require network communication, especially when the manifest emphasizes 'No Puppeteer required' and does not disclose online dependencies.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code fetches SVGs from an external CDN and writes them into a local cache directory, which are safety-relevant operations under the code-file warning criteria. Although the file-level comments describe the behavior, there is no user-facing log, prompt, or explicit disclosure at the point of network access and filesystem modification.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
96% confidence
Finding

The dependency is specified with a caret range (^0.33.0), which allows automatic installation of newer patch/minor releases within the 0.33.x line rather than a fully fixed version. This weakens build reproducibility and can unintentionally pull in a vulnerable release such as 0.33.5, increasing supply-chain risk even though version ranges alone are not inherently malicious.

Content

Scanner excerpt · scripts/package.json (reported line 5)May include surrounding context.

json
"name": "table-image-scripts",
  "type": "module",
  "dependencies": {
    "sharp": "^0.33.0"
  }
}

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
tests/table.test.mjs:23