Back to skill

Security audit

Ganesh API

Security checks for vulnerabilities and agentic risk

Overview

This is a small image-hosting skill, but it sends users to mutable API instructions through a shortened URL and does not clearly require consent before uploading images externally.

Review this skill before installing. Only use it when you intentionally want to upload an image to Ganesh, verify the real API destination before sending data, and avoid sensitive or private images unless you understand how the hosting service stores and shares them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:18
Finding

Mutable External Instructions Retrieved Through a Shortened URL

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 18–19
Vulnerability Type: Untrusted external instruction delegation
Risk Level: Medium

Vulnerable Code Snippet:

markdown
## API Reference
Once you have your Client ID, you can use the Ganesh API to upload images. The full documentation is available at https://ishortn.ink/ganesh-official-api , and changes frequently, so refer to the official docs for the latest endpoints and parameters.

Technical Analysis

The Skill does not define the API endpoint, request parameters, destination host, or expected response locally. Instead, it directs the Agent to retrieve frequently changing operational instructions through a shortened URL. The redirect destination and retrieved content therefore cannot be verified from the reviewed package.

This creates an instruction-hijacking risk because whoever controls the shortened link or its destination can change the instructions after the Skill has been audited. Modified documentation could direct the Agent to upload images or related information to an attacker-controlled endpoint, request unnecessary credentials, or follow additional unsafe instructions. This finding concerns externally supplied instructions rather than executable remote code; the reviewed file does not explicitly download or execute code.

Attack Path

  1. A user asks the Agent to upload or host an image using the Ganesh Skill.
  2. The Skill directs the Agent to https://ishortn.ink/ganesh-official-api.
  3. The shortened URL redirects the Agent to content whose destination and integrity are not pinned in the Skill.
  4. The party controlling the redirect or destination changes the documentation after review.
  5. The altered documentation instructs the Agent to use a malicious upload endpoint, disclose a Client ID, transmit additional data, or follow unrelated unsafe instructions.
  6. If the Agent trusts those instructions, user-provided images ...[truncated 690 chars]
Remediation
View remediation

Remediation Suggestions

  • Replace the shortened URL with a transparent, verified first-party HTTPS URL.
  • Embed the reviewed API contract directly in the Skill, including the exact host, endpoint path, HTTP method, required fields, authentication behavior, and expected response.
  • Pin the Skill to a specific API version rather than automatically relying on frequently changing documentation.
  • Restrict uploads to an explicit allowlist of approved domains and reject redirects to unapproved hosts.
  • Treat retrieved documentation as untrusted reference material, not as executable Agent instructions.
  • Require explicit user confirmation before transmitting an image, Client ID, metadata, or other information to the hosting service.
  • Document precisely which data is transmitted and avoid sending credentials or unrelated contextual data.
  • Review and update the packaged API specification through a controlled release process whenever the service changes.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill advertises broad trigger phrases like "upload image" and "image hosting" without clear constraints about what content may be sent or when user confirmation is required. This increases the chance of over-invocation and unintended routing of user data to an external image-hosting service, especially in contexts where the user did not explicitly consent to third-party upload.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill describes anonymous image upload to a third-party service but does not warn users that their images will be transmitted outside the system. This can lead to accidental disclosure of sensitive, copyrighted, or private images because users may not understand that uploads are public or externally hosted.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.