Back to skill

Security audit

Photo Guide

Security checks for vulnerabilities and agentic risk

Overview

This photo-guidance skill is mostly coherent, but it reads precise GPS metadata from photos and can automatically install an unpinned Python image library.

Review before installing. Use a virtual environment, do not allow automatic dependency installation without approval, pin or lock Pillow, and strip GPS/location metadata from personal photos before using this skill unless you are comfortable exposing that metadata to the agent context.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/extract_exif.py:84
Finding

Unnecessary Disclosure of Sensitive GPS Metadata

Content
View full analysis

Vulnerability Details

File Location: scripts/extract_exif.py, lines 84-89
Vulnerability Type: Excessive access to and disclosure of sensitive location metadata
Risk Level: Medium

Vulnerable Code:

python
      # GPS information
      if 34853 in exif_data:
          gps_info = {}
          for key, val in exif_data[34853].items():
              gps_info[GPSTAGS.get(key, key)] = val
          result["gps"] = gps_info

Technical Analysis

The script extracts all available GPS EXIF fields and includes them in its JSON output. The documented photography workflow requires shooting parameters such as aperture, shutter speed, ISO, focal length, and camera model, but it does not require precise geographical location.

Consequently, the implementation accesses and discloses sensitive metadata beyond the minimum necessary scope. Because the JSON is returned to the Agent, GPS information may enter the conversation context, execution logs, or other downstream records. The audit found no code that transmits this information to an external service, so this is a local over-collection and disclosure issue rather than confirmed network exfiltration.

Attack Path

  1. A user provides a photograph containing embedded GPS EXIF metadata.
  2. The Skill invokes scripts/extract_exif.py with the photograph path.
  3. Pillow reads the photograph and returns its complete EXIF structure.
  4. The script identifies EXIF tag 34853 and copies every GPS field into gps_info.
  5. The GPS data is serialized into the JSON response under the gps property.
  6. The Agent runtime, conversation history, or execution logs may retain the disclosed location.

No attacker-controlled privilege escalation is required; the issue occurs during normal processing of a geotagged image.

Impact Assessment

The script can read and expose location metadata already embedded in any image that the invoking user permits it to acce ...[truncated 360 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove GPS extraction because it is unnecessary for the documented photography analysis:

    python
    # Do not extract or return GPS metadata.
    result = {"has_exif": True, "params": params}
    return result
    
  2. If location analysis becomes a legitimate optional feature, require explicit informed consent before reading or returning GPS fields.

  3. Return only an indicator such as has_gps: true unless exact coordinates are essential.

  4. When approximate location is sufficient, round coordinates and omit altitude, timestamp, processing method, and other unnecessary GPS fields.

  5. Ensure Agent prompts, diagnostic output, telemetry, and execution logs do not retain precise GPS values.

  6. Document all collected EXIF fields and provide users with a privacy warning before processing geotagged photographs.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:43
Finding

Automatic Installation of an Unpinned Third-Party Dependency

Content
View full analysis

Vulnerability Details

File Locations: SKILL.md, lines 43-51; requirements.txt, line 1
Vulnerability Type: Uncontrolled third-party dependency resolution and automatic package installation
Risk Level: Medium

Vulnerable Code and Configuration:

markdown
### Step Zero: Check and install dependencies

Before starting the analysis, check whether the Python dependency is installed:

```bash
python3 -c "import PIL" 2>/dev/null || pip install -r requirements.txt
  • If PIL is installed, skip installation and continue.
  • If it is not installed, execute pip install -r requirements.txt and continue after installation.
text

```text
Pillow>=9.0.0

Technical Analysis

The Skill instructs the Agent to run pip install automatically when Pillow is unavailable. The requirement specifies only a minimum version, allowing the resolver to install any future release satisfying Pillow>=9.0.0. No exact version, artifact hash, trusted index configuration, or isolated environment is required.

This makes installations non-reproducible and places trust in the package index, resolver configuration, network path, and latest available matching release at execution time. Python package installation can execute package build or installation logic with the permissions of the Agent process.

The dependency name Pillow is legitimate, and the audit found no evidence of typosquatting or a currently malicious package. The vulnerability is the unsafe installation policy and unrestricted future version resolution, not a confirmed malicious dependency.

Attack Path

  1. The Skill runs in an environment where PIL cannot be imported.
  2. The fallback expression automatically invokes pip install -r requirements.txt.
  3. Pip resolves Pillow>=9.0.0 using the environment's configured package indexes and resolver settings.
  4. A compromised index, malicious mirror, altered resolver configuration, compromised ...[truncated 1016 chars]
Remediation
View remediation

Remediation Suggestions

  1. Do not install packages automatically during Skill activation. Detect the missing dependency, stop safely, and request explicit user or administrator approval.

  2. Pin Pillow to an exact reviewed version instead of using an unrestricted lower bound:

    text
    Pillow==REVIEWED_VERSION
    
  3. Generate a lock file containing cryptographic hashes and install with hash enforcement:

    bash
    python3 -m pip install --require-hashes -r requirements.lock
    
  4. Obtain hashes from reviewed release artifacts and include hashes for every permitted distribution required by supported platforms.

  5. Use a dedicated virtual environment or another isolated, non-privileged runtime rather than modifying the Agent's global Python environment.

  6. Configure an approved HTTPS package index explicitly and prevent untrusted additional indexes or mirrors from participating in resolution.

  7. Run dependency vulnerability and provenance checks as part of release maintenance.

  8. Separate dependency installation from image analysis so ordinary Skill execution does not unexpectedly perform network access or execute installer code.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This is a true privacy vulnerability because the code exposes precise geolocation metadata without clear necessity for the advertised functionality. In the context of a photo-guidance skill, disclosing location data is more dangerous because users are likely uploading personal photos for creative advice, not consenting to location analysis or sharing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The primary README content, including usage examples and operational description, is written in Chinese, while only a link to an English file is provided. This can constitute a language-policy issue if the skill experience defaults to a specific language without explicitly offering language selection or opt-in within the skill description itself.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The entire skill file is written only in Chinese and does not indicate any language choice, fallback, or opt-in. Under the stated policy, fixed language constraints can be a natural-language policy violation unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script returns GPS EXIF metadata even though the skill’s stated purpose is photography guidance about style, shooting parameters, and post-processing. GPS coordinates can reveal a user’s home, workplace, or travel patterns, so exposing them creates unnecessary sensitive-data disclosure beyond the minimum data needed for the feature.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README states that uploaded photos will have EXIF metadata extracted automatically, but it does not clearly warn users that metadata may contain sensitive information such as device model, timestamps, and GPS coordinates. In a photo-analysis skill, this creates a real privacy risk because users may not realize that hidden metadata will be accessed and used alongside the image content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file contains user-facing instructional content exclusively in Chinese, and there is no indication that the skill is region-specific or that users can opt into this language. Under the policy rule for natural-language violations, forcing a specific language without user choice can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

The dependency is specified as Pillow>=9.0.0, which allows installation of many different versions over time, including future releases and historically vulnerable versions. In a photo-analysis skill that is likely to process user-supplied images, an unpinned image library increases supply-chain and exposure risk because Pillow has had memory corruption, resource exhaustion, and code-execution-related advisories.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
Pillow>=9.0.0

Unverifiable Dependency: Pillow has 16 known advisory(ies) (CVE-2016-2533 (Pillow buffer overflow in ImagingPcdDecode); CVE-2023-50447 (Arbitrary Code Execution in Pillow); CVE-2021-27922 (Pillow Uncontrolled Resource Consumption) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
96% confidence
Finding

The manifest does not pin the Pillow version, so there is no way to verify whether deployment will use a release affected by known CVEs. This is more dangerous in this skill's context because photography guidance commonly involves handling untrusted uploaded images, and Pillow vulnerabilities have included issues such as arbitrary code execution and denial of service triggered during image parsing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The module docstring and user-facing error/help text are written in Chinese, indicating the skill is oriented to a single language. The policy requires avoiding forced language/locale constraints unless the skill offers a choice or clearly documents a justified region-specific limitation, which is not present here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.