Back to skill

Security audit

Image Processor

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward local image-processing skill, with ordinary file-output risks but no evidence of hidden behavior, exfiltration, persistence, or privilege escalation.

Before installing, treat it as a local file-modifying utility: keep backups of important images, always pass an explicit --output path, avoid running batch operations on originals, install Pillow from a trusted pinned dependency source where possible, and avoid extreme resize or filter values.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Note
Location
scripts/process.py:25
Finding

Unpinned Third-Party Dependency Installation Guidance

Content
View full analysis
Remediation
View remediation
--hash=sha256: ``` 3. Install dependencies with hash verification, such as `pip install --require-hashes -r requirements.txt`. 4. Specify an explicitly trusted package index in deployment documentation and prevent fallback to unapproved indexes. 5. Integrate dependency vulnerability scanning and controlled version-update reviews. 6. Replace the runtime message with instructions referencing the reviewed dependency file rather than a floating `pip install pillow` command. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/process.py:35
Finding

Unbounded Image Processing Parameters Permit Resource Exhaustion

Content
View full analysis
Remediation
View remediation
MAX_PIXELS: raise ValueError("Requested image exceeds the pixel limit") ``` 3. Bound scale percentages, blur radii, rotation values, crop dimensions, and thumbnail sizes to documented safe ranges. 4. Validate computed automatic dimensions after resolving zero-width or zero-height requests. 5. Check source-image dimensions and configure Pillow decompression-bomb protections rather than disabling them. 6. Enforce per-process CPU, memory, execution-time, and output-file-size limits at the container or operating-system level. 7. Limit the number of files accepted in batch mode and stop processing after repeated failures. 8. Catch parsing, Pillow, memory, and filesystem exceptions and return a controlled error without exposing a traceback or leaving partial output files. ]]>
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill documentation instructs users to run a local script that writes output files, but the skill declares no explicit tool scope such as permissions or allowed-tools. That mismatch can lead to overbroad file-write behavior or unclear enforcement boundaries, increasing the chance of unintended file modification if an agent executes the skill with implicit filesystem access.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code claims fallback mode supports format conversion, but the fallback path only copies the original bytes and may assign a new extension. This can misrepresent file contents, causing downstream consumers or security checks to trust an extension that does not match the actual data, which can lead to unsafe handling or operational errors.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The processor defaults output_path to args.input, so transformations can overwrite the original file in place without confirmation. In an agent or automated workflow, this can cause silent destruction of user data or corruption of source images, especially when batch or scripted operations are used.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes the skill as handling resize, crop, compress, format conversion, thumbnails, and filters. While blur may fit the broad 'apply filters' wording, the code also performs rotate, grayscale, and scale operations that are not mentioned in the manifest description. This is a mild description-behavior mismatch because the code’s capabilities exceed the specifically claimed processing scope.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The inline comment and CLI help indicate a crop syntax of 'WxH+X+Y', but the code splits on '+' only once and then parses the offset using split('y'), which does not match the documented format. This is an intent-code divergence because the documented interface contradicts the actual parser behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The fallback path performs a file write via shutil.copy and only reports the action after it has completed. There is no prior warning, confirmation, or explanatory comment indicating to users that a new file will be created in fallback mode.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.