Back to skill

Security audit

Cn Batch Image Editor

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent local batch image tool, but a filename handling flaw in the rename command can write outside the intended output folder.

Review this skill before use. Run it only on copied image folders or with an explicit output directory, avoid prefix or date-format values containing slashes, backslashes, absolute paths, or '..', and install Pillow from a trusted, pinned environment if possible.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/batch_image.py:308
Finding

Output Path Traversal in the Rename Command

Content
View full analysis

Vulnerability Details

File Location: scripts/batch_image.py:308-317
Vulnerability Type: Path traversal and arbitrary file overwrite
Risk Level: Medium

python
      if date_format:
          try:
              mtime = datetime.fromtimestamp(f.stat().st_mtime)
              new_name = mtime.strftime(date_format) + f.suffix
          except:
              new_name = f"{prefix}{start + i - 1:04d}{f.suffix}"
      else:
          new_name = f"{prefix}{start + i - 1:04d}{f.suffix}"

      output_file = output_path / new_name
      img.save(output_file)

Technical Analysis

The user-controlled --prefix and --date-format arguments are incorporated into new_name without validating whether the resulting value is a safe filename. The code does not reject absolute paths, path separators, or parent-directory components such as ...

With pathlib, joining an output directory to an absolute path discards the original output directory. A relative name containing traversal components can similarly resolve outside the intended directory. The resulting path is passed directly to img.save(), which writes the processed image and can overwrite an existing file.

No canonical-path containment check is performed before the write. The broad exception handler around strftime() does not address this issue and may instead fall back to the equally unvalidated prefix.

Attack Path

  1. An attacker or untrusted caller supplies a crafted --prefix or --date-format.
  2. The supplied value produces an absolute filename or a filename containing parent-directory traversal components.
  3. The application joins that value to output_path without sanitization.
  4. The resulting destination resolves outside the configured output directory.
  5. img.save(output_file) creates or overwrites an image file at that destination.

Exploitation is limited by filesystem permissions, the existence of required parent ...[truncated 536 chars]

Remediation
View remediation

Remediation Suggestions

  • Treat generated names strictly as basenames and reject absolute paths.
  • Reject /, \, .., null characters, and platform-specific reserved filename patterns in --prefix and formatted date output.
  • Resolve the candidate destination and verify that it remains under the resolved output directory before writing.
  • Use a conservative filename allowlist, such as letters, digits, underscores, hyphens, and periods.
  • Refuse to overwrite existing files by default, or require an explicit overwrite option.
  • Replace broad exception handling with specific exceptions and report invalid date formats clearly.
  • Consider generating the final filename internally rather than treating formatting arguments as unrestricted path fragments.

A containment check should compare canonical paths, for example by resolving the output directory and candidate destination and then using relative_to() to confirm that the destination is a descendant of the output directory.

T08 · Insecure Dependencies

Note
Location
scripts/batch_image.py:12
Finding

Unpinned Third-Party Dependency Installation Guidance

Content
View full analysis

Vulnerability Details

File Location: scripts/batch_image.py:12-18
Vulnerability Type: Unpinned dependency installation
Risk Level: Low

python
try:
    from PIL import Image, ImageDraw, ImageFont, ImageEnhance
except ImportError:
    print("Please install Pillow: pip install Pillow")
    sys.exit(1)

Technical Analysis

When Pillow is unavailable, the script recommends installing it with pip install Pillow without specifying an audited version, package hash, or trusted package index. This causes pip to resolve whichever release is current at installation time, making installations non-reproducible and exposing users to future compromised or incompatible releases.

The reviewed project does not automatically execute the installation command, and the package name is the legitimate Pillow name rather than an apparent typo-squatted dependency. Exploitation therefore depends on a user following the displayed guidance and on compromise or unsafe behavior in the package source or resolved release.

Attack Path

  1. The script runs in an environment where Pillow is not installed.
  2. The import raises ImportError, and the script displays the unpinned installation command.
  3. A user executes pip install Pillow.
  4. Pip retrieves the currently resolved package version from its configured index without project-provided version or integrity constraints.
  5. A compromised, unexpectedly modified, or incompatible release executes installation or runtime code with the user's privileges.

Impact Assessment

The potential impact is equivalent to executing third-party package code under the privileges of the user performing the installation. In a compromised supply-chain scenario, this could affect files, credentials, and processes accessible to that account.

The practical risk is reduced because installation is manual, Pillow is a well-known package, and no evidence of an actively malicious depen ...[truncated 57 chars]

Remediation
View remediation

Remediation Suggestions

  • Declare Pillow in a project dependency file rather than relying on ad hoc installation instructions.
  • Pin Pillow to an audited, compatible version or constrained version range.
  • Use a lock file with cryptographic hashes for reproducible installations.
  • Document the expected trusted package index and discourage installation from untrusted mirrors.
  • Regularly review and update the pinned version to incorporate security patches.
  • Prefer installation in an isolated virtual environment with only the permissions required for image processing.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill describes destructive or output-altering batch operations such as rename, convert, compress, resize, and watermark without clearly warning that these actions can modify filenames, overwrite expectations, or create changed outputs for an entire directory. In an agent setting, a user may point to the wrong path or misunderstand defaults, leading to unintended bulk data alteration or loss of original organization.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code file contains natural-language descriptions and CLI help text that force a specific language/locale for users. Under the policy, locale constraints should either offer user opt-in/choice or be clearly justified as region-specific, neither of which is present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Multiple string literals shown to users, including installation guidance, errors, command descriptions, and progress output, are written only in Chinese. Because the file provides no option to select another language and no justification for a Chinese-only locale, this is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

SQP-3 applies to natural-language policy issues in all file types, including markdown. The file forces a specific language for the skill description and instructions, and there is no user opt-in, alternate language option, or justification that this skill is intentionally limited to a Chinese-speaking audience.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.