Back to skill

Security audit

Image Analyzer Advisor

Security checks for vulnerabilities and agentic risk

Overview

This is a simple image-analysis guidance skill with no executable code, persistence, credential use, or hidden behavior.

Before installing, be aware that the skill may activate for many image-related requests and may echo the image path or URL in its response; avoid using it with sensitive images or private file paths unless that context is intended to be shared in the conversation.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger description is very broad, covering many generic phrases about inspecting or understanding images, screenshots, charts, and URLs. This can cause the skill to activate in situations where a more specific or safer skill should handle the request, increasing the chance of unintended data exposure or incorrect tool use, though the skill itself does not contain overtly malicious behavior.

Static analysis

No suspicious patterns detected.