Back to skill

Security audit

photo-alchemy

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent photo-art tool, but its install and automation instructions give broad local execution and persistence with insufficient safety controls.

Review this carefully before installing. Avoid the curl-to-sh installer, prefer a pinned and verifiable package version, use least-privilege photo albums, consider environment variables or a platform credential store instead of saving keys to the app database, and only enable launchd scheduling if you understand how to inspect, unload, and remove the LaunchAgent and accept recurring API usage and photo uploads.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:34
Finding

Unverified Remote Installer Is Executed Directly by the Shell

Content
View full analysis
Remediation
View remediation

T06 · System Persistence

Warning
Location
SKILL.md:118
Finding

Optional Feature Creates a Persistent macOS LaunchAgent

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:29
Finding

Unpinned Third-Party Package Is Resolved and Executed

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:41
Finding

API Credentials Are Persisted in an Application SQLite Database Without Documented Protection

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The documentation instructs users to fetch and execute a remote shell script via curl ... | sh, which gives the remote server immediate code-execution capability on the user's machine. If the hosting domain, network path, or script content is compromised, users can be silently infected with arbitrary malware or have secrets exfiltrated.

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

Permanent install

bash
curl -LsSf uvx.sh/imagemine/install.sh | sh

API Key Setup

Chaining Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

Piping downloaded content directly into sh removes any opportunity for inspection and turns any upstream compromise into immediate command execution. In a skill that also asks for API keys and integrates with local photos, this becomes more dangerous because a malicious installer could steal credentials, access personal media, or establish persistence.

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

Permanent install

bash
curl -LsSf uvx.sh/imagemine/install.sh | sh

API Key Setup

Rp1

Medium
Category
MCP Rug Pull
Confidence
65% confidence
Finding

uvx/uv tool run commands without ==version create a rug-pull risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill processes user photos, extracts face/name metadata from Apple Photos, sends image-derived content to external AI providers, and stores run metadata locally, but the description does not present this privacy impact prominently up front. That omission can cause users to expose sensitive personal data, including identities and photo contents, without informed consent.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 126)May include surrounding context.

  1. Schedule via launchd (runs every N minutes):
bash
imagemine --launchd 30
# Writes ~/Library/LaunchAgents/imagemine.plist and prints the launchctl command
launchctl load ~/Library/LaunchAgents/imagemine.plist

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 127)May include surrounding context.

  1. Schedule via launchd (runs every N minutes):
bash
imagemine --launchd 30
# Writes ~/Library/LaunchAgents/imagemine.plist and prints the launchctl command
launchctl load ~/Library/LaunchAgents/imagemine.plist

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 127)May include surrounding context.

bash
imagemine --launchd 30
# Writes ~/Library/LaunchAgents/imagemine.plist and prints the launchctl command
launchctl load ~/Library/LaunchAgents/imagemine.plist
  1. On Apple TV: Photos app → Shared Albums → select your output album → Set as Screen Saver

Static analysis

No suspicious patterns detected.