Back to skill

Security audit

P图

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward local image-editing skill with expected file I/O and no evidence of hidden access, persistence, or data exfiltration.

Install this in a virtual environment, avoid running installs as administrator/root, and choose output paths carefully when saving images. For stricter environments, pin Pillow to a reviewed version and use a lockfile or hashes.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Unpinned Third-Party Dependency Without Integrity Verification

Content
View full analysis
=10.0.0 ``` The documented installation command in `README.md:11-12` and `SKILL.md:55-56` is: ```bash pip install -r requirements.txt ``` ### Technical Analysis The project specifies only a minimum Pillow version. Consequently, each installation may resolve to a different future release that was not available or reviewed when this audit was performed. The project also provides no lock file or cryptographic hashes with which pip can verify that the exact reviewed distribution is installed. This does not establish that Pillow is currently malicious. The weakness is that dependency resolution remains mutable and does not guarantee reproducible or integrity-verified installation. If the upstream package, distribution channel, maintainer account, or a future release were compromised, users following the documented installation process could receive unreviewed code. ### Attack Path 1. An attacker compromises a permitted future Pillow release, its publication account, or the package distribution channel. 2. The attacker publishes a release satisfying `pillow>=10.0.0`. 3. A user runs the documented `pip install -r requirements.txt` command. 4. pip resolves the mutable dependency constraint to the compromised release without checking it against a project-supplied artifact hash. 5. Malicious package installation or runtime code executes in the environment where the Skill is installed or invoked. This path is conditional on compromise of the upstream supply chain; no evidence of such a compromise was identified in the audited project. ### Impact Assessment Successful exploitation could execute code with the privileges of the account performing install ...[truncated 413 chars]
Remediation
View remediation
``` 2. Generate and commit a reproducible dependency lock file containing cryptographic hashes. 3. Install dependencies with hash enforcement, such as: ```bash python -m pip install --require-hashes -r requirements.txt ``` 4. Obtain packages only from approved package indexes over authenticated TLS. 5. Review release notes and security advisories before updating the pinned version. 6. Perform dependency updates through a controlled process that includes automated vulnerability scanning and tests. 7. Install and run the Skill in a least-privileged virtual environment or container rather than as an administrator or root user. ]]>
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill documentation is entirely in Chinese, including installation and API usage guidance, with no indication that other languages are supported or that the Chinese-only presentation is a justified regional constraint. Under the language/locale policy, forcing a single language without opt-in can be a natural-language policy issue.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill centers invocation around the broad natural-language phrase "P一下图片," which is generic and likely to appear in ordinary conversation. Without explicit activation boundaries, the agent may invoke the skill unintentionally, causing unexpected file/image processing actions and reducing user control over tool use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description is presented entirely in Chinese and does not indicate that language selection is optional or that the skill is intentionally limited to a Chinese-language or region-specific audience. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This Python file contains user-facing natural-language descriptions entirely in Chinese in the module docstring, and there is no indication that language choice is optional or region-specific. Under the policy rule, forcing a specific language without user opt-in can be a locale-policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This markdown file documents the save_image operation and shows an example writing output.jpg, but it does not include any user-facing caution about filesystem effects such as creating or overwriting files. For a skill that affects user data on disk, a brief warning in the README would improve disclosure.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency is specified as pillow>=10.0.0, which allows any newer release to be installed and makes builds non-reproducible. This can unintentionally introduce vulnerable or breaking versions through future upstream releases or dependency confusion in the supply chain.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
pillow>=10.0.0

Unverifiable Dependency: pillow has 16 known advisory(ies) (CVE-2016-2533 (Pillow buffer overflow in ImagingPcdDecode); CVE-2023-50447 (Arbitrary Code Execution in Pillow); CVE-2021-27922 (Pillow Uncontrolled Resource Consumption) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
83% confidence
Finding

Pillow has a history of multiple security advisories, and because the manifest does not pin an exact version, it is not possible to verify whether the installed package will include fixes for known issues. While >=10.0.0 may exclude some older CVEs, the lack of exact version control still creates uncertainty and weakens supply-chain assurance.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.