Back to skill

Security audit

Picture

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward local image-processing skill with a normal Pillow dependency and no evidence of hidden network access, persistence, credential use, or deceptive behavior.

Install and run this in a normal least-privileged environment, be careful not to save over files you want to keep, and consider pinning Pillow to a reviewed version if you need reproducible or higher-assurance installs.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unpinned Pillow Dependency Permits Unreviewed Future Releases

Content
View full analysis
=10.0.0 ``` `README.md:11-13`: ```bash pip install -r requirements.txt ``` `SKILL.md:59-63`: ```markdown ### Installation ```bash pip install -r requirements.txt ``` ``` ### Technical Analysis The dependency specification establishes only a minimum Pillow version and does not set an upper bound, pin an audited release, or verify package hashes. Consequently, identical installation commands can resolve to different Pillow releases over time. This creates a supply-chain risk because a future eligible release is trusted automatically without corresponding review of the Skill. If an eligible package release or the associated package-distribution infrastructure is compromised, the documented installation procedure could install attacker-controlled code. Python package installation can execute build-related code, while malicious runtime code can execute when the dependency is imported. This finding does not establish that the current Pillow package is malicious. The vulnerability is the absence of reproducible version and integrity controls. ### Attack Path 1. An attacker compromises an eligible future Pillow release, its publishing credentials, or a relevant package-distribution channel. 2. The attacker publishes a malicious version satisfying `pillow>=10.0.0`. 3. A user follows the documented command: ```bash pip install -r requirements.txt ``` 4. The package resolver selects the malicious or compromised release because no exact version or hash is required. 5. Attacker-controlled code executes during package installation, build processing, or later when the project imports Pillow. 6. The payload operates with the permissions of the acco ...[truncated 677 chars]
Remediation
View remediation
``` 2. Generate and commit a deterministic lock file containing cryptographic hashes. For example: ```bash pip-compile --generate-hashes requirements.in ``` 3. Require hash verification during installation: ```bash pip install --require-hashes -r requirements.txt ``` 4. Update dependencies through a controlled process that includes security advisory review, compatibility testing, and explicit approval before changing the pinned version. 5. Perform dependency installation and image processing in an isolated, least-privileged environment without unnecessary credentials or filesystem access. 6. Add automated dependency scanning and monitoring for Pillow security advisories while retaining manual review before upgrades. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The natural-language content of the skill documentation is effectively fixed to Chinese, and there is no opt-in, alternative language, or justification that this is a region-specific skill. Under SQP-3, forcing a specific language without user choice is a policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill is framed around a very broad, colloquial trigger concept ("P一下图片" / picture editing) that could match common user requests in many contexts. Overly broad activation increases the chance the skill is invoked unintentionally, causing capability hijacking or routing image-related requests to this skill when the user did not explicitly ask for it.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This markdown file documents save_image(..., output_path, ...) as writing an image to disk, but it does not include any caution about selecting an output path carefully or potential overwriting of existing files. For markdown files, SQP-2 applies when descriptions omit warnings about behaviors that can affect user data or system integrity.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The documentation states that the skill will automatically detect and use a system Chinese font, which implies locale-specific behavior without explicit user choice. This can produce unexpected output, inconsistent rendering across systems, or override user expectations about language/font selection, especially in multilingual environments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module docstring presents the skill description entirely in Chinese and does not indicate that language is configurable or limited to a justified region-specific context. This can violate language/locale policy when users are not given an explicit choice or opt-in.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
96% confidence
Finding

The dependency is specified as pillow>=10.0.0, which permits installation of many different future versions and does not guarantee a known, reviewed build. This weakens reproducibility and can allow vulnerable or incompatible releases to be pulled in later through normal installs, creating supply-chain risk.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
pillow>=10.0.0

Unverifiable Dependency: pillow has 16 known advisory(ies) (CVE-2016-2533 (Pillow buffer overflow in ImagingPcdDecode); CVE-2023-50447 (Arbitrary Code Execution in Pillow); CVE-2021-27922 (Pillow Uncontrolled Resource Consumption) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
88% confidence
Finding

Pillow has a history of security advisories, and because the manifest does not pin an exact version, it is impossible to verify from this file alone whether deployments will receive a patched release. The risk is contextual: if the skill processes untrusted images, a vulnerable Pillow version could expose the system to denial of service or potentially code-execution issues documented in past advisories.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.