Back to skill

Security audit

TencentCloud FaceID DetectAIFakeFaces

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Tencent Cloud face anti-fraud API wrapper, but it handles sensitive face images or videos and users should treat use of it as third-party biometric processing.

Install only if you intend to send the selected face images or videos to Tencent Cloud for analysis, have proper consent or legal basis for biometric processing, and can provide narrowly scoped Tencent Cloud credentials. Prefer installing the SDK in an isolated environment with a pinned, reviewed dependency version.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:41
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 41
Vulnerability Type: Unpinned package installation without integrity verification
Risk Level: Medium

Vulnerable Code Snippet:

bash
pip install tencentcloud-sdk-python

Technical Analysis

The documented installation command retrieves the currently available version of tencentcloud-sdk-python without an exact version constraint, cryptographic hash verification, or a dependency lockfile. Consequently, the code installed by users can differ from the version originally reviewed.

This creates a supply-chain risk if the package, one of its transitive dependencies, a package-index account, or the distribution channel is compromised. Malicious package code could execute during installation or when scripts/main.py imports the Tencent Cloud SDK. The audit found no evidence that the package name itself is typosquatted or currently malicious; the finding concerns the absence of reproducible and integrity-verified dependency controls.

Attack Path

  1. An attacker compromises the package publisher, package-index account, release pipeline, or a transitive dependency.
  2. The attacker publishes a malicious release under a version accepted by the unrestricted installation command.
  3. A user follows the Skill documentation and runs pip install tencentcloud-sdk-python.
  4. The package manager downloads and installs the attacker-controlled release.
  5. Malicious code executes during package installation or when scripts/main.py imports the SDK.
  6. That code can access data available to the Python process, potentially including Tencent Cloud credentials, submitted facial media, accessible local files, and network resources.

Impact Assessment

Exploitation would run code with the privileges of the user or service account installing or invoking the Skill. Potential impact includes theft of TENCENTCLOUD_SECRET_ID and TENCENTCLOUD_SECRET_KEY, una ...[truncated 450 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin tencentcloud-sdk-python to an exact, reviewed version rather than installing the latest available release.
  2. Record direct and transitive dependencies in a lockfile or hash-locked requirements file.
  3. Require cryptographic hash verification during installation, for example with pip install --require-hashes -r requirements.txt.
  4. Generate hashes only from packages obtained through the official, trusted package index and verify the package publisher and release provenance.
  5. Periodically review and deliberately update the pinned version after security testing instead of accepting upgrades automatically.
  6. Install and execute the Skill in an isolated virtual environment or container under a minimally privileged service account.
  7. Limit the associated Tencent Cloud credentials to only the API permissions required for DetectAIFakeFaces, and avoid exposing unrelated secrets to the process.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill handles highly sensitive biometric data but does not explicitly warn that local face images/videos or Base64 payloads will be transmitted to Tencent Cloud for remote processing. Because users may assume local-only handling, this omission undermines informed consent and increases privacy, compliance, and data-governance risk when processing personal information such as facial imagery.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill requires access to sensitive environment variables containing Tencent Cloud API credentials, but it does not declare an explicit tool scope or permissions boundary. This can lead to overbroad execution in hosting agents, reduce auditability, and make it easier for the skill to access secrets without clear user or platform visibility.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger conditions are broad enough to activate the skill for nearly any face anti-fraud or image/video detection request, which can cause unintended invocation on sensitive biometric data. In this context, over-triggering increases the chance that face images or videos are processed or transmitted when the user did not explicitly intend to use Tencent Cloud or external biometric analysis.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script transmits highly sensitive biometric data (face images/videos) to Tencent Cloud for analysis, but it does not present an explicit runtime warning or consent notice about remote transmission, retention, or privacy implications. In a skill handling biometric content, this omission can cause users to unknowingly exfiltrate sensitive personal data to a third party, creating privacy, compliance, and trust risks even though the API call itself is expected functionality.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language strings in the docstring and user-facing CLI messages are entirely in Chinese, which imposes a specific language/locale on users. There is no indication that the skill is region-specific or that users can opt into another language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.