Back to skill

Security audit

Face8 Celebrity Recognition

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says: it uploads photos to Face8 for celebrity recognition and clearly documents optional commands that can add or confirm faces in Face8's database.

Install only if you are comfortable sending selected photos and face data to Face8. Use the normal recognition command for lookup, and use --register or --confirm only when you intentionally want to change Face8's remote face database.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill is described as a celebrity recognition tool, but its documented behavior also includes registering unknown faces and confirming matches, which are write operations that modify a remote facial-recognition database. This creates a significant trust and privacy risk because users may invoke the skill expecting read-only identification while actually contributing biometric data and labels to a third-party service.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The script makes outbound HTTP requests to a third-party face recognition service, uploading local image contents and sending face tokens and confirmation data, but the finding indicates this network capability is not declared in permissions. Undeclared network access is dangerous because it can exfiltrate sensitive biometric data without clear user consent or sandbox policy coverage, especially in a skill whose inputs are user photos.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The module and function documentation present the script as a recognition utility, but the CLI includes remote write functionality through registration and confirmation endpoints. Misleading documentation reduces reviewer and user awareness of state-changing biometric operations, increasing the chance of unintended or unauthorized modification of the external face database.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script’s description, CLI help text, status messages, and output are all hard-coded in Traditional Chinese, with no option to select another language or indication that the tool is intentionally limited to a Chinese-speaking context. This is a natural-language policy concern because it imposes a specific locale on all users without opt-in.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The stated skill purpose is celebrity identification from an uploaded photo, but the code also supports registering new faces and confirming matches, which are write operations that modify the remote Face8 gallery. This mismatch is risky because users or reviewers may believe the tool is read-only while it can actually alter biometric records on a third-party service.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.