Back to skill

Security audit

E-commerce Board Graphics

Security checks for vulnerabilities and agentic risk

Overview

This is a local image-processing skill that reads product image files and writes generated graphics, with no evidence of hidden network access, credential use, persistence, or destructive behavior.

Before installing or running it, review the default Windows paths and provide explicit input/output arguments so it processes only the intended product image folders and writes results where you expect. It is suitable for local graphics generation, but it is not a polished, fully portable package.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding

声明描述的是一个较完整的UV荧光板产品图处理技能包,包含多项图像处理能力和两类输出(A5包边板子、紫光灯效果图)。但提供的代码只实现了其中一小部分:A5板子生成中的“内包边”和“横竖版自适应”。脚本通过PIL读取PNG,判断横竖版,缩放到固定尺寸,并叠加边框图层保存。没有任何PSD解析逻辑、抠图逻辑、紫光灯效果/发光特效处理,也没有宣传册排版相关流程。因此描述明显高于实际行为,属于能力与主要产出不一致的情况。代码未表现出额外越权或可疑资源访问,问题主要是声明功能远多于实际实现。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The README presents the skill entirely as a Chinese-language workflow and frames the deliverable in Chinese without stating that language is configurable or user-selected. Under the policy, forcing a specific language or locale without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The markdown states '命名:全部英文', which imposes a language policy on outputs. This is a natural-language locale/language constraint, and the file does not indicate user opt-in or a region/compliance justification for forcing English naming.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module docstring, usage text, and operational labels are written in Chinese, which imposes a specific language on users without any visible opt-in or alternate locale support. This matches the policy category for language/locale constraints because the file does not indicate that the skill is region-specific or provide a user-selectable language option.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The module docstring includes Chinese-language guidance ('用户要求直接读取最上方图层') alongside English, which creates a language-specific instruction path without any user opt-in or documented locale constraint. Under the policy, forcing or assuming a specific language can be a natural-language policy issue when no choice is offered.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code file performs a file write by saving generated images to a hard-coded destination, but there is no confirmation prompt or prior disclosure before the write occurs. Because file writes are in scope for missing user warnings, this should be disclosed or gated, even though it appears limited to a local test path.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This code file performs a file write via combo.save(...) but provides no prior comment, docstring detail, or user-facing warning that an output image will be created at a fixed path. Under the code-file criteria, file writes are safety-relevant when they lack any disclosure at all.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.