Back to skill

Security audit

Thumbnail QA

Security checks for vulnerabilities and agentic risk

Overview

This skill is purpose-built for thumbnail QA, but it can automatically edit project files and create git commits with limited confirmation.

Install only if you want an agent to inspect your Next.js image usage, run browser-based checks, edit object-position classes, and create git commits. Review the working tree before and after running it, and ask the agent to show proposed edits before committing if you do not want automatic repository history changes.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The changelog advertises that the skill will automatically modify source files and create git commits, but it does not indicate any explicit confirmation, dry-run mode, or warning that repository state will be changed. In an agentic workflow, unattended code edits and commits can cause unintended changes, pollute history, or commit sensitive or broken content, especially if triggered proactively after image uploads.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README states that the skill will auto-fix thumbnails and make each fix its own atomic commit, but it does not present a prominent warning or explicit consent flow for repository modifications. In this context, the skill also runs proactively after image uploads, which increases the chance of unexpected edits and commit creation without the user's informed approval.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises broad natural-language triggers such as "Check my thumbnails" and "Fix image cropping," which can overlap with ordinary user requests and cause the skill to activate in contexts where the user did not intend repository-wide scanning, screenshotting, or code modification. This is more dangerous here because the skill is not read-only: it can start services, analyze local assets, change code, and create commits automatically.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger guidance is broad enough to proactively invoke the skill after routine image additions or replacements in /public, which can cause the agent to launch a high-impact workflow without a narrowly scoped user request. Because this skill performs browsing, file edits, and git commits, over-broad invocation increases the chance of unintended repository changes from ordinary asset updates.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs the agent to modify repository state by creating commits automatically, including a commit to change .gitignore during setup and per-image atomic commits later. Even if intended as normal workflow automation, automatic VCS writes can persist unintended changes, clutter history, or commit sensitive or incorrect edits without explicit user approval.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.