Back to skill

Security audit

While traveling, try recreating iconic scenes from classic movies in your photos!

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it advertises, but it automatically uses and exposes precise location details in ways users should review before installing.

Review this skill before installing if you are uncomfortable with automatic IP-based location lookup or having precise coordinates/address-like details echoed in the chat log. Prefer giving a coarse city manually, avoid sharing a home/work address, and use the installer only for the platform you intend to update.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose describes an end-user content skill focused on finding nearby filming locations and generating structured cinematic photography outputs. The supplied code does none of that. It is purely an installation utility: it detects supported assistant environments, computes install paths, creates directories, deletes any existing installation, and copies files into place. Those filesystem and platform-detection behaviors are undeclared and materially different from the described primary purpose. While an installer can be a supporting artifact for a skill package, this code chunk itself does not implement the advertised functionality at all, so the description does not accurately represent what the supplied code actually does.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to auto-detect the user's location via IP and collect precise coordinates to 6 decimal places, which can identify a very specific place. It does this without an upfront privacy notice, data-minimization rationale, or explicit opt-in before collection, creating a meaningful privacy and safety risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The logging section directs the system to record and display exact coordinates and user-confirmed place information in visible output. Exposing sensitive location data in logs increases the risk of inadvertent disclosure, retention, or secondary use beyond the user's expectation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README states that the skill auto-detects the user's city via IP geolocation and relies on external services, but it does not clearly warn that the user's IP-derived location data may be transmitted to third parties. In a location-centric skill, this omission matters because users may unknowingly expose approximate location and related metadata to external providers, creating privacy and consent risks.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger conditions are broad enough that the skill could activate on casual travel, photography, or movie-related requests without clear user intent to share location or receive geolocation-based processing. That raises consent and privacy risks because subsequent steps immediately move toward IP-based location detection and precise nearby recommendations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The instructions require storing the city name in 'Chinese + English' and mandate Chinese search queries alongside English ones. This imposes specific language behavior without offering the user a choice or explaining why those languages are required.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly requires presenting precise user location details in the model's output logs, making sensitive data part of the response surface. Even if intended for transparency, surfacing exact coordinates and confirmed locations can expose the user's whereabouts to anyone viewing or storing the conversation.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · install.sh (reported line 146)May include surrounding context.

sh
return 0
    fi

    # Create parent directory if needed
    mkdir -p "$(dirname "$install_path")"

    # Remove existing installation

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The README's 'Or naturally' section provides trigger phrases in Chinese and English only, which may imply a language constraint without clarifying whether other languages are supported. Because no user language-choice or explicit limitation is documented, this can create an avoidable locale-policy ambiguity in the natural-language interface.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.