Back to skill

Security audit

Autoglm Image Recognition

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it says, but it uploads local files to a public third-party URL and uses local authentication without enough safeguards or scoping.

Review carefully before installing. Use this only for non-sensitive images you are comfortable sending to AutoGLM and potentially exposing through a public URL. Do not point the upload script at documents, credentials, private screenshots, regulated data, or arbitrary local files; the skill should add confirmation, image validation, size limits, private URLs, and secret handling before broad use.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
upload-mix.py:33
Finding

Unrestricted Local File Upload to Third-Party Storage

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
image-recognition.py:11
Finding

Hard-Coded Shared Application Signing Key

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented primarily as image recognition, but its workflow also instructs uploading arbitrary local files to an external service and relying on a local token service. That behavioral gap is security-relevant because users or agent operators may not realize the skill exfiltrates local content before analysis.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill explicitly requires uploading a local image to a remote service that returns a public URL, which is a direct data exfiltration path for user-provided local files. Because the URL is publicly accessible, the exposure is broader than normal third-party processing and can enable unauthorized access if the link leaks or is guessable.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The documented end-to-end workflow operationalizes exfiltration by directing the agent to take a local image, upload it externally, and then process the returned public link. In context, this makes the risk more dangerous because the unsafe transfer is not incidental; it is the prescribed default path for local files.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill performs network-relevant operations but does not declare any tool scope or allowed-tools boundary. In an agent setting, missing explicit permission boundaries increases the chance that the skill can invoke network actions without transparent review or policy enforcement.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instructions tell the agent to upload local images to obtain a publicly accessible URL, but they do not warn that this may expose private or sensitive image contents to third parties. This creates a meaningful privacy and consent risk, especially for personal photos, documents, screenshots, or regulated data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script silently retrieves an authorization token from a local service and then uses it to authenticate to an external API, without informing the user that local credentials are being accessed. This can violate user expectations and weakens transparency around credential use; if a malicious or compromised skill is executed in this environment, automatic token pickup could enable unauthorized use of local secrets.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script transmits user-provided image URLs and prompts to a third-party AutoGLM API, but it does not clearly disclose that user content is leaving the local environment. This creates a privacy and data-handling risk, especially because image URLs and prompts may contain sensitive internal resources, personal data, or confidential business information.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script hardcodes APP_ID and APP_KEY even though the skill is described as token-based, creating embedded long-lived credentials in distributable code. If these credentials are valid, anyone with access to the skill can reuse them against the remote API, enabling unauthorized use, abuse attribution to the owner, or credential harvesting; the mismatch between the manifest and implementation increases suspicion.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script sends the selected local file to an external API without any user-facing confirmation, preview, or warning about off-device transmission. Because this skill is meant to operate on user-supplied local images and may also be used on documents containing OCR-readable sensitive data, silent upload can lead to inadvertent disclosure of private or regulated information.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill is presented as image recognition, but the helper script uploads arbitrary local files to a remote service before analysis, which materially changes the trust boundary and data exposure risk. In this skill context, users may provide sensitive local images or documents expecting analysis, not realizing the content is transmitted externally, so the mismatch makes the behavior more dangerous than a purely local preprocessing step.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.