Back to skill

Security audit

Seisoai

Security checks for vulnerabilities and agentic risk

Overview

This media-generation gateway is coherent but needs review because it includes face swap and voice-clone tools without consent or anti-impersonation safeguards.

Review this skill before installing if you may use it with real people’s images, video, or voices. Use it only with media you have rights and consent to process, and add your own refusal or confirmation step for face swap, voice cloning, lip sync, and motion-transfer requests. API-key and x402 payment use are disclosed and expected, but keep credentials scoped and monitor billable calls.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill explicitly exposes high-risk impersonation capabilities such as `image.face-swap` and voice-clone TTS (`audio.tts`) but provides no user-facing safety warning, consent requirement, or policy guardrails around identity misuse, privacy, or non-consensual media generation. In an agent context, that omission increases the chance these tools are used for deceptive deepfakes, harassment, or privacy violations because the documentation normalizes direct invocation without any abuse-prevention guidance.

Static analysis

No suspicious patterns detected.