Back to skill

Security audit

vision-skill

Security checks for vulnerabilities and agentic risk

Overview

This vision skill mostly does what it says, but it has real review-worthy privacy and local-file safety issues around cloud image retention and task file access.

Install only if you are comfortable sending selected local images, prompts, and results to Tencent COS and Doubao/Volcengine. Use a private COS bucket with lifecycle deletion, avoid sensitive documents unless retention is acceptable, run it in a restricted environment, and do not expose the status command to untrusted input until task IDs are validated.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/cos_client.py:151
Finding

Uploaded images use non-expiring COS object URLs and are not deleted

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/task_utils.py:103
Finding

Unvalidated task IDs allow path traversal and arbitrary JSON file disclosure

Content
View full analysis
/../../path/to/target.json ``` 4. The operating system resolves the traversal outside `.tasks`. 5. If the target exists, is valid JSON, and is readable by the Skill ...[truncated 562 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/task_utils.py:129
Finding

Sensitive task parameters and model results are stored with implicit filesystem permissions

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Third-party dependencies are installed without version or integrity constraints

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/vision_cli.py:173
Finding

Generated-image downloader accepts untrusted URLs without network or resource limits

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (37)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 70)May include surrounding context.

复制配置文件并填入密钥:

bash
cp .env.example .env

在 .env 中填入你的腾讯云和豆包 API 密钥:

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This code chunk’s actual purpose is cloud object storage interaction: uploading files to Tencent COS, constructing public URLs, and checking whether objects exist. While COS storage is mentioned in the description, the core declared functionality centers on computer vision and image generation tasks, which are entirely absent here. There is also no asynchronous workflow management or any usage of Doubao AI models. Therefore, the supplied code materially under-implements and does not accurately represent the declared skill purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The code broadly matches part of the description: it does perform visual recognition-style requests and image generation via Doubao models, including text-to-image and image-to-image style inputs. However, important declared elements are not implemented in this chunk. There is no Tencent COS storage support, no asynchronous task execution/orchestration, and no concrete OCR or object detection logic beyond sending a generic multimodal prompt to a vision model. Because the description specifically claims async execution with Tencent COS storage and enumerates OCR/object detection capabilities, the supplied code only partially fulfills the declared purpose and materially overstates implemented functionality.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Using shell=True for process management unnecessarily exposes shell execution semantics in a tool that already handles user-driven tasks and external resources. In this skill context, which orchestrates background jobs and remote downloads, reducing command-execution surface is important because future code changes or hostile runtime environments could turn this into a command-execution vector.

Content

Scanner excerpt · scripts/vision_cli.py (reported line 61)May include surrounding context.

python
# grep -v grep 排除自身,wc -l 统计行数
        # 注意:这只是一个简易的软限制,不够精确但能防止瞬间炸机
        cmd = "ps -ef | grep worker.py | grep -v grep | wc -l"
        result = subprocess.check_output(cmd, shell=True)
        count = int(result.strip())
        
        MAX_CONCURRENT_WORKERS = 5

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/vision_cli.py (reported line 74)May include surrounding context.

python
except:
        pass

    env = os.environ.copy()
    env['PYTHONPATH'] = SCRIPT_DIR + os.pathsep + env.get('PYTHONPATH', '')
    
    subprocess.Popen(

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/vision_cli.py (reported line 186)May include surrounding context.

python
for image_path in args.image_path:
        if not os.path.exists(image_path) and not image_path.startswith(('http://', 'https://')):
            print(json.dumps({"error": f"图片文件不存在或无效URL: {image_path}"}))
            return

    prompt = args.prompt
    if args.format and args.format in FORMAT_PRESETS:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explicitly advertises automatic upload of local images to Tencent COS, but the introduction and usage guidance do not provide a prominent, upfront warning that user-provided files will be transmitted to third-party cloud services. In a vision skill, inputs commonly contain sensitive documents, screenshots, or personal data, so this omission increases the risk of unintended data disclosure and privacy/compliance violations.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises operations that inherently require sensitive capabilities—environment access for secrets, local file reads/writes, network egress, and shell execution via the CLI—but it does not declare any tool scope or permission boundaries. In an agent setting, this weakens least-privilege controls and makes it easier for the skill to access or exfiltrate local images, prompts, credentials, or generated outputs beyond what a user may expect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill states that local images are uploaded to Tencent COS and prompts/images are sent to external AI services, but it does not present a prominent user warning about this data transfer. In this context, users may supply screenshots, invoices, contracts, or other sensitive documents, so undisclosed cloud upload creates privacy, compliance, and data exfiltration risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The code uploads arbitrary local files to Tencent COS using configured cloud credentials and returns a directly accessible URL, but it provides no consent boundary, allowlist, or privacy warning. In an agent skill context, this creates a real data exfiltration risk if untrusted workflow inputs can influence which local file is uploaded.

Content

No source excerpt is available for this finding.

Cloud Storage Exfiltration

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This is the concrete sink where a local file is transmitted to remote cloud storage. Because the function accepts a caller-supplied local path and constructs a retrievable URL, it can be abused by surrounding agent logic to exfiltrate sensitive local files, especially in a vision skill that may process user-provided paths or intermediate files.

Content

Scanner excerpt · scripts/cos_client.py (reported line 110)May include surrounding context.

python
upload_params['ContentType'] = content_type
            
            # 使用高级上传接口
            response = self.client.upload_file(**upload_params)
            
            # 构造访问URL
            url = self._build_url(remote_key)

Cloud Storage Exfiltration

Medium
Category
Data Exfiltration
Confidence
55% confidence
Finding

Data is uploaded to cloud storage (S3 / GCS / Azure Blob). This may be a legitimate backup or exfiltration to an external bucket. Manual review is recommended.

Content

Scanner excerpt · scripts/cos_client.py (reported line 194)May include surrounding context.

python
if len(sys.argv) > 1:
            test_file = sys.argv[1]
            cos_client = COSClient()
            result = cos_client.upload_file(test_file)
            print(result)
        else:
            print("Usage: python3 cos_client.py <file_path>")

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/doubao_client.py (reported line 109)May include surrounding context.

python
try:
            self.logger.info(f"开始视觉识别: {image_url}")
            response = requests.post(url, headers=headers, json=payload, timeout=60)
            response.raise_for_status()
            return response.json()
        except Exception as e:

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/doubao_client.py (reported line 166)May include surrounding context.

python
try:
            self.logger.info(f"开始视觉识别: {image_url}")
            response = requests.post(url, headers=headers, json=payload, timeout=60)
            response.raise_for_status()
            return response.json()
        except Exception as e:

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/doubao_client.py (reported line 184)May include surrounding context.

python
try:
            self.logger.info(f"开始视觉识别: {image_url}")
            response = requests.post(url, headers=headers, json=payload, timeout=60)
            response.raise_for_status()
            return response.json()
        except Exception as e:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code posts user-supplied image URLs and text prompts to an external service using requests.post. While there is logging for operation start/failure, the code does not include any disclosure that user content will be transmitted off-system, and that behavior is not otherwise explained in a user-facing warning within this file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The generate_image method sends prompts and possibly reference image URLs to a third-party endpoint for image generation. Although the action is logged, there is no user disclosure in comments/docstrings or prompts warning that potentially sensitive content will leave the local environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code performs file deletions in clean_old_tasks and file writes in save_task, but there is no confirmation prompt or user-facing logging when these safety-relevant filesystem operations occur. The Chinese docstrings/comments describe behavior for developers, but they do not clearly disclose to end users that task data may be automatically persisted and later deleted.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This file embeds natural-language descriptions and prompt presets in Chinese, including user-visible defaults for recognition behavior. Because the skill does not offer language selection or clearly justify a Chinese-only locale requirement, it creates a language policy concern for users who did not opt into that locale.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
88% confidence
Finding

The code invokes subprocess.check_output with shell=True, which is inherently riskier because it executes through a shell and can be influenced by shell semantics or environment manipulation. Although the command string is currently static, this pattern expands attack surface and can become exploitable if any part of the command later becomes user-controlled or if PATH/shell environment is compromised.

Content

Scanner excerpt · scripts/vision_cli.py (reported line 61)May include surrounding context.

python
# grep -v grep 排除自身,wc -l 统计行数
        # 注意:这只是一个简易的软限制,不够精确但能防止瞬间炸机
        cmd = "ps -ef | grep worker.py | grep -v grep | wc -l"
        result = subprocess.check_output(cmd, shell=True)
        count = int(result.strip())
        
        MAX_CONCURRENT_WORKERS = 5

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/vision_cli.py (reported line 77)May include surrounding context.

python
env = os.environ.copy()
    env['PYTHONPATH'] = SCRIPT_DIR + os.pathsep + env.get('PYTHONPATH', '')
    
    subprocess.Popen(
        [sys.executable, WORKER_SCRIPT, task_id],
        env=env,
        stdout=subprocess.DEVNULL,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill writes recognition output directly to the user-specified output path, which affects local filesystem state and may overwrite existing files. The code announces success after writing, but does not provide advance disclosure, confirmation, or overwrite protection for this safety-relevant operation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code saves downloaded content directly to the path supplied by the user, which modifies local files and can overwrite existing data. Although there is a post-action print confirming where the file was saved, there is no pre-action warning, confirmation, or descriptive disclosure near the write operation about the file-write side effect.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file's docstring and multiple user-facing prompt strings are written to require Chinese output/instructions, such as quality suffixes and default prompts. This appears to impose a specific language/locale without any opt-in or documented justification, which violates the language-choice policy.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code uploads local image paths to COS and later passes the resulting URLs to vision/generation APIs, which transmits user-provided data off the local system. Although there is internal logging, there is no confirmation prompt or clear user-facing disclosure in the file warning that local images will be uploaded to remote services.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.