Back to skill

Security audit

SVG Draw

Security checks for vulnerabilities and agentic risk

Overview

This skill provides SVG templates and a local SVG-to-PNG converter with no evidence of hidden access, persistence, or data exfiltration.

Installers should treat this as a local graphics helper. Use explicit workspace paths for generated SVG/PNG files, check before overwriting existing files, and only send generated images to external channels when the user asked for that.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The code chunk accurately implements the SVG-to-PNG conversion portion of the description, including use of system rsvg-convert and configurable output dimensions. However, it does not implement any capability to create or generate SVG images, custom illustrations, avatars, logos, or artwork. Because the declared purpose presents SVG creation as a core part of the skill, while the supplied code only performs format conversion, the description overstates the implemented functionality and is materially broader than the actual behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill instructs writing arbitrary output files and generating PNGs without any warning about overwriting existing paths. In an agentic environment, this can lead to unintended modification or loss of local files if unsafe or user-supplied paths are used.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The visible text content is fixed to Chinese ("大龙 🐉") with no indication that this asset is intended only for a Chinese-speaking locale or that users can choose another language. The policy requires flagging language or locale constraints when they are imposed without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This file contains the visible label "大龙虾 🦞", which forces a specific language presentation in the asset. The policy requires avoiding language-specific behavior unless the user is given a choice or the locale restriction is clearly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.