Back to skill

Security audit

算力超市skills

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed helper for a user-configured compute-marketplace API, with sensitive media and social actions bounded by user direction and confirmations.

Install only if you trust the configured 算力超市 tenant and API key scope. Use social-media and watermark features only for content you own or are authorized to process, and confirm local media uploads only when you are comfortable sending that file to the tenant API.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
The bundled references include watermark-removal and social-media scraping/search APIs that materially exceed the skill’s stated tenant-scoped 算力超市 workflow purpose. In an agent setting, exposing these capabilities expands the action surface to copyright/attribution removal and bulk content harvesting, which can be misused through prompt steering or accidental invocation.

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
Including general-purpose account, pricing, and temporary file-upload APIs broadens the skill beyond its declared operation categories and gives the agent auxiliary capabilities that can be chained for unintended data movement or reconnaissance. Temporary upload endpoints in particular can be abused to exfiltrate user-provided files or stage content for downstream tools if not tightly scoped.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill explicitly supports resolving social-media and public share URLs via `watermark_removal/*` and related social lookup flows, but it does not warn that submitting third-party links may expose personal data, metadata, or content to the tenant platform and downstream processors. In an orchestration skill that automates media retrieval and transformation, the absence of a privacy notice increases the risk of users processing content they do not own or inadvertently disclosing sensitive URLs and identifiers.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.