Back to skill

Security audit

Image Editor

Security checks for vulnerabilities and agentic risk

Overview

This image-editing skill is mostly purpose-aligned, but it includes an unsafe command example that could let a malicious image path run local code if followed literally.

Review before installing. The skill should be safe to use only if agents treat image paths as data, validate they are expected local image files, and avoid literal string substitution into python3 -c snippets. The publisher should revise the command example to pass paths via argv or another structured channel.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:17
Finding

Unsafe Image Path Interpolation Enables Local Code Injection

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill description is broad enough to match many generic image-editing requests, which can cause the agent to invoke this skill in situations it was not specifically designed or constrained for. Overbroad routing increases the chance of inappropriate tool use, mishandling unsupported formats or workflows, and bypassing more suitable or safer skills.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Hard-coding a specific font choice, especially a language-specific system font, can produce incorrect or misleading edits when the original typography differs or the environment lacks that font. In an image-editing skill, this can cause integrity issues in the output and may alter meaning or reveal environment-specific assumptions rather than respecting user intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This JSON file contains natural-language prompts and expected outputs exclusively in Chinese, which implies a fixed language requirement for the skill's behavior. Under the policy rules, forcing a specific language without offering user choice or documenting a justified locale restriction is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.