Back to skill

Security audit

Design Studio V101

Security checks for vulnerabilities and agentic risk

Overview

This is a local design-asset skill with no hidden network, credential, persistence, or prompt-hijacking behavior, though users should be careful with output paths because one pipeline script uses predictable temporary filenames.

Install only if you are comfortable with a local graphics skill that reads selected images or CSV files and writes generated assets. Choose a fresh output directory for pipeline runs to avoid collisions with files named like *_draft.png or *_improved_1.png, and expect several script messages and help text to be in Russian.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/design_pipeline.py:354
Finding

Predictable Temporary File Names Permit Unintended File Overwrite and Deletion

Content
View full analysis

Vulnerability Details

File Location: scripts/design_pipeline.py:215, scripts/design_pipeline.py:272, and scripts/design_pipeline.py:354-372
Vulnerability Type: Predictable and unsafe temporary-file handling
Risk Level: Medium

Vulnerable Code

python
def автоулучшение(путь, детали, итерация=1):
    """
    Автоматическое улучшение на основе слабых метрик.
    Возвращает путь к улучшенному файлу.
    """
    print(f"\n  Итерация улучшения #{итерация}")
    tmp = путь.replace(".png", f"_improved_{итерация}.png")
python
# Промежуточный файл
tmp_output = output.replace(".png", "_draft.png")
python
# Сохраняем финальный результат
from PIL import Image as PILImage
final = PILImage.open(текущий)
output_dir = os.path.dirname(output)
if output_dir:
    os.makedirs(output_dir, exist_ok=True)
final.save(output, "PNG", quality=95)

# Очистка промежуточных файлов
for f in [tmp_output] + [
    output.replace(".png", f"_improved_{i}.png") for i in range(1, макс_итераций + 1)
]:
    if f != output and os.path.exists(f):
        try:
            os.remove(f)
        except Exception:
            pass

Technical Analysis

The pipeline constructs temporary file names deterministically by applying string replacement to the caller-controlled output path. It does not use exclusive temporary-file creation, verify whether a derived path existed before the current run, or maintain an authoritative list of files created by the current invocation.

For example, an output path named report.png produces predictable sibling paths such as:

  • report_draft.png
  • report_improved_1.png
  • report_improved_2.png
  • report_improved_3.png

If any of those files already exist, image-generation or improvement operations can overwrite them. The cleanup loop subsequently deletes every matching predictable path that exists, regardless of whether the current p ...[truncated 1766 chars]

Remediation
View remediation

Remediation Suggestions

  1. Use tempfile.TemporaryDirectory() to place all intermediate files in a unique, isolated directory created for the current invocation.
  2. Alternatively, use tempfile.NamedTemporaryFile() or tempfile.mkstemp() with exclusive creation rather than deriving temporary paths from the final output name.
  3. Maintain an explicit collection of temporary paths successfully created by the current process. Cleanup must operate only on that collection.
  4. Never delete a path merely because it matches a predictable naming pattern.
  5. Construct paths with pathlib.Path and inspect suffixes with .suffix or generate names with .with_name() instead of using unrestricted string replacement.
  6. Write the final image to a unique temporary file in the destination directory and publish it with os.replace() only after successful generation. This provides atomic finalization while avoiding partially written output.
  7. Reject or explicitly confirm overwriting when the requested final output already exists.
  8. Replace broad exception suppression with specific exception handling and visible error reporting or logging.
  9. Where symlink-based attacks are relevant, validate that output and temporary paths are regular files under an approved directory and use secure open semantics supported by the target platform.

A safer structure is:

python
from pathlib import Path
from tempfile import TemporaryDirectory
import os

destination = Path(output).resolve()
destination.parent.mkdir(parents=True, exist_ok=True)

with TemporaryDirectory(
    prefix=".design-pipeline-",
    dir=destination.parent,
) as temp_directory:
    temp_root = Path(temp_directory)
    draft_path = temp_root / "draft.png"
    improved_paths = [
        temp_root / f"improved_{index}.png"
        for index in range(1, max_iterations + 1)
    ]

    # Generate and process only within temp_root.
    # After successful completion:
 
...[truncated 141 chars]
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (46)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents a comprehensive design studio with asset creation, editing, batch processing, and branding-support features. The supplied code does only one narrow task: analyze an existing image and rate its design quality using simple image heuristics. While 'check design quality' is one item mentioned in the description, the overall declared purpose substantially overstates the skill’s functionality and primary behavior. There is no evidence of generating designs, adding watermarks, processing CSV batches, selecting fonts, or creating GIFs/mockups/logos. Therefore the description does not accurately represent what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The description broadly advertises a full-featured design studio with numerous asset types and utility features. The supplied code chunk is narrower: it supports only three task types (cover, banner, avatar), runs image-quality analysis, and performs iterative auto-improvement using basic PIL-based adjustments. While some declared functions are partially represented (creating covers/banners/avatars and checking design quality), several prominently declared capabilities are absent from this code chunk, including logos, mockups, portfolios, GIF creation, watermarking, CSV batch generation, and palette/font recommendation. Therefore the description overstates what this code actually does, making it a meaningful description-to-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents a full-featured design studio with many different content-generation and design-assistance capabilities. The supplied code implements only one narrow function: generating professional avatar images containing initials. It supports palettes, gradients, decoration, font selection, and PNG export, which aligns with the 'avatars' portion of the description, but none of the other major advertised functions are implemented in this chunk. There is no evidence of banner/cover/logo/mockup/portfolio/GIF creation, quality analysis, watermarking, CSV batch processing, or recommendation features. Therefore the description materially overstates and misrepresents what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a full-featured design studio covering multiple design asset types and auxiliary functions. The supplied code only implements banner generation: it renders text onto an image with predefined palettes, font loading, size presets, and simple decorative graphics, then saves a PNG. This is aligned with one narrow subset of the description ('banners'), but the overall declared purpose substantially overstates the implemented functionality. There are no suspicious undeclared security-sensitive behaviors or external data access beyond invoking fc-match to locate installed fonts, but the primary capability scope is materially narrower than advertised.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The code accurately fits one narrow slice of the description: generating covers for freelance marketplaces. However, the declared purpose describes a much broader design studio with many creation and analysis features. This script only accepts marketplace, title, subtitle, style, and output path, then renders a static PNG cover at predefined dimensions. It does not create logos, avatars, mockups, portfolios, GIFs, or generic social media banners; it does not read CSV files for batch generation; it does not add watermarks; and it does not perform design quality review beyond an internal contrast check used during rendering. The primary purpose is therefore substantially narrower than declared, making the description materially inaccurate.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code only implements SVG asset generation: it creates a predefined set of minimal vector elements (icons, badges, shapes, frames) and saves them locally. While this could support a design workflow, it does not provide the broad design-studio capabilities claimed in the description, such as creating marketplace covers, social banners, avatars, logos, mockups, GIFs, QA checks, watermarking, CSV-driven batch cover generation, or palette/font recommendations. The actual primary purpose is materially narrower and different from the declared one.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The description claims a full-featured professional design studio with many design-generation and evaluation capabilities. The supplied code only implements one specific function: generating static device mockups from a single input image using Pillow. It does not include tools for creating banners, logos, avatars, portfolios, GIFs, watermarks, design QA, CSV batch processing, or palette/font recommendation. While 'mockups' are mentioned in the description, the declared purpose materially overstates the skill’s functionality and primary scope compared with the actual code.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill advertises and instructs use of shell commands, file reads, and file writes, but it does not declare any explicit tool scope such as permissions or allowed-tools. In an agent environment, this increases the risk of overbroad tool access and accidental execution of filesystem or shell operations beyond what is necessary for design tasks.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The module docstring and all user-facing CLI/help/output strings are written in Russian, indicating the skill is effectively fixed to a specific language. Under the policy, locale-specific behavior should either offer user opt-in/choice or be clearly justified as region-specific, which is not present here.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The module docstring is entirely in Russian, and all user-facing CLI output and argument descriptions in this file are also Russian-only. This imposes a specific language on users without offering any language choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code file contains natural-language instructions, descriptions, and output text exclusively in Russian. Under the policy, forcing a specific language without an explicit user choice or documented locale justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/design_utils.py (reported line 13)May include surrounding context.

python
"""Найти шрифт через fc-match."""
    style = f"{name}:Bold" if bold else name
    try:
        result = subprocess.run(
            ['fc-match', '--format=%{file}', style],
            capture_output=True, text=True, timeout=5
        )

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language strings such as the module docstring and CLI help text entirely in Russian, which effectively forces a specific language on users. The policy allows locale constraints only when user choice or clear justification is provided, neither of which appears here.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/generate_avatar.py (reported line 40)May include surrounding context.

python
"""Ищет шрифт в системе."""
    стиль = "Bold" if bold else "Regular"
    try:
        result = subprocess.run(
            ["fc-match", "--format=%{file}", f"{имя}:style={стиль}"],
            capture_output=True, text=True, timeout=5,
        )

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/generate_banner.py (reported line 100)May include surrounding context.

python
"""Ищет шрифт в системе."""
    стиль = "Bold" if bold else "Regular"
    try:
        result = subprocess.run(
            ["fc-match", "--format=%{file}", f"{имя}:style={стиль}"],
            capture_output=True, text=True, timeout=5,
        )

Static analysis

No suspicious patterns detected.