Back to skill

Security audit

TencentCloud Image Face Fusion

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to perform its stated Tencent Cloud face-fusion task, but it handles sensitive face images and cloud credentials with automatic execution, weak consent disclosure, and unpinned runtime dependency installation.

Review this carefully before installing. Only use it with images you are authorized to process, keep the AI-synthesis logo enabled unless you have a legitimate reason, and assume provided images are sent to Tencent Cloud. Use narrowly scoped Tencent credentials, avoid persisting secrets in shell startup files when possible, and install a pinned Tencent SDK in a controlled environment instead of allowing runtime pip installation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
scripts/main.py:10
Finding

Unpinned Automatic Dependency Installation at Runtime

Content
View full analysis

Vulnerability Details

File Location: scripts/main.py, lines 10–19
Vulnerability Type: Runtime installation of an unpinned third-party dependency
Risk Level: Medium

Vulnerable Code

python
def ensure_dependencies():
    try:
        import tencentcloud  # noqa: F401
    except ImportError:
        print("[INFO] tencentcloud-sdk-python not found. Installing...", file=sys.stderr)
        subprocess.check_call(
            [sys.executable, "-m", "pip", "install", "tencentcloud-sdk-python", "-q"],
            stdout=sys.stderr,
            stderr=sys.stderr,
        )
        print("[INFO] tencentcloud-sdk-python installed successfully.", file=sys.stderr)

Technical Analysis

The script automatically invokes pip when the Tencent Cloud SDK cannot be imported. The package name is not pinned to a reviewed version, and no cryptographic hash or lock file is used to verify the installed artifact.

Consequently, the effective code executed by the Skill can change after review as package indexes publish new releases or resolve different transitive dependencies. Python package installation may execute package-controlled build hooks, and imported package code subsequently executes in the Skill process.

Although the automatic installation behavior is disclosed in SKILL.md, it exceeds the minimum privileges needed during normal Skill execution. Dependency resolution and installation should occur in a controlled deployment phase rather than while processing user images and cloud credentials.

Attack Path

  1. The Skill runs in an environment where tencentcloud is unavailable or its import is made to fail.
  2. ensure_dependencies() invokes the environment's Python interpreter with -m pip install tencentcloud-sdk-python -q.
  3. pip resolves the latest package and its transitive dependencies from its configured package source without version or hash verification.
  4. A compromised upstream release, transitive dependency, configured pack ...[truncated 1103 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove automatic package installation from scripts/main.py. If the dependency is absent, terminate with a clear setup error.
  2. Install dependencies during a controlled build or deployment phase, before credentials or user images are made available.
  3. Pin the SDK and all transitive dependencies to reviewed versions in a lock file.
  4. Require cryptographic hashes during installation, such as:
    bash
    python -m pip install --require-hashes -r requirements.txt
    
  5. Use a trusted, explicitly configured package repository and prevent fallback to untrusted indexes.
  6. Build and scan an immutable virtual environment or container image, then run the Skill with package installation disabled.
  7. Run the Skill with a minimally privileged operating-system identity and narrowly scoped Tencent Cloud credentials.
  8. Regularly scan pinned dependencies for known vulnerabilities and update them through a reviewed release process.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (36)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The skill description materially overstates implemented functionality and omits the significant runtime behavior of automatically installing dependencies. This can mislead operators about what data processing, validation, and controls exist, while unexpected package installation introduces supply-chain and execution risk beyond the declared purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs the agent to perform face fusion automatically without obtaining user confirmation or checking for consent from depicted individuals. Because face images are highly sensitive biometric data and the operation enables deepfake-like manipulation, automatic execution raises serious privacy, impersonation, and abuse risks.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill declares shell and environment-variable dependent behavior but does not scope or constrain those capabilities with explicit permissions or allowed-tools metadata. In an agent ecosystem, this increases the chance that the agent can execute local commands or access secrets more broadly than intended, which is risky when the skill also contains imperative execution instructions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill presents remote result URLs and cloud-based processing but does not clearly warn that user-provided images are transmitted to an external Tencent cloud service. This undermines informed consent and may cause users to expose biometric or personal images without understanding where data is sent or stored.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

md
**参数说明**:

| 参数                   | 必选 | 说明                                                                                        |
| -------------------- | -- | ----------------------------------------------------------------------------------------- |
| `--model`            | 是  | 素材模板图片(URL 或本地文件路径)                                                                       |
| `--face`             | 是  | 用户人脸图片(URL 或本地文件路径)                                                                       |

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document describes uploading and processing face images via URL/base64 and returning synthesized face images, which involves biometric and highly sensitive personal data. It does not mention consent, lawful basis, retention, third-party disclosure, or misuse risks, and the same API also supports disabling or replacing the AI-generated watermark, which increases the risk of deceptive or unauthorized face synthesis.

Content

No source excerpt is available for this finding.

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · references/FuseFaceUltraApi.md (reported line 14)May include surrounding context.

md
## 输入参数

| 参数名称           | 必选 | 类型               | 描述                                                                                                                                                                                                                                                                                                                                              |
| ---------------- | ---- | ------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Action           | 是   | String             | 公共参数,本接口取值:FuseFaceUltra。                                                                                                                                                                                                                                                                                                                     |
| Version          | 是   | String             | 公共参数,本接口取值:2022-09-27。                                                                                                                                                                                                                                                                                                                        |

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · references/FuseFaceUltraApi.md (reported line 16)May include surrounding context.

md
## 输入参数

| 参数名称           | 必选 | 类型               | 描述                                                                                                                                                                                                                                                                                                                                              |
| ---------------- | ---- | ------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Action           | 是   | String             | 公共参数,本接口取值:FuseFaceUltra。                                                                                                                                                                                                                                                                                                                     |
| Version          | 是   | String             | 公共参数,本接口取值:2022-09-27。                                                                                                                                                                                                                                                                                                                        |

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · references/FuseFaceUltraApi.md (reported line 17)May include surrounding context.

md
## 输入参数

| 参数名称           | 必选 | 类型               | 描述                                                                                                                                                                                                                                                                                                                                              |
| ---------------- | ---- | ------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Action           | 是   | String             | 公共参数,本接口取值:FuseFaceUltra。                                                                                                                                                                                                                                                                                                                     |
| Version          | 是   | String             | 公共参数,本接口取值:2022-09-27。                                                                                                                                                                                                                                                                                                                        |

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · references/FuseFaceUltraApi.md (reported line 18)May include surrounding context.

md
## 输入参数

| 参数名称           | 必选 | 类型               | 描述                                                                                                                                                                                                                                                                                                                                              |
| ---------------- | ---- | ------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Action           | 是   | String             | 公共参数,本接口取值:FuseFaceUltra。                                                                                                                                                                                                                                                                                                                     |
| Version          | 是   | String             | 公共参数,本接口取值:2022-09-27。                                                                                                                                                                                                                                                                                                                        |

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · references/FuseFaceUltraApi.md (reported line 19)May include surrounding context.

md
## 输入参数

| 参数名称           | 必选 | 类型               | 描述                                                                                                                                                                                                                                                                                                                                              |
| ---------------- | ---- | ------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Action           | 是   | String             | 公共参数,本接口取值:FuseFaceUltra。                                                                                                                                                                                                                                                                                                                     |
| Version          | 是   | String             | 公共参数,本接口取值:2022-09-27。                                                                                                                                                                                                                                                                                                                        |

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · references/FuseFaceUltraApi.md (reported line 23)May include surrounding context.

md
## 输入参数

| 参数名称           | 必选 | 类型               | 描述                                                                                                                                                                                                                                                                                                                                              |
| ---------------- | ---- | ------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Action           | 是   | String             | 公共参数,本接口取值:FuseFaceUltra。                                                                                                                                                                                                                                                                                                                     |
| Version          | 是   | String             | 公共参数,本接口取值:2022-09-27。                                                                                                                                                                                                                                                                                                                        |

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · references/FuseFaceUltraApi.md (reported line 25)May include surrounding context.

md
## 输入参数

| 参数名称           | 必选 | 类型               | 描述                                                                                                                                                                                                                                                                                                                                              |
| ---------------- | ---- | ------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Action           | 是   | String             | 公共参数,本接口取值:FuseFaceUltra。                                                                                                                                                                                                                                                                                                                     |
| Version          | 是   | String             | 公共参数,本接口取值:2022-09-27。                                                                                                                                                                                                                                                                                                                        |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/FuseFaceUltraApi.md (reported line 14)May include surrounding context.

md
## 输入参数

| 参数名称           | 必选 | 类型               | 描述                                                                                                                                                                                                                                                                                                                                              |
| ---------------- | ---- | ------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Action           | 是   | String             | 公共参数,本接口取值:FuseFaceUltra。                                                                                                                                                                                                                                                                                                                     |
| Version          | 是   | String             | 公共参数,本接口取值:2022-09-27。                                                                                                                                                                                                                                                                                                                        |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/FuseFaceUltraApi.md (reported line 16)May include surrounding context.

md
| 参数名称           | 必选 | 类型               | 描述                                                                                                                                                                                                                                                                                                                                              |
| ---------------- | ---- | ------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Action           | 是   | String             | 公共参数,本接口取值:FuseFaceUltra。                                                                                                                                                                                                                                                                                                                     |
| Version          | 是   | String             | 公共参数,本接口取值:2022-09-27。                                                                                                                                                                                                                                                                                                                        |
| Region           | 是   | String             | 公共参数,详见产品支持的地域列表。                                                                                                                                                                                                                                                                                                                           |
| RspImgType       | 否   | String             | 返回融合结果图片方式(url 或 base64),二选一。url
...[truncated 25 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/FuseFaceUltraApi.md (reported line 17)May include surrounding context.

md
| 参数名称           | 必选 | 类型               | 描述                                                                                                                                                                                                                                                                                                                                              |
| ---------------- | ---- | ------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Action           | 是   | String             | 公共参数,本接口取值:FuseFaceUltra。                                                                                                                                                                                                                                                                                                                     |
| Version          | 是   | String             | 公共参数,本接口取值:2022-09-27。                                                                                                                                                                                                                                                                                                                        |
| Region           | 是   | String             | 公共参数,详见产品支持的地域列表。                                                                                                                                                                                                                                                                                                                           |
| RspImgType       | 否   | String             | 返回融合结果图片方式(url 或 base64),二选一。url
...[truncated 25 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/FuseFaceUltraApi.md (reported line 18)May include surrounding context.

md
| ---------------- | ---- | ------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Action           | 是   | String             | 公共参数,本接口取值:FuseFaceUltra。                                                                                                                                                                                                                                                                                                                     |
| Version          | 是   | String             | 公共参数,本接口取值:2022-09-27。                                                                                                                                                                                                                                                                                                                        |
| Region           | 是   | String             | 公共参数,详见产品支持的地域列表。                                                                                                                                                                                                                                                                                                                           |
| RspImgType       | 否   | String             | 返回融合结果图片方式(url 或 base64),二选一。url有效期为1天。                                                                                                                                                                                                                                                                                                        |
| MergeInfos       | 否   | Array of MergeInfo | 用户人脸图片、素材模板图的人脸位置信息。主要用于素材模版
...[truncated 25 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/FuseFaceUltraApi.md (reported line 19)May include surrounding context.

md
| Action           | 是   | String             | 公共参数,本接口取值:FuseFaceUltra。                                                                                                                                                                                                                                                                                                                     |
| Version          | 是   | String             | 公共参数,本接口取值:2022-09-27。                                                                                                                                                                                                                                                                                                                        |
| Region           | 是   | String             | 公共参数,详见产品支持的地域列表。                                                                                                                                                                                                                                                                                                                           |
| RspImgType       | 否   | String             | 返回融合结果图片方式(url 或 base64),二选一。url有效期为1天。                                                                                                                                                                                                                                                                                                        |
| MergeInfos       | 否   | Array of MergeInfo | 用户人脸图片、素材模板图的人脸位置信息。主要用于素材模版中人脸以及用作融合的用户人脸相关信息,两种人脸都需要提供人脸图片,可选择提供人脸框位置。目前最多支持融合模板图片中的6张人脸。                                                                                                                                                                                                                                                  |
| ModelUrl         | 否   | String             | 素材模版图片的url地址。base64 和 url 必须提供一个,如
...[truncated 25 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/FuseFaceUltraApi.md (reported line 20)May include surrounding context.

md
| Version          | 是   | String             | 公共参数,本接口取值:2022-09-27。                                                                                                                                                                                                                                                                                                                        |
| Region           | 是   | String             | 公共参数,详见产品支持的地域列表。                                                                                                                                                                                                                                                                                                                           |
| RspImgType       | 否   | String             | 返回融合结果图片方式(url 或 base64),二选一。url有效期为1天。                                                                                                                                                                                                                                                                                                        |
| MergeInfos       | 否   | Array of MergeInfo | 用户人脸图片、素材模板图的人脸位置信息。主要用于素材模版中人脸以及用作融合的用户人脸相关信息,两种人脸都需要提供人脸图片,可选择提供人脸框位置。目前最多支持融合模板图片中的6张人脸。                                                                                                                                                                                                                                                  |
| ModelUrl         | 否   | String             | 素材模版图片的url地址。base64 和 url 必须提供一个,如果都提供以 url 为准。图片分辨率限制:图片中面部尺寸大于34×34;图片尺寸大于64×64,小于8000×8000(单边限制)。图片大小限制:base64 编码后大小不可超过10M,url不超过20M。图片格式:支持jpg或png。                                                                                                                                                                                       |
| ModelImage       | 否   | String             | 素材模版图片base64数据。base64 和 url 必须提供一
...[truncated 25 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/FuseFaceUltraApi.md (reported line 21)May include surrounding context.

md
| Region           | 是   | String             | 公共参数,详见产品支持的地域列表。                                                                                                                                                                                                                                                                                                                           |
| RspImgType       | 否   | String             | 返回融合结果图片方式(url 或 base64),二选一。url有效期为1天。                                                                                                                                                                                                                                                                                                        |
| MergeInfos       | 否   | Array of MergeInfo | 用户人脸图片、素材模板图的人脸位置信息。主要用于素材模版中人脸以及用作融合的用户人脸相关信息,两种人脸都需要提供人脸图片,可选择提供人脸框位置。目前最多支持融合模板图片中的6张人脸。                                                                                                                                                                                                                                                  |
| ModelUrl         | 否   | String             | 素材模版图片的url地址。base64 和 url 必须提供一个,如果都提供以 url 为准。图片分辨率限制:图片中面部尺寸大于34×34;图片尺寸大于64×64,小于8000×8000(单边限制)。图片大小限制:base64 编码后大小不可超过10M,url不超过20M。图片格式:支持jpg或png。                                                                                                                                                                                       |
| ModelImage       | 否   | String             | 素材模版图片base64数据。base64 和 url 必须提供一个,如果都提供以 url 为准。素材图片限制:图片中面部尺寸大于34×34;图片尺寸大于64×64,小于8000×8000(单边限制)。图片大小限制:base64 编码后大小不可超过10M,url不超过20M。支持图片格式:支持jpg或png。                                                                                                                                                                                  |
| FusionUltraParam | 否   | FusionUltraParam   | 图片人脸融合(专业版)效果参数。可用于设置拉脸、人脸增强、磨皮、牙齿
...[truncated 25 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/FuseFaceUltraApi.md (reported line 22)May include surrounding context.

md
| RspImgType       | 否   | String             | 返回融合结果图片方式(url 或 base64),二选一。url有效期为1天。                                                                                                                                                                                                                                                                                                        |
| MergeInfos       | 否   | Array of MergeInfo | 用户人脸图片、素材模板图的人脸位置信息。主要用于素材模版中人脸以及用作融合的用户人脸相关信息,两种人脸都需要提供人脸图片,可选择提供人脸框位置。目前最多支持融合模板图片中的6张人脸。                                                                                                                                                                                                                                                  |
| ModelUrl         | 否   | String             | 素材模版图片的url地址。base64 和 url 必须提供一个,如果都提供以 url 为准。图片分辨率限制:图片中面部尺寸大于34×34;图片尺寸大于64×64,小于8000×8000(单边限制)。图片大小限制:base64 编码后大小不可超过10M,url不超过20M。图片格式:支持jpg或png。                                                                                                                                                                                       |
| ModelImage       | 否   | String             | 素材模版图片base64数据。base64 和 url 必须提供一个,如果都提供以 url 为准。素材图片限制:图片中面部尺寸大于34×34;图片尺寸大于64×64,小于8000×8000(单边限制)。图片大小限制:base64 编码后大小不可超过10M,url不超过20M。支持图片格式:支持jpg或png。                                                                                                                                                                                  |
| FusionUltraParam | 否   | FusionUltraParam   | 图片人脸融合(专业版)效果参数。可用于设置拉脸、人脸增强、磨皮、牙齿增强、妆容迁移等融合效果参数,生成理想的融合效果。不传默认使用接口推荐值。                                                                                                                                                                                                                                                                        |
| LogoAdd          | 否   | Integer            | 为融合结果图添加合成标识的开关,默认为1。1:添加标识。0:不
...[truncated 25 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/FuseFaceUltraApi.md (reported line 23)May include surrounding context.

md
| MergeInfos       | 否   | Array of MergeInfo | 用户人脸图片、素材模板图的人脸位置信息。主要用于素材模版中人脸以及用作融合的用户人脸相关信息,两种人脸都需要提供人脸图片,可选择提供人脸框位置。目前最多支持融合模板图片中的6张人脸。                                                                                                                                                                                                                                                  |
| ModelUrl         | 否   | String             | 素材模版图片的url地址。base64 和 url 必须提供一个,如果都提供以 url 为准。图片分辨率限制:图片中面部尺寸大于34×34;图片尺寸大于64×64,小于8000×8000(单边限制)。图片大小限制:base64 编码后大小不可超过10M,url不超过20M。图片格式:支持jpg或png。                                                                                                                                                                                       |
| ModelImage       | 否   | String             | 素材模版图片base64数据。base64 和 url 必须提供一个,如果都提供以 url 为准。素材图片限制:图片中面部尺寸大于34×34;图片尺寸大于64×64,小于8000×8000(单边限制)。图片大小限制:base64 编码后大小不可超过10M,url不超过20M。支持图片格式:支持jpg或png。                                                                                                                                                                                  |
| FusionUltraParam | 否   | FusionUltraParam   | 图片人脸融合(专业版)效果参数。可用于设置拉脸、人脸增强、磨皮、牙齿增强、妆容迁移等融合效果参数,生成理想的融合效果。不传默认使用接口推荐值。                                                                                                                                                                                                                                                                        |
| LogoAdd          | 否   | Integer            | 为融合结果图添加合成标识的开关,默认为1。1:添加标识。0:不添加标识。其他数值:默认按1处理。建议您使用显著标识来提示结果图使用了人脸融合技术,是AI合成的图片。                                                                                                                                                                                                                                                              |
| LogoParam        | 否   | LogoParam          | 标识内容设置。默认在融合结果图右下角添加"本图片为AI合成图
...[truncated 25 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/FuseFaceUltraApi.md (reported line 24)May include surrounding context.

md
| ModelUrl         | 否   | String             | 素材模版图片的url地址。base64 和 url 必须提供一个,如果都提供以 url 为准。图片分辨率限制:图片中面部尺寸大于34×34;图片尺寸大于64×64,小于8000×8000(单边限制)。图片大小限制:base64 编码后大小不可超过10M,url不超过20M。图片格式:支持jpg或png。                                                                                                                                                                                       |
| ModelImage       | 否   | String             | 素材模版图片base64数据。base64 和 url 必须提供一个,如果都提供以 url 为准。素材图片限制:图片中面部尺寸大于34×34;图片尺寸大于64×64,小于8000×8000(单边限制)。图片大小限制:base64 编码后大小不可超过10M,url不超过20M。支持图片格式:支持jpg或png。                                                                                                                                                                                  |
| FusionUltraParam | 否   | FusionUltraParam   | 图片人脸融合(专业版)效果参数。可用于设置拉脸、人脸增强、磨皮、牙齿增强、妆容迁移等融合效果参数,生成理想的融合效果。不传默认使用接口推荐值。                                                                                                                                                                                                                                                                        |
| LogoAdd          | 否   | Integer            | 为融合结果图添加合成标识的开关,默认为1。1:添加标识。0:不添加标识。其他数值:默认按1处理。建议您使用显著标识来提示结果图使用了人脸融合技术,是AI合成的图片。                                                                                                                                                                                                                                                              |
| LogoParam        | 否   | LogoParam          | 标识内容设置。默认在融合结果图右下角添加"本图片为AI合成图片"字样,您可根据自身需要替换为其他的Logo图片。                                                                                                                                                                                                                                                                                         |
| SwapModelType    | 否   | Integer            | 融合模型类型参数:默认为1。1:默认泛娱乐场景,画面
...[truncated 25 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/FuseFaceUltraApi.md (reported line 25)May include surrounding context.

md
| ModelImage       | 否   | String             | 素材模版图片base64数据。base64 和 url 必须提供一个,如果都提供以 url 为准。素材图片限制:图片中面部尺寸大于34×34;图片尺寸大于64×64,小于8000×8000(单边限制)。图片大小限制:base64 编码后大小不可超过10M,url不超过20M。支持图片格式:支持jpg或png。                                                                                                                                                                                  |
| FusionUltraParam | 否   | FusionUltraParam   | 图片人脸融合(专业版)效果参数。可用于设置拉脸、人脸增强、磨皮、牙齿增强、妆容迁移等融合效果参数,生成理想的融合效果。不传默认使用接口推荐值。                                                                                                                                                                                                                                                                        |
| LogoAdd          | 否   | Integer            | 为融合结果图添加合成标识的开关,默认为1。1:添加标识。0:不添加标识。其他数值:默认按1处理。建议您使用显著标识来提示结果图使用了人脸融合技术,是AI合成的图片。                                                                                                                                                                                                                                                              |
| LogoParam        | 否   | LogoParam          | 标识内容设置。默认在融合结果图右下角添加"本图片为AI合成图片"字样,您可根据自身需要替换为其他的Logo图片。                                                                                                                                                                                                                                                                                         |
| SwapModelType    | 否   | Integer            | 融合模型类型参数:默认为1。1:默认泛娱乐场景,画面偏锐。2:影视级场景,画面偏自然。3:影视级场景,高分辨率,画面偏自然。4:影视级场景,高分辨率,高人脸相似度,画面偏自然,可用于证件照等场景。5:影视级场景,高分辨率,对闭眼和遮挡更友好。6:影视级场景,高分辨率,极高人脸相似度,可用于电商照片、证件照、文旅照片等场景。                                                                                                                                                     |

### MergeInfo 结构

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/FuseFaceUltraApi.md (reported line 26)May include surrounding context.

md
| FusionUltraParam | 否   | FusionUltraParam   | 图片人脸融合(专业版)效果参数。可用于设置拉脸、人脸增强、磨皮、牙齿增强、妆容迁移等融合效果参数,生成理想的融合效果。不传默认使用接口推荐值。                                                                                                                                                                                                                                                                        |
| LogoAdd          | 否   | Integer            | 为融合结果图添加合成标识的开关,默认为1。1:添加标识。0:不添加标识。其他数值:默认按1处理。建议您使用显著标识来提示结果图使用了人脸融合技术,是AI合成的图片。                                                                                                                                                                                                                                                              |
| LogoParam        | 否   | LogoParam          | 标识内容设置。默认在融合结果图右下角添加"本图片为AI合成图片"字样,您可根据自身需要替换为其他的Logo图片。                                                                                                                                                                                                                                                                                         |
| SwapModelType    | 否   | Integer            | 融合模型类型参数:默认为1。1:默认泛娱乐场景,画面偏锐。2:影视级场景,画面偏自然。3:影视级场景,高分辨率,画面偏自然。4:影视级场景,高分辨率,高人脸相似度,画面偏自然,可用于证件照等场景。5:影视级场景,高分辨率,对闭眼和遮挡更友好。6:影视级场景,高分辨率,极高人脸相似度,可用于电商照片、证件照、文旅照片等场景。                                                                                                                                                     |

### MergeInfo 结构

Static analysis

No suspicious patterns detected.