Back to skill

Security audit

TencentCloud YT Segment Portrait

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to perform Tencent Cloud portrait segmentation as advertised, but it automatically uploads potentially sensitive images and installs an unpinned dependency at runtime.

Review before installing. Use this only if you are comfortable sending portrait images or image URLs to Tencent Cloud, and run it with narrowly scoped Tencent credentials. Prefer installing a pinned, reviewed Tencent SDK outside the skill instead of allowing runtime pip installation, and avoid storing long-lived cloud secrets in shell startup files when possible.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
scripts/main.py:10
Finding

Unpinned Automatic Dependency Installation at Runtime

Content
View full analysis

Vulnerability Details

File Location: scripts/main.py, lines 10–18
Vulnerability Type: Unpinned runtime dependency installation
Risk Level: Medium

Vulnerable Code:

python
def ensure_dependencies():
    try:
        import tencentcloud  # noqa: F401
    except ImportError:
        print("[INFO] tencentcloud-sdk-python not found. Installing...", file=sys.stderr)
        subprocess.check_call(
            [sys.executable, "-m", "pip", "install", "tencentcloud-sdk-python", "-q"],
            stdout=sys.stderr,
            stderr=sys.stderr,
        )

Technical Analysis

If the Tencent Cloud SDK cannot be imported, the script automatically invokes pip to install the latest package resolved under the name tencentcloud-sdk-python. The installation uses no exact version pin, package hash verification, lockfile, trusted repository restriction, or explicit user approval.

This makes the effective code executed by the Skill mutable after review. A compromised package release, malicious package-index mirror, or attacker-controlled Python package configuration could cause arbitrary installation or import-time code to run under the invoking user's identity. The dependency also executes in a process that can access the environment variables used for Tencent Cloud authentication.

Although the command uses a fixed argument list and does not introduce shell injection, unattended installation of an unverified dependency exceeds the minimum privileges needed for portrait segmentation. Dependency provisioning should occur through a controlled deployment process rather than during ordinary Skill execution.

Attack Path

  1. The Tencent Cloud SDK is absent from the runtime environment, causing the ImportError branch to execute.
  2. An attacker compromises a future package release or influences package resolution through a malicious or compromised package index or mirror.
  3. The script invokes `py ...[truncated 1401 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove automatic package installation from main.py. If the SDK is unavailable, terminate safely with a concise dependency error.
  2. Declare dependencies outside runtime code in a reviewed requirements or lock file.
  3. Pin the Tencent SDK to an exact, tested version rather than an open-ended package name.
  4. Record and verify package hashes, for example by installing from a hash-locked requirements file with:
    bash
    python -m pip install --require-hashes -r requirements.txt
    
  5. Restrict installation to an approved package index and a controlled build or deployment stage.
  6. Build and scan an immutable virtual environment or container before executing the Skill.
  7. Run the Skill as a minimally privileged account and use Tencent credentials restricted to only the API operations and resources required for portrait segmentation.
  8. Treat dependency installation failure as an operational error rather than silently modifying the environment.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (25)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

A documented portrait-segmentation skill whose implementation/interface behavior reportedly includes audio/ASR-style handling is a trust-boundary problem: users and agents may pass the wrong data types or misinterpret what the script does. Such mismatch can hide unsafe code paths, weaken reviewability, and make accidental data processing or unexpected network/file handling more likely.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill's prompts, help text, variable names, and error messages describe audio/ASR inputs, but the implementation actually uploads image data to Tencent Cloud portrait-segmentation APIs. This mismatch can mislead users and reviewers about what data is being handled, causing accidental disclosure of images under false expectations and undermining informed consent.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill declares executable behavior involving shell and environment-variable access but does not define any tool/permission scope. That creates an over-broad execution model where an agent may invoke code or read secrets without explicit least-privilege boundaries, increasing the chance of unintended command execution or secret exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs the agent to automatically send user-provided images to Tencent Cloud without requiring confirmation, while not clearly disclosing the privacy consequences of external transmission. Because images may contain faces and other sensitive biometric/personal data, silent upload to a third party creates a meaningful privacy and compliance risk.

Content

No source excerpt is available for this finding.

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · references/SegmentPortraitPicApi.md (reported line 14)May include surrounding context.

md
## 输入参数

| 参数名称       | 必选  | 类型     | 描述                                                                                                                                                                                                                                                                    |
| ---------- | --- | ------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Action     | 是   | String | [公共参数](https://cloud.tencent.com/document/api/1208/42965),本接口取值:SegmentPortraitPic。                                                                                                                                                                                   |
| Version    | 是   | String | [公共参数](https://cloud.tencent.com/document/api/1208/42965),本接口取值:2020-03-24。                                                                                                                                                                                           |

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · references/SegmentPortraitPicApi.md (reported line 26)May include surrounding context.

md
## 输入参数

| 参数名称       | 必选  | 类型     | 描述                                                                                                                                                                                                                                                                    |
| ---------- | --- | ------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Action     | 是   | String | [公共参数](https://cloud.tencent.com/document/api/1208/42965),本接口取值:SegmentPortraitPic。                                                                                                                                                                                   |
| Version    | 是   | String | [公共参数](https://cloud.tencent.com/document/api/1208/42965),本接口取值:2020-03-24。                                                                                                                                                                                           |

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · references/SegmentPortraitPicApi.md (reported line 30)May include surrounding context.

md
## 输入参数

| 参数名称       | 必选  | 类型     | 描述                                                                                                                                                                                                                                                                    |
| ---------- | --- | ------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Action     | 是   | String | [公共参数](https://cloud.tencent.com/document/api/1208/42965),本接口取值:SegmentPortraitPic。                                                                                                                                                                                   |
| Version    | 是   | String | [公共参数](https://cloud.tencent.com/document/api/1208/42965),本接口取值:2020-03-24。                                                                                                                                                                                           |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/SegmentPortraitPicApi.md (reported line 14)May include surrounding context.

md
## 输入参数

| 参数名称       | 必选  | 类型     | 描述                                                                                                                                                                                                                                                                    |
| ---------- | --- | ------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Action     | 是   | String | [公共参数](https://cloud.tencent.com/document/api/1208/42965),本接口取值:SegmentPortraitPic。                                                                                                                                                                                   |
| Version    | 是   | String | [公共参数](https://cloud.tencent.com/document/api/1208/42965),本接口取值:2020-03-24。                                                                                                                                                                                           |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/SegmentPortraitPicApi.md (reported line 16)May include surrounding context.

md
| 参数名称       | 必选  | 类型     | 描述                                                                                                                                                                                                                                                                    |
| ---------- | --- | ------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Action     | 是   | String | [公共参数](https://cloud.tencent.com/document/api/1208/42965),本接口取值:SegmentPortraitPic。                                                                                                                                                                                   |
| Version    | 是   | String | [公共参数](https://cloud.tencent.com/document/api/1208/42965),本接口取值:2020-03-24。                                                                                                                                                                                           |
| Region     | 是   | String | [公共参数](https://cloud.tencent.com/document/api/1208/42965),详见产品支持的 [地域列表](https://cloud.tencent.com/document/api/1208/42965#.E5.9C.B0.E5.9F.9F.E5.88.97.E8.A1.A8)。                                                                                                     |
| Image      | 否   | String | 图片 base64 数据,base64 编码后大小不可超过5M。<br>图片分辨率须小于2000*2000。<br>支持PNG、JPG、JPEG、BMP,不支持 GIF 图片。<br>示例值:/9j/4AAQSkZJRgABAQAAAQABAAD/4gIo...lftXF/DjFZNXoSP5V2U0HMt/1FQf/Z                                                                                                     |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/SegmentPortraitPicApi.md (reported line 17)May include surrounding context.

md
| 参数名称       | 必选  | 类型     | 描述                                                                                                                                                                                                                                                                    |
| ---------- | --- | ------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Action     | 是   | String | [公共参数](https://cloud.tencent.com/document/api/1208/42965),本接口取值:SegmentPortraitPic。                                                                                                                                                                                   |
| Version    | 是   | String | [公共参数](https://cloud.tencent.com/document/api/1208/42965),本接口取值:2020-03-24。                                                                                                                                                                                           |
| Region     | 是   | String | [公共参数](https://cloud.tencent.com/document/api/1208/42965),详见产品支持的 [地域列表](https://cloud.tencent.com/document/api/1208/42965#.E5.9C.B0.E5.9F.9F.E5.88.97.E8.A1.A8)。                                                                                                     |
| Image      | 否   | String | 图片 base64 数据,base64 编码后大小不可超过5M。<br>图片分辨率须小于2000*2000。<br>支持PNG、JPG、JPEG、BMP,不支持 GIF 图片。<br>示例值:/9j/4AAQSkZJRgABAQAAAQABAAD/4gIo...lftXF/DjFZNXoSP5V2U0HMt/1FQf/Z                                                                                                     |
| Url        | 否   | String | 图片的 Url 。<br>Url、Image必须提供一个,如果都提供,只使用 Url。<br>图片分辨率须小于2000*2000 ,图片 base64 编码后大小不可超过5M。<br>图片存储于腾讯云的Url可保障更高下载速度和稳定性,建议图片存储于腾讯云。<br>非腾讯云存储的Url速度和稳定性可能受一定影响。<br>支持PNG、JPG、JPEG、BMP,不支持 GIF 图片。<br>示例值:https:/
...[truncated 24 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/SegmentPortraitPicApi.md (reported line 18)May include surrounding context.

md
| ---------- | --- | ------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Action     | 是   | String | [公共参数](https://cloud.tencent.com/document/api/1208/42965),本接口取值:SegmentPortraitPic。                                                                                                                                                                                   |
| Version    | 是   | String | [公共参数](https://cloud.tencent.com/document/api/1208/42965),本接口取值:2020-03-24。                                                                                                                                                                                           |
| Region     | 是   | String | [公共参数](https://cloud.tencent.com/document/api/1208/42965),详见产品支持的 [地域列表](https://cloud.tencent.com/document/api/1208/42965#.E5.9C.B0.E5.9F.9F.E5.88.97.E8.A1.A8)。                                                                                                     |
| Image      | 否   | String | 图片 base64 数据,base64 编码后大小不可超过5M。<br>图片分辨率须小于2000*2000。<br>支持PNG、JPG、JPEG、BMP,不支持 GIF 图片。<br>示例值:/9j/4AAQSkZJRgABAQAAAQABAAD/4gIo...lftXF/DjFZNXoSP5V2U0HMt/1FQf/Z                                                                                                     |
| Url        | 否   | String | 图片的 Url 。<br>Url、Image必须提供一个,如果都提供,只使用 Url。<br>图片分辨率须小于2000*2000 ,图片 base64 编码后大小不可超过5M。<br>图片存储于腾讯云的Url可保障更高下载速度和稳定性,建议图片存储于腾讯云。<br>非腾讯云存储的Url速度和稳定性可能受一定影响。<br>支持PNG、JPG、JPEG、BMP,不支持 GIF 图片。<br>示例值:https://liudehua-9527.cos.ap-guangzhou.myqcloud.com/input.jpeg |
| RspImgType | 否   | String | 返回图像方式(base64 或 Url ) ,二选一。url有效期为30分钟。<br>示例值:url                                                                                                                                                            
...[truncated 24 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/SegmentPortraitPicApi.md (reported line 19)May include surrounding context.

md
| ---------- | --- | ------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Action     | 是   | String | [公共参数](https://cloud.tencent.com/document/api/1208/42965),本接口取值:SegmentPortraitPic。                                                                                                                                                                                   |
| Version    | 是   | String | [公共参数](https://cloud.tencent.com/document/api/1208/42965),本接口取值:2020-03-24。                                                                                                                                                                                           |
| Region     | 是   | String | [公共参数](https://cloud.tencent.com/document/api/1208/42965),详见产品支持的 [地域列表](https://cloud.tencent.com/document/api/1208/42965#.E5.9C.B0.E5.9F.9F.E5.88.97.E8.A1.A8)。                                                                                                     |
| Image      | 否   | String | 图片 base64 数据,base64 编码后大小不可超过5M。<br>图片分辨率须小于2000*2000。<br>支持PNG、JPG、JPEG、BMP,不支持 GIF 图片。<br>示例值:/9j/4AAQSkZJRgABAQAAAQABAAD/4gIo...lftXF/DjFZNXoSP5V2U0HMt/1FQf/Z                                                                                                     |
| Url        | 否   | String | 图片的 Url 。<br>Url、Image必须提供一个,如果都提供,只使用 Url。<br>图片分辨率须小于2000*2000 ,图片 base64 编码后大小不可超过5M。<br>图片存储于腾讯云的Url可保障更高下载速度和稳定性,建议图片存储于腾讯云。<br>非腾讯云存储的Url速度和稳定性可能受一定影响。<br>支持PNG、JPG、JPEG、BMP,不支持 GIF 图片。<br>示例值:https://liudehua-9527.cos.ap-guangzhou.myqcloud.com/input.jpeg |
| RspImgType | 否   | String | 返回图像方式(base64 或 Url ) ,二选一。url有效期为30分钟。<br>示例值:url                                                                                                                                                            
...[truncated 24 chars]

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation explicitly supports sending human portrait images either as base64 payloads or remote URLs, but it does not include any warning about the privacy implications of transmitting biometric or highly sensitive personal imagery to a third-party cloud service. In a skill focused on portrait segmentation, this omission is more concerning because users are likely to process real identifiable photos, increasing the risk of uninformed handling of personal data.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/SegmentPortraitPicApi.md (reported line 21)May include surrounding context.

md
| Region     | 是   | String | [公共参数](https://cloud.tencent.com/document/api/1208/42965),详见产品支持的 [地域列表](https://cloud.tencent.com/document/api/1208/42965#.E5.9C.B0.E5.9F.9F.E5.88.97.E8.A1.A8)。                                                                                                     |
| Image      | 否   | String | 图片 base64 数据,base64 编码后大小不可超过5M。<br>图片分辨率须小于2000*2000。<br>支持PNG、JPG、JPEG、BMP,不支持 GIF 图片。<br>示例值:/9j/4AAQSkZJRgABAQAAAQABAAD/4gIo...lftXF/DjFZNXoSP5V2U0HMt/1FQf/Z                                                                                                     |
| Url        | 否   | String | 图片的 Url 。<br>Url、Image必须提供一个,如果都提供,只使用 Url。<br>图片分辨率须小于2000*2000 ,图片 base64 编码后大小不可超过5M。<br>图片存储于腾讯云的Url可保障更高下载速度和稳定性,建议图片存储于腾讯云。<br>非腾讯云存储的Url速度和稳定性可能受一定影响。<br>支持PNG、JPG、JPEG、BMP,不支持 GIF 图片。<br>示例值:https://liudehua-9527.cos.ap-guangzhou.myqcloud.com/input.jpeg |
| RspImgType | 否   | String | 返回图像方式(base64 或 Url ) ,二选一。url有效期为30分钟。<br>示例值:url                                                                                                                                                                                                                    |
| Scene      | 否   | String | 适用场景类型。<br><br>取值:GEN/GS。GEN为通用场景模式;GS为绿幕场景模式,针对绿幕场景下的人像分割效果更好。<br>两种模式选择一种传入,默认为GEN。<br>示例值:GEN                                                                                                                                                                      |

## 输出参数

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/SegmentPortraitPicApi.md (reported line 28)May include surrounding context.

md
| Region     | 是   | String | [公共参数](https://cloud.tencent.com/document/api/1208/42965),详见产品支持的 [地域列表](https://cloud.tencent.com/document/api/1208/42965#.E5.9C.B0.E5.9F.9F.E5.88.97.E8.A1.A8)。                                                                                                     |
| Image      | 否   | String | 图片 base64 数据,base64 编码后大小不可超过5M。<br>图片分辨率须小于2000*2000。<br>支持PNG、JPG、JPEG、BMP,不支持 GIF 图片。<br>示例值:/9j/4AAQSkZJRgABAQAAAQABAAD/4gIo...lftXF/DjFZNXoSP5V2U0HMt/1FQf/Z                                                                                                     |
| Url        | 否   | String | 图片的 Url 。<br>Url、Image必须提供一个,如果都提供,只使用 Url。<br>图片分辨率须小于2000*2000 ,图片 base64 编码后大小不可超过5M。<br>图片存储于腾讯云的Url可保障更高下载速度和稳定性,建议图片存储于腾讯云。<br>非腾讯云存储的Url速度和稳定性可能受一定影响。<br>支持PNG、JPG、JPEG、BMP,不支持 GIF 图片。<br>示例值:https://liudehua-9527.cos.ap-guangzhou.myqcloud.com/input.jpeg |
| RspImgType | 否   | String | 返回图像方式(base64 或 Url ) ,二选一。url有效期为30分钟。<br>示例值:url                                                                                                                                                                                                                    |
| Scene      | 否   | String | 适用场景类型。<br><br>取值:GEN/GS。GEN为通用场景模式;GS为绿幕场景模式,针对绿幕场景下的人像分割效果更好。<br>两种模式选择一种传入,默认为GEN。<br>示例值:GEN                                                                                                                                                                      |

## 输出参数

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/SegmentPortraitPicApi.md (reported line 22)May include surrounding context.

md
| Image      | 否   | String | 图片 base64 数据,base64 编码后大小不可超过5M。<br>图片分辨率须小于2000*2000。<br>支持PNG、JPG、JPEG、BMP,不支持 GIF 图片。<br>示例值:/9j/4AAQSkZJRgABAQAAAQABAAD/4gIo...lftXF/DjFZNXoSP5V2U0HMt/1FQf/Z                                                                                                     |
| Url        | 否   | String | 图片的 Url 。<br>Url、Image必须提供一个,如果都提供,只使用 Url。<br>图片分辨率须小于2000*2000 ,图片 base64 编码后大小不可超过5M。<br>图片存储于腾讯云的Url可保障更高下载速度和稳定性,建议图片存储于腾讯云。<br>非腾讯云存储的Url速度和稳定性可能受一定影响。<br>支持PNG、JPG、JPEG、BMP,不支持 GIF 图片。<br>示例值:https://liudehua-9527.cos.ap-guangzhou.myqcloud.com/input.jpeg |
| RspImgType | 否   | String | 返回图像方式(base64 或 Url ) ,二选一。url有效期为30分钟。<br>示例值:url                                                                                                                                                                                                                    |
| Scene      | 否   | String | 适用场景类型。<br><br>取值:GEN/GS。GEN为通用场景模式;GS为绿幕场景模式,针对绿幕场景下的人像分割效果更好。<br>两种模式选择一种传入,默认为GEN。<br>示例值:GEN                                                                                                                                                                      |

## 输出参数

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/SegmentPortraitPicApi.md (reported line 26)May include surrounding context.

md
## 输出参数

| 参数名称           | 类型      | 描述                                                                                                                                                                                                                                                                                                                                               |
| -------------- | ------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| ResultImage    | String  | 处理后的图片 base64 数据,透明背景图。<br>注意:此字段可能返回 null,表示取不到有效值。<br>示例值:/9j/4AAQSkZJRgABAQAAAQABAAD/4gIo...lftXF/DjFZNXoSP5V2U0HMt/1FQf/Z                                                                                                                                                                                                                    |
| ResultMask     | String  | 一个通过 base64 编码的文件,解码后文件由 Float 型浮点数组成。这些浮点数代表原图从左上角开始的每一行的每一个像素点,每一个浮点数的值是原图相应像素点位于人体轮廓内的置信度(0-1)转化的灰度值(0-255)。<br>注意:此字段可能返回 null,表示取不到有效值。<br>示例值:/9j/4AAQSkZJRgABAQAAAQABAAD/4gIo...lftXF/DjFZNXoSP5V2U0HMt/1FQf/Z                                                                                                                            |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/SegmentPortraitPicApi.md (reported line 29)May include surrounding context.

md
| 参数名称           | 类型      | 描述                                                                                                                                                                                                                                                                                                                                               |
| -------------- | ------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| ResultImage    | String  | 处理后的图片 base64 数据,透明背景图。<br>注意:此字段可能返回 null,表示取不到有效值。<br>示例值:/9j/4AAQSkZJRgABAQAAAQABAAD/4gIo...lftXF/DjFZNXoSP5V2U0HMt/1FQf/Z                                                                                                                                                                                                                    |
| ResultMask     | String  | 一个通过 base64 编码的文件,解码后文件由 Float 型浮点数组成。这些浮点数代表原图从左上角开始的每一行的每一个像素点,每一个浮点数的值是原图相应像素点位于人体轮廓内的置信度(0-1)转化的灰度值(0-255)。<br>注意:此字段可能返回 null,表示取不到有效值。<br>示例值:/9j/4AAQSkZJRgABAQAAAQABAAD/4gIo...lftXF/DjFZNXoSP5V2U0HMt/1FQf/Z                                                                                                                            |
| HasForeground  | Boolean | 图片是否存在前景。<br>注意:此字段可能返回 null,表示取不到有效值。<br>示例值:false                                                                                                                                                                                                                                                                                              |
| ResultImageUrl | String  | 支持将处理过的图片 base64 数据,透明背景图以Url的形式返回值,Url有效期为30分钟。<br>注意:此字段可能返回 null,表示取不到有效值。<br>示例值:https://liudehua-9527.cos.ap-guangzhou.myqclou
...[truncated 25 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/SegmentPortraitPicApi.md (reported line 30)May include surrounding context.

md
| -------------- | ------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| ResultImage    | String  | 处理后的图片 base64 数据,透明背景图。<br>注意:此字段可能返回 null,表示取不到有效值。<br>示例值:/9j/4AAQSkZJRgABAQAAAQABAAD/4gIo...lftXF/DjFZNXoSP5V2U0HMt/1FQf/Z                                                                                                                                                                                                                    |
| ResultMask     | String  | 一个通过 base64 编码的文件,解码后文件由 Float 型浮点数组成。这些浮点数代表原图从左上角开始的每一行的每一个像素点,每一个浮点数的值是原图相应像素点位于人体轮廓内的置信度(0-1)转化的灰度值(0-255)。<br>注意:此字段可能返回 null,表示取不到有效值。<br>示例值:/9j/4AAQSkZJRgABAQAAAQABAAD/4gIo...lftXF/DjFZNXoSP5V2U0HMt/1FQf/Z                                                                                                                            |
| HasForeground  | Boolean | 图片是否存在前景。<br>注意:此字段可能返回 null,表示取不到有效值。<br>示例值:false                                                                                                                                                                                                                                                                                              |
| ResultImageUrl | String  | 支持将处理过的图片 base64 数据,透明背景图以Url的形式返回值,Url有效期为30分钟。<br>注意:此字段可能返回 null,表示取不到有效值。<br>示例值:https://liudehua-9527.cos.ap-guangzhou.myqcloud.com/result.mp4?q-sign-algorithm=sha1&q-ak=AKID********EXAMPLE&q-sign-time=8888;9999&q-key-time=8888;9999&q-header-list=&q-url-param-list=&q-signature=7de87f7bf9cfd23df9da32f46661e7cf97a5603c              |
| ResultMaskUrl  | String  | 一个通过 base64 编码的文件,解码后文件由 Float 型浮点数组成。支持以Url形式的返回值;Url有效期为30分钟。<br>注意:此字段可能返回 null,表示取不到有效值。<br>示例值:https://liudehua-9527.cos.ap-gu
...[truncated 25 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/SegmentPortraitPicApi.md (reported line 33)May include surrounding context.

md
| HasForeground  | Boolean | 图片是否存在前景。<br>注意:此字段可能返回 null,表示取不到有效值。<br>示例值:false                                                                                                                                                                                                                                                                                              |
| ResultImageUrl | String  | 支持将处理过的图片 base64 数据,透明背景图以Url的形式返回值,Url有效期为30分钟。<br>注意:此字段可能返回 null,表示取不到有效值。<br>示例值:https://liudehua-9527.cos.ap-guangzhou.myqcloud.com/result.mp4?q-sign-algorithm=sha1&q-ak=AKID********EXAMPLE&q-sign-time=8888;9999&q-key-time=8888;9999&q-header-list=&q-url-param-list=&q-signature=7de87f7bf9cfd23df9da32f46661e7cf97a5603c              |
| ResultMaskUrl  | String  | 一个通过 base64 编码的文件,解码后文件由 Float 型浮点数组成。支持以Url形式的返回值;Url有效期为30分钟。<br>注意:此字段可能返回 null,表示取不到有效值。<br>示例值:https://liudehua-9527.cos.ap-guangzhou.myqcloud.com/mask.mp4?q-sign-algorithm=sha1&q-ak=AKID********EXAMPLE&q-sign-time=8888;9999&q-key-time=8888;9999&q-header-list=&q-url-param-list=&q-signature=7de87f7bf9cfd23df9da32f46661e7cf97a5603c |
| RequestId      | String  | 唯一请求 ID,由服务端生成,每次请求都会返回(若请求因其他原因未能抵达服务端,则该次请求不会获得 RequestId)。定位问题时需要提供该次请求的 RequestId。                                                                                                                                                                                                                                                           |

## 错误码

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill installs a package at runtime through pip even though this is not essential to its core logic and is not disclosed as a privileged operation. This expands the attack surface through dependency confusion, compromised upstream packages, or unsafe execution in restricted environments, and is especially risky because it happens automatically during normal use.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
95% confidence
Finding

The code executes a runtime pip installation via subprocess when the dependency is missing. Although the command is hardcoded and not directly command-injection prone, installing packages during execution introduces a supply-chain risk, performs unexpected network activity, and allows unpinned third-party code to be fetched and executed in the user's environment.

Content

Scanner excerpt · scripts/main.py (reported line 15)May include surrounding context.

python
import tencentcloud  # noqa: F401
    except ImportError:
        print("[INFO] tencentcloud-sdk-python not found. Installing...", file=sys.stderr)
        subprocess.check_call(
            [sys.executable, "-m", "pip", "install", "tencentcloud-sdk-python", "-q"],
            stdout=sys.stderr,
            stderr=sys.stderr,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill sends user-supplied image URLs or base64-encoded local files to a remote Tencent Cloud API, but it does not clearly warn the user at the point of use that image data leaves the local environment. For portrait segmentation, the transferred data is likely personally sensitive, so lack of transparent disclosure creates privacy and compliance risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The natural-language content and execution instructions are entirely in Chinese, but the file does not indicate that the skill is intentionally limited to Chinese-speaking users or provide an opt-in language choice. Under the locale policy, forcing a specific language without user choice can be a policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The credential setup guidance includes Chinese-only instructional text in the emitted error message, which imposes a locale preference on users who may not read Chinese. There is no opt-in, alternative language selection, or explanation that the skill is intended only for a Chinese-speaking audience.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.