other
- Location
SKILL.md:14- Finding
Misleading Local-Processing Claim May Cause Undisclosed External Image Transmission
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 14-56
Vulnerability Type: Undisclosed External Data Transmission
Risk Level: MediumThe documentation states that no external API is required, yet the only documented access mechanism is a paid third-party endpoint. This discrepancy may cause users or agents to transmit product images and related information externally under the mistaken belief that processing occurs locally.
Vulnerable Documentation
markdown Analyze product images to identify items, extract technical specifications, compare features across variants, and generate optimized product descriptions for e-commerce. Powered by local Qwen2.5-VL — no external API required. ## Parameters | Parameter | Type | Required | Description | |-----------|------|----------|-------------| | `images` | array | ✅ | Product image URLs or base64 (up to 10 per product) | | `tasks` | array | ❌ | `identify`, `specs`, `compare`, `description` (default: all) | | `category_hint` | string | ❌ | Product category hint for better accuracy | | `competitor_images` | array | ❌ | Competitor product images for comparison | ... ## Access ```bash # x402 endpoint — pay $0.05 USDC per call (Base mainnet) POST https://x402.ntriq.co.kr/vision-product # Service catalog curl https://x402.ntriq.co.kr/servicesx402 micropayments — USDC on Base, gasless EIP-3009
text ### Technical Analysis The statement “Powered by local Qwen2.5-VL — no external API required” conflicts with the documented instruction to submit requests to `https://x402.ntriq.co.kr/vision-product`. If `images` or `competitor_images` are supplied as base64 data, their complete contents must be sent to the external service for remote processing. If URLs are supplied, the service receives those URLs, which may expose private resource names, internal storage structure, tracking data, or sensitive signed query parameters. The documentation provides no disclosure co ...[truncated 1842 chars]- Remediation
View remediation
Remediation Suggestions
- Replace the local-processing claim with a precise statement that requests and supplied images are sent to the external
x402.ntriq.co.krservice. - If local inference is genuinely supported, provide complete local installation and execution instructions and clearly distinguish the local and hosted operating modes.
- Require explicit user confirmation before transmitting image contents, image URLs, or competitor materials to the external service.
- Display the destination hostname, exact payment amount, network, token, and recipient before authorizing each payment.
- Enforce configurable per-call, per-session, and cumulative spending limits, and prevent automatic retries from creating duplicate charges.
- Warn users not to submit confidential images or signed/private URLs unless they accept third-party disclosure. Prefer short-lived, least-privilege URLs when remote retrieval is necessary.
- Strip unnecessary image metadata before upload and avoid logging base64 image contents or sensitive URL query parameters.
- Document the service’s retention period, deletion procedure, subprocessors, permitted data uses, privacy policy, and security controls.
- Validate that requests and payment authorizations target only the documented HTTPS hostname and expected blockchain network.
- Replace the local-processing claim with a precise statement that requests and supplied images are sent to the external
