Back to skill

Security audit

Ntriq Vision Product Analyzer Mcp

Security checks for vulnerabilities and agentic risk

Overview

The skill says image analysis is local, but its documented use sends product images to a paid external service.

Review this carefully before installing. Do not submit confidential product, prototype, inventory, competitor, private URL, or signed-link images unless you are comfortable sending them to x402.ntriq.co.kr and paying the documented per-call fee. Prefer a version that clearly separates local and hosted modes and states data handling and payment controls.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

other

Warning
Location
SKILL.md:14
Finding

Misleading Local-Processing Claim May Cause Undisclosed External Image Transmission

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 14-56
Vulnerability Type: Undisclosed External Data Transmission
Risk Level: Medium

The documentation states that no external API is required, yet the only documented access mechanism is a paid third-party endpoint. This discrepancy may cause users or agents to transmit product images and related information externally under the mistaken belief that processing occurs locally.

Vulnerable Documentation

markdown
Analyze product images to identify items, extract technical specifications, compare features across variants, and generate optimized product descriptions for e-commerce. Powered by local Qwen2.5-VL — no external API required.

## Parameters

| Parameter | Type | Required | Description |
|-----------|------|----------|-------------|
| `images` | array | ✅ | Product image URLs or base64 (up to 10 per product) |
| `tasks` | array | ❌ | `identify`, `specs`, `compare`, `description` (default: all) |
| `category_hint` | string | ❌ | Product category hint for better accuracy |
| `competitor_images` | array | ❌ | Competitor product images for comparison |

...

## Access

```bash
# x402 endpoint — pay $0.05 USDC per call (Base mainnet)
POST https://x402.ntriq.co.kr/vision-product

# Service catalog
curl https://x402.ntriq.co.kr/services

x402 micropayments — USDC on Base, gasless EIP-3009

text

### Technical Analysis

The statement “Powered by local Qwen2.5-VL — no external API required” conflicts with the documented instruction to submit requests to `https://x402.ntriq.co.kr/vision-product`.

If `images` or `competitor_images` are supplied as base64 data, their complete contents must be sent to the external service for remote processing. If URLs are supplied, the service receives those URLs, which may expose private resource names, internal storage structure, tracking data, or sensitive signed query parameters. The documentation provides no disclosure co
...[truncated 1842 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the local-processing claim with a precise statement that requests and supplied images are sent to the external x402.ntriq.co.kr service.
  2. If local inference is genuinely supported, provide complete local installation and execution instructions and clearly distinguish the local and hosted operating modes.
  3. Require explicit user confirmation before transmitting image contents, image URLs, or competitor materials to the external service.
  4. Display the destination hostname, exact payment amount, network, token, and recipient before authorizing each payment.
  5. Enforce configurable per-call, per-session, and cumulative spending limits, and prevent automatic retries from creating duplicate charges.
  6. Warn users not to submit confidential images or signed/private URLs unless they accept third-party disclosure. Prefer short-lived, least-privilege URLs when remote retrieval is necessary.
  7. Strip unnecessary image metadata before upload and avoid logging base64 image contents or sensitive URL query parameters.
  8. Document the service’s retention period, deletion procedure, subprocessors, permitted data uses, privacy policy, and security controls.
  9. Validate that requests and payment authorizations target only the documented HTTPS hostname and expected blockchain network.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly accepts image URLs/base64 and directs users to a remote paid HTTPS endpoint, but it provides no privacy or data-handling warning for potentially sensitive product, prototype, inventory, or competitor imagery. This can lead users to transmit confidential business images off-platform without informed consent or understanding of retention, logging, or third-party processing risks.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.