Back to skill

Security audit

Ntriq X402 Image Upscale Batch

Security checks for vulnerabilities and agentic risk

Overview

This is a simple paid image-upscaling instruction skill that discloses its external API endpoint and $30 USDC payment requirement.

Before installing or using this skill, confirm you are comfortable sending the selected image URLs to x402.ntriq.co.kr and paying the disclosed flat $30 USDC charge. Avoid private images, intranet URLs, or long-lived signed links unless sharing them with this provider is acceptable.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill instructs users to submit image URLs to a third-party endpoint but does not clearly warn that those URLs, and the linked image resources, will be transmitted to an external service for processing. This can lead users to unintentionally disclose sensitive or internal image locations, including private CDN links, signed URLs, or intranet-accessible resources, creating privacy and data-handling risk.

Static analysis

No suspicious patterns detected.