Back to skill

Security audit

image-upload-imgcdn

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says by uploading a chosen image for a permanent public link, but its response parsing creates a real remote-code-execution risk if the upload service returns malicious content.

Review before installing. Use only if you trust img.scdn.io and understand uploaded images become public and permanent. The script should be fixed to parse JSON from stdin or a file, validate the returned URL, and avoid interpolating server responses into executable Python code.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
upload-image.sh:21
Finding

Remote Code Execution Through Unsafe Python Source Interpolation

Content
View full analysis
/dev/null) ``` ### Technical Analysis The script obtains `RESPONSE` from the external `img.scdn.io` service and interpolates it directly into the source code supplied to `python3 -c`. Although the shell variable is enclosed in double quotes at the shell level, its contents are inserted into a single-quoted Python string: ```python data = json.loads('$RESPONSE') ``` A response containing a single quote can terminate the Python string and introduce additional Python statements. This makes the remote HTTP response executable code rather than treating it exclusively as JSON data. For example, a malicious service response shaped like the following could close the string, complete the existing operation, and append Python code: ```text {}'); __import__("os").system("id"); data={"url":"https://example.invalid/x"}; # ``` After interpolation, the Python program would effectively contain: ```python import json; data = json.loads('{}'); __import__("os").system("id"); data={"url":"https://example.invalid/x"}; #'); print(data.get('url', '')) ``` The vulnerability does not require the image path itself to contain shell syntax. Exploitation depends on control of the upload service's response, such as through compromise of the service, malicious server behavior, or compromise of its delivery infrastructure. HTTPS reduces network interception risk but does not protect against a compromised or intentionally malicious endpoint. The static pre-scan warning concerning `curl | bash` was not ...[truncated 1955 chars]
Remediation
View remediation
/dev/null) ``` Additional hardening should include: 1. Check the `curl` exit status using `--fail` so HTTP errors are not parsed as successful responses. 2. Apply connection and total-operation timeouts to prevent indefinite blocking. 3. Validate that the parsed top-level value is a JSON object and that `url` is a non-empty string. 4. If only known CDN URLs are expected, parse the URL and enforce an HTTPS scheme and an explicit hostname allowlist. 5. Avoid printing the entire server response on failure because it may contain unexpected or sensitive server-generated content. 6. Document clearly that the selected image is transmitted to a third-party service and becomes publicly accessible. 7. Run the Skill with only ordinary user permissions and without unnecessary access to secrets or sensitive directories. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · upload-image.sh (reported line 22)May include surrounding context.

sh
echo "Uploading $IMAGE_PATH to img.scdn.io..."
echo ""

RESPONSE=$(curl -s -X POST -F "image=@$IMAGE_PATH" https://img.scdn.io/api/v1.php)

# Parse response and get url
# Response format: {"url": "https://img.cdn1.vip/i/xxx.png"}

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill invokes shell-based behavior but does not declare any tool scope or permission boundaries. This weakens reviewability and can lead to unintended command execution capability being granted or assumed by the runtime, increasing the blast radius if the skill is modified or abused.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill facilitates uploading local images to a third-party service that returns a permanent public URL, but the warning about irreversible public exposure is not made explicit at the point of use. Users may upload sensitive local files under the mistaken assumption that this is temporary or private, causing unintended data disclosure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The file presents key instructions and outputs in both English and Chinese, but it does not state whether multilingual content is intentional or give the user any language/locale choice. This can be a policy concern where organizational guidance requires respecting user language preferences rather than implicitly forcing or mixing locales.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.