Back to skill

Security audit

Storyboard Creation

Security checks for vulnerabilities and agentic risk

Overview

This storyboard skill is mostly coherent, but it tells users to execute mutable remote installation code and unpinned package commands, which warrants manual review before installation.

Review this skill before installing. Use the storyboard guidance freely, but do not run the curl-to-shell installer or unpinned npx commands in an environment with sensitive files or credentials unless you independently trust and verify the sources. Treat prompts, scripts, shot lists, and image filenames used with infsh as potentially sent to a third-party service.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:14
Finding

Remote Installer Is Downloaded and Executed Without Independent Verification

Content
View full analysis
Remediation
View remediation
//infsh" printf '%s %s\n' '' 'infsh' | sha256sum --check - install -m 0755 infsh "$HOME/.local/bin/infsh" ``` The actual URL, platform identifier, version, signature, and digest must come from authenticated and audited release metadata. ]]>

T08 · Insecure Dependencies

Warning
Location
SKILL.md:259
Finding

Unpinned Packages and Skill Sources Are Installed Through npx

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (9)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

curl ... | sh fetches and immediately executes a remote script, which is a classic high-risk supply-chain pattern because any compromise of the distribution endpoint, DNS, TLS termination, or upstream publishing process can lead to arbitrary code execution on the host. The risk is amplified here because the skill is framed as a benign storyboard aid, making users more likely to run the command without the scrutiny they would apply to a software-installation skill.

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

Quick Start

bash
curl -fsSL https://cli.inference.sh | sh && infsh login

# Generate a storyboard panel
infsh app run falai/flux-dev-lora --input '{

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest presents the skill as storyboard knowledge and planning, but the content materially expands into remote AI image generation and image stitching through an external CLI. That mismatch can cause agents or users to grant broader execution and data-sharing capabilities than expected, increasing the chance of unsafe tool use under a seemingly innocuous creative-planning label.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description lists triggers such as "storyboard," "film planning," "video planning," and "scene planning" without narrowing context or giving exclusion conditions. Several of these phrases are broad enough to match ordinary conversations about media projects, which could cause unintended invocation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The examples send user prompts and local file references to a remote CLI service without a clear privacy or data-transmission warning. In a creative workflow, prompts, script details, shot plans, and local filenames may contain proprietary or unreleased production information, so silent remote transmission materially increases confidentiality risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill includes software installation and remote service usage even though its stated purpose is instructional storyboard creation. In context, that makes the capability more dangerous because users invoking a planning skill may not expect shell installation, authentication, or data transmission to third-party services, creating elevated supply-chain and privacy risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.