Back to skill

Security audit

Model Skin Swap Prompt Generator

Security checks for vulnerabilities and agentic risk

Overview

This prompt-only skill has no code or persistence, but it needs review because it directs region-linked skin and facial-feature changes by default.

Review this skill carefully before installing if you work with real people or commercial imagery. It is prompt-only, but it may steer edits toward nationality or region-based facial features and beauty standards rather than limiting itself to user-specified skin-tone adjustments.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is explicitly designed to adapt outputs to regional aesthetic standards, which bakes locale-based normative judgments into image-editing instructions without requiring affirmative user opt-in. That can steer the model toward demographic profiling or beauty-standard enforcement tied to geography, creating fairness and sensitive-trait concerns.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases are broad enough to capture common image-editing requests, which can cause this skill to activate in contexts beyond its intended niche. In this skill, that matters because the downstream behavior is to generate identity- and region-linked appearance transformation prompts, increasing the chance of inappropriate or policy-sensitive output without clear user intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This section goes beyond skin-tone editing and instructs the system to match target-region facial features such as eye shape, nose bridge, and jawline. That crosses into generating physiognomic changes associated with ethnicity or nationality, which is more sensitive and potentially discriminatory than ordinary cosmetic retouching.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 40)May include surrounding context.

3. Output

Output the prompt directly without asking additional questions:

text
Change the model's skin tone in the original image to [target skin tone], [skin tone feature description], with delicate and natural skin texture, strictly preserve original clothing, lighting, background, hairstyle, hair color, and composition, skin tone should be realistic and harmonious, while reflecting the popular aesthetic standards of that country, do not modify the original high-definition commercial fashion photography style

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The default prompt template operationalizes country-specific aesthetic alignment as a mandatory output behavior. Because it is embedded in the template, the skill will repeatedly produce locale-normative edits even when the user only asked for a basic skin-tone adjustment.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

md
## Constraints

- Provide the prompt directly; do not ask the user additional questions
- Prompt should be concise and clear, ready for direct use
- All product details (fabric texture, color, folds, accessories, posture, brand logos) must remain 100% identical
- New skin tone should be natural and realistic; avoid exaggerated stereotypes

Static analysis

No suspicious patterns detected.