Back to skill

Security audit

Image Tools (ImageMagick)

Security checks for vulnerabilities and agentic risk

Overview

This image-editing skill is mostly coherent, but two scripts can turn crafted image text, filenames, or options into local shell commands.

Read carefully before installing. Use only with trusted local filenames, captions, and option values until adjust.sh and annotate.sh are rewritten to call ImageMagick with argument arrays instead of eval, and composite.sh uses mktemp with trapped cleanup. Avoid processing sensitive images in shared multi-user environments with the current temporary-file handling.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/adjust.sh:45
Finding

Arbitrary Command Execution Through Unsafe eval in adjust.sh

Content
View full analysis
$output" eval "$cmd" ``` ### Technical Analysis The script builds an ImageMagick command as a string containing user-controlled input and then passes that string to `eval`. The shell therefore parses the command twice: 1. Once while the command string is assembled. 2. Again when `eval` interprets the completed string as shell source code. The embedded quotation marks do not safely quote hostile values during the second parsing stage. Values such as the input path, output path, rotation, saturation, blur geometry, border geometry, and border color can introduce quotation marks, command separators, command substitutions, redirections, or other shell syntax. The affected option values are not validated against their documented numeric, color, or geometry formats. Consequently, the flaw is not limited to unusual filenames. ### Attack Path 1. An attacker obtains control over an argument passed to `adjust.sh`, such as the output filename or an adjustment option. 2. The attacker supplies a value that closes the generated quotation context and appends a shell command, for example an output argument structurally equiv ...[truncated 960 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/annotate.sh:46
Finding

Arbitrary Command Execution Through Annotation Text and Options

Content
View full analysis
$output | \"$text\"" eval "$cmd" ``` ### Technical Analysis The annotation text and multiple command options are inserted into a shell command string and then executed with `eval`. The annotation text is particularly exposed because arbitrary text is an expected and documented input to the script. Adding literal double quotes around `$text` while constructing the string is not a security boundary. An attacker-controlled quotation mark can terminate the generated quoted argument when `eval` reparses it. Shell operators can then append an independent command. The same weakness affects the input path, output path, gravity, stroke, stroke width, fill color, font, point size, background color, and offset. Several values are concatenated without even generated quotation marks, and none are constrained to their documented formats. ### Attack Path 1. An attacker controls text that is passed to the annotation feature, such as a caption, watermark, label, or user-provided message. 2. The supplied text contains a quotation mark followed by shell syntax, structurally equivalent to: ```text label"; id > /tmp/annotate-injection; # ``` 3. Line 50 embeds this content into the dynamic `cmd` string. 4. Line 53 passes the string to `eval`. 5. The shell treats the appended content as a separate command and executes it under the Skill process account. An attacker could alternatively inject through a crafted output path or one of the ...[truncated 553 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/composite.sh:44
Finding

Predictable Temporary Files Permit Symlink Attacks and Data Retention

Content
View full analysis
$output (gravity: $gravity, offset: $offset)" composite -gravity "$gravity" -geometry "$offset" "$overlay_cmd" "$background" "$output" [ -n "$tmp_files" ] && rm -f $tmp_files ``` ### Technical Analysis Temporary filenames are generated directly under the shared `/tmp` directory using the process ID: ```text /tmp/comp_resize_.png /tmp/comp_opacity_.png ``` Process identifiers are predictable, and the script does not create temporary files atomically or verify that an existing path is not a symbolic link. A local attacker can attempt to create one of these names before ImageMagick writes to it and point it at another file writable by the victim account. Cleanup is also fragile. Because the script uses `set -e`, any failure before line 61 can terminate execution without removing generated images. There is no `trap` to guarantee cleanup. This can leave copies or processed versions of potentially sensitive images in a shared temporary directory. The unquoted `rm -f $tmp_files` is poor defensive practice, although the currently generated temporary names contain no spaces or glob characters. ### Attack Path 1. A local attacker observes or predicts the process ID of a future or running `composite.sh` process. 2. The attacker creates a symbolic link at a p ...[truncated 1155 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Chaining Abuse

High
Category
Tool Misuse
Confidence
94% confidence
Finding

The cleanup uses an unquoted variable in rm -f $tmp_files, and tmp_files is built from predictable /tmp paths. Because shell word-splitting applies, a crafted temporary filename or unexpected contents in the variable can alter which paths are removed, and the use of predictable names in /tmp also creates symlink/race risks in a multi-user environment. In this image-processing context, the issue is more dangerous because the script routinely handles attacker-controlled file paths and writes temporary artifacts during normal operation.

Content

Scanner excerpt · scripts/composite.sh (reported line 61)May include surrounding context.

sh
echo "Compositing: $overlay onto $background -> $output (gravity: $gravity, offset: $offset)"
composite -gravity "$gravity" -geometry "$offset" "$overlay_cmd" "$background" "$output"
[ -n "$tmp_files" ] && rm -f $tmp_files
echo "Done: $output ($(identify -format '%wx%h' "$output"))"

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script builds a shell command string from user-controlled inputs and executes it with eval, which causes the shell to re-parse the constructed command. Although some parameters are quoted, several options such as rotate, blur, sharpen, saturation, and border are inserted without robust validation, so crafted input can break command structure or inject additional shell syntax, leading to arbitrary command execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code file executes a dynamically constructed shell command with eval, which is a safety-relevant subprocess operation. Although the script prints a progress message, it does not disclose that it will invoke an external command through shell evaluation, nor does it ask for confirmation or include a warning comment/docstring about that execution behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script constructs a shell command string from user-controlled inputs such as text, font, color, gravity, offset, and output path, then executes it with eval. Because eval re-parses the assembled string as shell syntax, an attacker can inject command substitutions or quoting payloads and achieve arbitrary command execution, which is far more dangerous than ordinary ImageMagick argument handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

This code executes a dynamically constructed shell command with eval, which is a safety-relevant subprocess operation for code files. Although the script prints source and destination paths, it does not explicitly disclose that it will invoke ImageMagick through shell execution, and the usage/comments do not warn about that behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The script writes a transformed image to the output path, and if no output is provided it auto-generates a new filename. While it echoes the source and destination paths, there is no explicit warning or confirmation about the file-write behavior in the script comments or usage text, which is relevant for a code file performing filesystem modification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.