Back to skill

Security audit

Google Imagen 3 Portrait Photography

Security checks for vulnerabilities and agentic risk

Overview

This skill is a low-risk prompt template for portrait image generation, with placeholder support files but no hidden execution, credential use, persistence, or data access.

Install this only if you want a simple portrait prompt template, not a working Google Imagen 3 integration. Review the prompt content and language mix for your workflow; the placeholder script and reference files do not add real generation functionality.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description claims a concrete image-generation capability focused on professional portrait photography using Google Imagen 3. However, the actual code chunk does not implement any such functionality. It only prints a static example message and includes TODO comments indicating missing logic. This is a material mismatch because the code’s actual behavior is merely a placeholder and does not perform the declared primary purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file presents the description and embedded prompt in English while the main title and usage guidance are in Chinese. This imposes mixed-language behavior on users without any opt-in or explanation, which can violate language/locale policy requirements for consistent user-facing communication.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.