Back to skill

Security audit

智能抠图助手

Security checks for vulnerabilities and agentic risk

Overview

This skill is a simple background-removal guide that uses disclosed cloud image APIs, with no hidden code, persistence, or automatic local changes.

Before installing or using this skill, consider whether the images may contain faces, IDs, documents, confidential products, or other sensitive content. The skill relies on third-party cloud APIs, so review the provider terms and avoid uploading sensitive images unless you have permission and are comfortable with that processing.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The README promotes sending user images to Baidu/Tencent third-party APIs for background removal but does not disclose any privacy, retention, consent, or cross-border data-handling implications. Because images may contain faces, products, documents, or other sensitive content, users and integrators could unknowingly transmit personal or confidential data to external providers.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill promotes cloud-based background removal via Baidu's image segmentation API but does not warn users that uploaded images may be transmitted to and processed by a third-party service. This is dangerous because users may submit sensitive personal, product, or identity images without informed consent, creating privacy, compliance, and data-handling risks.

Static analysis

No suspicious patterns detected.