Back to skill

Security audit

Image Detection

Security checks for vulnerabilities and agentic risk

Overview

This image-detection skill is coherent, but it needs review because it relies on changing npm packages and under-explains when images may leave the device.

Install only if you are comfortable auditing or sandboxing the npm packages first and treating the Hive API and reverse-image-search features as potentially sending images or metadata to outside services. Prefer the privacy-focused configuration for sensitive images and require pinned versions, a lockfile, and explicit network/data-flow documentation before broader use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:19
Finding

Unpinned and Unverifiable Third-Party npm Dependencies

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 19–78
Vulnerability Type: Unpinned third-party dependencies and unverifiable supply-chain code
Risk Level: Medium

The documentation instructs users to install multiple npm packages without fixed versions, integrity hashes, a lockfile, or bundled source code.

Vulnerable Code Snippets

SKILL.md, line 19:

bash
npm install @clawhub/image-analyzer

SKILL.md, line 43:

bash
npm install @clawhub/hf-image-detector

SKILL.md, lines 76–78:

bash
npm install @raghulpasupathi/image-detection

Technical Analysis

These commands resolve and install whatever package version the npm registry identifies as current at installation time. Consequently, the effective code can change after this Skill has been audited. npm installations may also execute package lifecycle scripts, such as preinstall, install, or postinstall, with the privileges of the user performing the installation.

The project contains no package manifest, lockfile, integrity metadata, vendored implementation, or other mechanism through which the installed code can be verified against the reviewed artifact. Because the referenced implementations are absent, claims such as localOnly, “Local inference,” and “no API calls” cannot be validated from this project.

This finding does not establish that the named packages are malicious. The vulnerability is the unsafe and unverifiable dependency-installation process, which creates a supply-chain attack opportunity if a package, publisher account, registry response, or transitive dependency is compromised.

Attack Path

  1. An attacker compromises a referenced package, its publisher account, or one of its transitive dependencies, or otherwise causes a malicious release to be resolved.
  2. The attacker publishes a modified package version containing malicious runtime behavior or an npm lifecycle script.
  3. A u ...[truncated 1197 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin every direct dependency to an exact, reviewed version rather than allowing npm to resolve a changing release.
  2. Provide a package manifest and commit a lockfile containing resolved versions and registry integrity hashes.
  3. Audit the complete transitive dependency graph before distribution and repeat the review whenever dependencies change.
  4. Verify package ownership, provenance, signatures, and registry origin. Consider npm provenance attestations where supported.
  5. Disable lifecycle scripts during installation with npm install --ignore-scripts when the packages do not require them. If scripts are required, inspect and explicitly document each script before execution.
  6. Include or link to auditable source code corresponding exactly to the pinned releases so that local-only and network-privacy claims can be independently verified.
  7. Run installation and image processing in a least-privileged, network-restricted sandbox without unnecessary credentials or access to unrelated files.
  8. Document whether images, metadata, or analysis results can leave the local system, especially for reverse-image-search and cloud-analysis features.
  9. Use automated dependency scanning and fail builds or releases when integrity checks, provenance verification, or vulnerability policies are not satisfied.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill advertises a cloud-based image analysis option ('hive-api') but does not clearly warn that submitted images may be transmitted to an external third-party service. This can lead users to unintentionally expose sensitive or private images, especially because other listed skills emphasize local-only or privacy-focused operation, which may create a misleading expectation of on-device processing.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.