Back to skill

Security audit

Faceswap

Security checks for vulnerabilities and agentic risk

Overview

This face-swap skill is coherent but needs careful review because it sends face/video media and an API key to an external service while using broad URL downloads and unsafe temporary-file instructions.

Install only if you are comfortable sending selected face images, videos, and your verging.ai API key to the service. Prefer local files or trusted HTTPS URLs, avoid private/internal URLs, use a pinned installer or reviewed commit when possible, and clean /tmp/verging-faceswap after use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
skill.md:105
Finding

Insufficient Validation and Unsafe Shell Interpolation of User-Controlled Arguments

Content
View full analysis
30s): ```bash ffmpeg -i input.mp4 -ss -to -c:v libx264 -c:a aac /tmp/verging-faceswap/trimmed.mp4 ``` ``` ### Technical Analysis The Skill directs the Agent to place user-provided video URLs, image URLs, and trim values into command-line operations without requiring strict validation. Although the example URLs are enclosed in quotes, the instructions do not restrict URL schemes, resolve and validate destinations, impose download limits, or verify that redirects remain on public networks. In particular, `curl -L` follows redirects and can retrieve resources from destinations selected by the user. This may permit access to loopback, private-network, link-local, or local-file resources, depending on the schemes and network access available to the installed client. The `` and `` values are also inserted into a shell command without a requirement that they be parsed as bounded numeric values. If an implementation constructs a shell command by textual substitution, shell metacharacters or malicious option values may cause command or argument injection. No file-size, media-type, or resource-consumption limits are prescribed before untrusted content is passed to `ffmpeg`, `ffprobe`, or `yt-dlp`. ### Attack Path 1. An attacker invokes `/faceswa ...[truncated 1614 chars]
Remediation
View remediation
= 0` - `end > start` - `end - start <= 30` - A reasonable maximum absolute duration 2. Execute external programs with argument arrays and without a command shell. Never construct commands through textual concatenation or substitution. 3. Insert `--` before positional file arguments where the target utility supports it, and reject ambiguous values beginning with `-`. 4. Allow only explicitly supported URL schemes, preferably `https`. 5. Resolve destination hostnames and reject loopback, link-local, multicast, private, reserved, and cloud-metadata address ranges for every redirect. 6. Limit redirect count, download size, transfer time, and bandwidth. 7. Validate downloaded files using magic bytes and trusted media parsers rather than relying on extensions or response `Content-Type`. 8. Run media-processing tools in a restricted sandbox with limited filesystem access, network access, CPU time, memory, and output size. 9. Require explicit user confirmation before uploading any resource fetched from a user-provided URL to a third-party service. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
skill.md:133
Finding

Predictable Shared Temporary Directory Permits Symlink Attacks and Cross-Session Data Exposure

Content
View full analysis
` (recommended)** — `Bearer ` also works - **Only the VIDEO needs separate upload** via /upload-video + PUT to presigned URL - **Face image is uploaded directly in create-job** as multipart `swap_image=@path` — no separate upload step - **`/upload-video` uses Form Data (`-F`)** — NOT JSON (`-d`) - **Max video duration: 30 seconds** — trim longer videos first - **Temp directory: `/tmp/verging-faceswap/`** — create with `mkdir -p` - If yt-dlp is unavailable, ask user to download video manually ``` The workflow also writes predictable names to that directory: ```bash yt-dlp "URL" -o /tmp/verging-faceswap/input.mp4 curl -L -o /tmp/verging-faceswap/face.jpg "URL" ffmpeg -i input.mp4 -ss -to -c:v libx264 -c:a aac /tmp/verging-faceswap/trimmed.mp4 ``` Cleanup is only advisory at `skill.md:153`: ```markdown - Temp files in `/tmp/verging-faceswap/` — clean up after use ``` ### Technical Analysis The Skill uses a fixed directory under the globally shared `/tmp` namespace and predictable filenames including `input.mp4`, `face.jpg`, and `trimmed.mp4`. Creating the directory with `mkdir -p` neither guarantees exclusive ownership nor prevents reuse of an attacker-created directory. On a multi-user system, another local process may pre-create the directory, create symbolic links at the expected file paths, or replace files between workflow stages. Some invoked utilities may follow symbolic links when creating or overwriting output files. Concurrent face-swap invocations can also overwrite or consume each other's files. The instructions do not require restrictive permissions, ownership verification, no-follow semantics, exclusive creation, per-invocation isolation, or guaranteed cleanup after errors and interruption ...[truncated 1326 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:9
Finding

Unpinned npx Installer Introduces a Third-Party Supply-Chain Risk

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The markdown states that the skill supports YouTube/Bilibili URLs and remote images, which implies transmitting user-provided URLs or downloading remote content, but it does not warn about privacy or network activity. It also presents file-affecting behavior elsewhere without a clear safety disclosure in the description.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
79% confidence
Finding

The skill demonstrates authenticated requests to an external API and encourages transmission of an API key and user media to a third-party service. While external transmission is central to the skill's purpose, it is still a genuine security/privacy concern because credentials and potentially sensitive face/video data leave the local environment, and the example includes a literal key-shaped token format that could normalize unsafe handling of secrets.

Content

Scanner excerpt · skill.md (reported line 50)May include surrounding context.

bash
# ✅ Recommended (canonical form)
curl -H "Authorization: ApiKey vrg_sk_your_key_here" https://verging.ai/api/v1/auth/me

# ✅ Also works (Bearer with API key is supported)
curl -H "Authorization: Bearer vrg_sk_your_key_here" https://verging.ai/api/v1/auth/me

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs the agent to download remote video/image content, store it under /tmp, and upload user media to an external service, but it does not require an explicit runtime warning or consent step before transmission and temporary storage. In a user-invocable skill handling personal media such as face images and videos, this creates a real privacy and data-handling risk because sensitive biometric content may be transferred off-device and left on local disk unexpectedly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The options table shows --download and --output, indicating that the skill can save results locally, but the README does not explicitly warn users about local file creation or overwrite considerations. For markdown files, behaviors affecting user data or system state should be clearly disclosed.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.