Back to skill

Security audit

Segment Anything

Security checks for vulnerabilities and agentic risk

Overview

This image segmentation skill is purpose-aligned, but it needs review because running it can install mutable remote code and download large unverified model files.

Use this only in an isolated Python environment you are comfortable modifying. Prefer preinstalling a pinned, reviewed segment_anything dependency and using locally verified SAM checkpoints instead of allowing first-run network installation and unverified cache downloads.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/segment.py:35
Finding

Runtime Retrieval and Execution of Unpinned Remote Code

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/segment.py:17
Finding

Downloaded Model Checkpoints Are Not Integrity-Verified

Content
View full analysis
0 else None) print() return path ``` The downloaded or cached file is subsequently passed to the model loader: ```python ckpt = ensure_checkpoint(model_type, checkpoint) sam = sam_model_registry[model_type](checkpoint=ckpt) ``` ### Technical Analysis The script downloads model checkpoints over HTTPS but does not verify a pinned cryptographic digest or signature before returning and loading them. It also trusts any existing file at the predictable cache path solely because it exists. HTTPS protects data in transit under normal conditions, but it does not independently establish that the received file matches the exact checkpoint audited by the project. A compromised upstream service, CDN, certificate trust path, or locally tampered cache could substitute another file. A failed or interrupted download may also leave an invalid destination file that later runs will trust. The ultimate exploitability depends on the checkpoint deserialization behavior of the installed SAM and PyTorch versions. Model formats that permit unsafe object deserialization can potentially turn checkpoint su ...[truncated 1365 chars]
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (8)

YARA rule 'agent_skill_remote_bootstrap_execution': Remote script or code download followed by execution/bootstrap installation [agent_skills]

High
Category
YARA Match
Confidence
95% confidence
Finding

The skill instructs installation directly from a remote Git repository and also notes automatic first-run installation/download behavior. Remote bootstrap of code and model artifacts without pinning, integrity verification, or trusted packaging controls is dangerous because a compromised repository, dependency, or download path could lead to arbitrary code execution in the agent environment.

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

ne PNG per element) python3 scripts/segment.py photo.jpg ./elements/ --all

Denser grid to capture small objects

python3 scripts/segment.py photo.jpg ./elements/ --all --grid 32

Use a local checkpoint

python3 scripts/segment.py photo.jpg output.png --checkpoint /path/to/sam_vit_h_4b8939.pth

text

## Dependencies

`segment_anything` is auto-installed on first run, or install manually:

```bash
pip install git+https://github.com/facebookresearch/segment-anything.git
pip install pillow numpy torch torchvision

Workflow

  1. User provides image path
  2. Ask if hint points are needed (when subject is off-center)
  3. Run script; checkpoint auto-downloads on first use to ~/.cache/sam/
  4. Output transparent-background PNG

Model Selection

ModelSizeSpeedQuality
vit_b~375 MBfastestgood
vit_l~1.25 GBmediumbetter
vit_h~2.5 GBslowerbest

CUDA is used automatically when a GPU is available.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code dynamically installs software during normal execution even though the skill's purpose is image segmentation, not environment management. Installing code on demand from a remote source increases attack surface and can execute unreviewed installer logic in the current environment, making the skill materially more dangerous than its description suggests.

Content

No source excerpt is available for this finding.

os.system() or os exec-family call

High
Category
Dangerous Code Execution
Confidence
97% confidence
Finding

The script invokes a shell command to install a Python package directly from a remote GitHub repository at runtime. This creates a software supply-chain risk because unpinned remote code is fetched and executed in the user's environment, and any compromise of the repo, dependency chain, or network path could result in arbitrary code execution.

Content

Scanner excerpt · scripts/segment.py (reported line 37)May include surrounding context.

python
from segment_anything import SamPredictor, sam_model_registry
    except ImportError:
        print("Installing segment_anything...")
        os.system("pip install git+https://github.com/facebookresearch/segment-anything.git -q")
        from segment_anything import SamPredictor, sam_model_registry

    import torch

YARA rule 'agent_skill_remote_bootstrap_execution': Remote script or code download followed by execution/bootstrap installation [agent_skills]

High
Category
YARA Match
Confidence
98% confidence
Finding

This matches a remote bootstrap pattern because the script installs executable code directly from a Git URL at runtime, then immediately imports and uses it. That pattern is dangerous in agent skills because it bypasses normal review and package-control processes, enabling arbitrary code execution if the remote source is altered or malicious.

Content

Scanner excerpt · scripts/segment.py (reported line 37)May include surrounding context.

python
)...")
        urllib.request.urlretrieve(url, path, reporthook=lambda b, bs, t: print(f"\r  {min(b*bs,t)*100//t}%", end="", flush=True) if t > 0 else None)
        print()
    return path


def _load_sam(model_type, checkpoint):
    try:
        from segment_anything import SamPredictor, sam_model_registry
    except ImportError:
        print("Installing segment_anything...")
        os.system("pip install git+https://github.com/facebookresearch/segment-anything.git -q")
        from segment_anything import SamPredictor, sam_model_registry

    import torch

    ckpt = ensure_checkpoint(model_type, checkpoint)
    sam = sam_model_registry[model_type](checkpoint=ckpt)
    sam.to("cuda" if torch.cuda.is_available() else "cpu")
    return SamPredictor(sam)


def segment(image_path, output_path, checkpoint=None, model_type="vit_b", points=None):
    """Single-subject segmentation using one or more hint points."""
    from PIL import Image

    predictor = _load_sam(model_type, checkpoint

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill declares executable and network-capable behavior but does not define an explicit permission or allowed-tools scope. That creates an underconstrained execution boundary: an agent may invoke shell commands and fetch remote assets without a clearly documented security policy, increasing the chance of unintended code execution or network access in sensitive environments.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description says to use the skill when users want to 'remove backgrounds, cut out objects, extract foreground subjects, or perform image segmentation' without defining narrower trigger constraints or exclusions. In a markdown skill file, this broad natural-language trigger guidance could match many ordinary image-editing requests and does not clarify when this skill should or should not be selected.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script silently bootstraps both model artifacts and Python package code from remote locations without explicit upfront consent or safety messaging. While downloading a model may be expected for ML tooling, combining it with implicit package installation obscures side effects and can surprise users with network access and code execution in their environment.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes using SAM to remove backgrounds and extract foreground subjects as transparent PNGs, which implies isolating a target subject. The segment_all path goes beyond that by scanning the whole image and exporting every distinct element it can find as separate transparent PNGs, which is a broader segmentation workflow than the stated single-subject/background-removal purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.