Back to skill

Security audit

长图转小红书图片切割工具

Security checks for vulnerabilities and agentic risk

Overview

This looks like a genuine image-cropping skill, but it needs review because invalid size settings can make it hang or exhaust resources and its AI image-sharing workflow lacks privacy guidance.

Review before installing if you will run this in an automated or shared environment. Use positive, reasonable width and height values only, avoid very large source images, and do not send screenshots containing personal, regulated, corporate, or confidential information unless you are comfortable sharing them with the AI system handling the image.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/cropper.py:31
Finding

Unvalidated Crop Height Causes Infinite Loop and Resource Exhaustion

Content
View full analysis
= image_height: break return crops ``` The command-line interface accepts any integer for the crop height: ```python parser.add_argument('--height', type=int, default=DEFAULT_HEIGHT, help=f'目标高度(默认:{DEFAULT_HEIGHT}px,4:3 比例)') ``` The GUI similarly passes the user-controlled height directly into `process_image()`: ```python height = self.height_var.get() count = process_image( input_path=self.input_path, output_dir=str(self.output_dir), start_y=start_y, width=width, height=height, remove_logo=remove_logo, logo_height=logo_height, output_format=output_format ) ``` ### Technical Analysis The crop calculation assumes that `height` is a positive integer, but neither the command-line interface, GUI, `process_image()`, nor `calculate_crops()` enforces this invariant. When `height` is zero, the following assignment does not advance the loop: ```python y_end = min(current_y + 0, image_height) current_y = y_end ``` Consequently, `current_y` remains unchanged while the same tuple is repeatedly appended to `crops`. The loop continues until the process is terminated or available memory is exhausted. When `height` is negative, `y_end` and `current_y` move backward on every iteration. The loop condition remains true, and the list continues growing without a termina ...[truncated 1520 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (13)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs users to send original images or screenshots to an AI for processing, but provides no privacy warning, data minimization guidance, or handling restrictions. Because screenshots and long images often contain personal, corporate, or confidential information, this creates a realistic risk of unintended data disclosure to third-party AI systems or operators.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/README.md (reported line 172)May include surrounding context.

bash
# Ubuntu/Debian
sudo apt-get install python3-tk

# CentOS/RHEL
sudo yum install python3-tkinter

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/README.md (reported line 175)May include surrounding context.

md
sudo apt-get install python3-tk

# CentOS/RHEL
sudo yum install python3-tkinter

# macOS (通常已安装)
brew install python-tk

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The module title, purpose description, CLI help text, and all user-facing output are written entirely in Chinese, which imposes a specific language on users. The file does not offer any language selection, fallback, or documentation that this tool is intentionally restricted to a Chinese-only audience or region-specific workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The description frames the skill around producing Xiaohongshu-friendly output, which is a platform and locale-specific publishing context. The file does not indicate that this regional constraint is optional, user-selected, or otherwise justified as a region-specific tool, so it may conflict with language/locale policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

A language or locale policy issue can arise when a skill effectively forces a specific language without offering an alternative or noting the restriction. This README is entirely Chinese-language and does not communicate whether the skill supports other languages or whether Chinese is an intentional, documented constraint.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The inline description says the tool cuts images at a 4:3 ratio, but the surrounding skill context states the purpose is automatic cutting to Xiaohongshu 3:4 images. This is a documentation-level contradiction about the intended output aspect ratio, which could mislead users about what the tool actually produces.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file states that the tool automatically removes the bottom Logo and later documents generated output files, but it does not clearly warn users that the process alters the original visual content and creates new files on disk. For a file-processing skill, a brief disclosure helps users understand data-modifying behavior before use.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README states height 1080px corresponds to a 4:3 ratio, and the table below clarifies that 1440x1080 is 4:3 while 1080x1440 is 3:4. Because ratio is defined by both width and height, this standalone statement is contradictory/misleading documentation about the generated format.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The top-level docstring says the tool cuts images at a '4:3' ratio, and the CLI description repeats that claim at L202, but the actual defaults are width 1080 and height 1440 at L19-L20, which is a 3:4 portrait ratio. This is an active documentation contradiction about the core behavior of the tool, even though the manifest description correctly states 3:4.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The calculate_crops docstring labels the target height as '4:3 比例', but the configured DEFAULT_HEIGHT of 1440 paired with DEFAULT_WIDTH 1080 is a 3:4 portrait format. This contradicts the implemented behavior and can mislead users or maintainers about the intended crop geometry.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The help text presents '--width 1440 --height 1080' under '自定义尺寸和输出格式' while surrounding documentation describes the tool as producing Xiaohongshu-friendly slices in the main stated mode. Although customization is supported, this example conflicts with the rest of the implementation's 1080x1440 portrait defaults and reinforces the incorrect 4:3 messaging elsewhere.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The top-level docstring and window/class labels repeatedly identify the tool as '飞书长图切割工具', which conflicts with the skill manifest naming it as a Xiaohongshu cropper. Although the code still targets Xiaohongshu 3:4 output, the inline documentation and UI branding actively present a different product intent than the manifest.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.