Back to skill

Security audit

550W Watermark & Text Eraser

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed media-processing integration that uploads user-selected images or videos to 550W and uses scoped credentials with explicit consent gates.

Install only if you are comfortable sending selected media, share links, and necessary 550W account credentials to the 550W service. Prefer OAuth or environment/host-managed credentials on shared systems, review credit charges before processing, and confirm deletion only for the exact task you intend to remove.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
Findings (63)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill can read user-selected local media and upload it to a remote endpoint, but the high-level description does not make that data-transfer behavior sufficiently prominent. In a privacy-sensitive context, under-disclosed remote upload of local files can lead to unintended exfiltration of personal or proprietary media.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill can read user-selected local media and upload it to a remote endpoint, but the high-level description does not make that data-transfer behavior sufficiently prominent. In a privacy-sensitive context, under-disclosed remote upload of local files can lead to unintended exfiltration of personal or proprietary media.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill can read user-selected local media and upload it to a remote endpoint, but the high-level description does not make that data-transfer behavior sufficiently prominent. In a privacy-sensitive context, under-disclosed remote upload of local files can lead to unintended exfiltration of personal or proprietary media.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill can read user-selected local media and upload it to a remote endpoint, but the high-level description does not make that data-transfer behavior sufficiently prominent. In a privacy-sensitive context, under-disclosed remote upload of local files can lead to unintended exfiltration of personal or proprietary media.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill can read user-selected local media and upload it to a remote endpoint, but the high-level description does not make that data-transfer behavior sufficiently prominent. In a privacy-sensitive context, under-disclosed remote upload of local files can lead to unintended exfiltration of personal or proprietary media.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill can read user-selected local media and upload it to a remote endpoint, but the high-level description does not make that data-transfer behavior sufficiently prominent. In a privacy-sensitive context, under-disclosed remote upload of local files can lead to unintended exfiltration of personal or proprietary media.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill can read user-selected local media and upload it to a remote endpoint, but the high-level description does not make that data-transfer behavior sufficiently prominent. In a privacy-sensitive context, under-disclosed remote upload of local files can lead to unintended exfiltration of personal or proprietary media.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill can read user-selected local media and upload it to a remote endpoint, but the high-level description does not make that data-transfer behavior sufficiently prominent. In a privacy-sensitive context, under-disclosed remote upload of local files can lead to unintended exfiltration of personal or proprietary media.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill can read user-selected local media and upload it to a remote endpoint, but the high-level description does not make that data-transfer behavior sufficiently prominent. In a privacy-sensitive context, under-disclosed remote upload of local files can lead to unintended exfiltration of personal or proprietary media.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill can read user-selected local media and upload it to a remote endpoint, but the high-level description does not make that data-transfer behavior sufficiently prominent. In a privacy-sensitive context, under-disclosed remote upload of local files can lead to unintended exfiltration of personal or proprietary media.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

md
file transfer. API Key uses an absolute `params.filePath`; OAuth uses bundled `scripts/550w-upload.cjs` inspect/upload and remote upload tickets. Read the sele

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The skill can source API credentials from local files such as 550w-ai/credentials.json and a legacy .credentials.json fallback, then optionally persist credentials after verification. Local credential-file access materially increases secret exposure risk on shared hosts, through weak file permissions, accidental inclusion in backups/logs, or unauthorized reuse by other processes.

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
This Skill grants no permissions. Use host-approved remote MCP tools, or bundled Node.js entrypoints only when execution is allowed. Read only explicitly selected images/videos; do not enumerate directories, read SSH/cloud/browser credentials, or change host rules, memory or startup files. Use only media, credits and task tools listed in the selected workflow. Task deletion requires separate user approval.

The API Key entrypoint uses only SUBTITLE_REMOVER_USER_NO and SUBTITLE_REMOVER_API_KEY, or its own user configuration file 550w-ai/credentials.json; the legacy installation .credentials.json is a read-only fallback. Region/language, configuration-directory variables and FFPROBE_PATH are local configuration, not an environment dump sent over the network. Before configureCredentials verifies and saves credentials, obtain explicit consent and set confirmCredentialStorage=true. Prefer OAuth or environment credentials on shared hosts; never print secrets in conversation or logs.

API Key video workflows may invoke ffprobe through execFile to inspect selected local videos or URLs passing public-address validation; user input is not executed through a shell. Host permission to run that binary is required. If probing is unavailable, explain the limitation rather than inventing dimensions/duration. Credit/task queries and separately confirmed task deletion support media processing; never purchase credits for the user. Installing the global package selects overseas service and English by default; use the domestic package for domestic service. Language changes must not silently switch account or service region.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · dist/550w-mcp.cjs (reported line 736)May include surrounding context.

js
get error() {
            if (this._error)
              return this._error;
            const error = new ZodError_js_1.ZodError(ctx.common.issues);
            this._error = error;
            return this._error;
          }
        };
      }
    };
    function processCreateParams(params) {
      if (!params)
        return {};
      const { errorMap, invalid_type_error, required_error, description: description2 } = params;
      if (errorMap && (invalid_type_error || required_error)) {
        throw new Error(`Can't use "invalid_type_error" or "required_error" in conjunction with custom error map.`);
      }
      if (errorMap)
        return { errorMap, description: description2 };
      const customMap = (iss, ctx) => {
        const { message } = params;
        if (iss.code === "invalid_enum_value") {
          return { message: message ?? ctx.defaultError };
        }
        if (typeof ctx.data === "undefined") {
          return { message: message ?? required_error ??

YARA rule 'exploit_framework': Exploit framework components and payloads [hacktools]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · dist/550w-mcp.cjs (reported line 24671)May include surrounding context.

js
...util.normalizeParams(params)
      });
    }
    // @__NO_SIDE_EFFECTS__
    function keyof(schema) {
      const shape = schema._zod.def.shape;
      return /* @__PURE__ */ _enum(Object.keys(shape));
    }
    exports2.ZodMiniObject = core.$constructor("ZodMiniObject", (inst, def) => {
      core.$ZodObject.init(inst, def);
      exports2.ZodMiniType.init(inst, def);
      util.installLazyProp(inst, "shape", (self) => self._zod.def.shape, false);
    });
    // @__NO_SIDE_EFFECTS__
    function object(shape, params) {
      const def = {
        type: "object",
        shape: shape ?? {},
        ...util.normalizeParams(params)
      };
      return new exports2.ZodMiniObject(def);
    }
    // @__NO_SIDE_EFFECTS__
    function strictObject(shape, params) {
      return new exports2.ZodMiniObject({
        type: "object",
        shape,
        catchall: /* @__PURE__ */ never(),
        ...util.normalizeParams(params)
      });
    }
    // @__NO_SIDE_EFFECTS__
    function loos

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · dist/550w-mcp.cjs (reported line 35892)May include surrounding context.

js
function validateAsync() {
        const ruleErrs = gen.let("ruleErrs", null);
        gen.try(() => assignValid((0, codegen_1._)`await `), (e) => gen.assign(valid, false).if((0, codegen_1._)`${e} instanceof ${it.ValidationError}`, () => gen.assign(ruleErrs, (0, codegen_1._)`${e}.errors`), () => gen.throw(e)));
        return ruleErrs;
      }
      function validateSync() {
        const validateErrs = (0, codegen_1._)`${validateRef}.errors`;

Credential Access

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

The skill reads and writes credentials in predictable filesystem locations such as ~/.config/550w-ai/credentials.json. Secrets stored in plaintext on disk are high-value targets and may be recoverable by other local processes, backups, logs, or users on shared systems.

Content

Scanner excerpt · dist/550w-mcp.cjs (reported line 43555)May include surrounding context.

js
var CredentialManager = class {
      constructor(storagePath) {
        const configRoot = process.env.XDG_CONFIG_HOME?.trim() || (process.platform === "win32" ? process.env.APPDATA?.trim() : null) || path.join(os.homedir(), ".config");
        this.storagePath = storagePath ?? path.join(configRoot, "550w-ai", "credentials.json");
        this.legacyStoragePath = path.resolve(__dirname, "../.credentials.json");
      }
      get() {

Credential Access

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

The legacy fallback path ../.credentials.json broadens the search space for secret discovery and may cause the skill to pick up unintended credentials from project directories. Predictable fallback secret files are risky because they are easy to leak via source control, workspace sharing, or unrelated tooling.

Content

Scanner excerpt · dist/550w-mcp.cjs (reported line 43556)May include surrounding context.

js
constructor(storagePath) {
        const configRoot = process.env.XDG_CONFIG_HOME?.trim() || (process.platform === "win32" ? process.env.APPDATA?.trim() : null) || path.join(os.homedir(), ".config");
        this.storagePath = storagePath ?? path.join(configRoot, "550w-ai", "credentials.json");
        this.legacyStoragePath = path.resolve(__dirname, "../.credentials.json");
      }
      get() {
        const envUserNo = process.env.SUBTITLE_REMOVER_USER_NO?.trim();

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This file implements a destructive remote task-deletion action even though the skill is presented as a subtitle/watermark remover. The mismatch expands the skill's authority beyond user expectations, increasing the risk of unauthorized or deceptive data-destruction workflows; the confirmDeletion flag reduces accidental invocation but does not address the hidden capability itself.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The implemented behavior returns success for deleting a remote task and asynchronously cleaning up related media, but the skill metadata only advertises watermark/text/subtitle removal. Omitting destructive deletion behavior from the manifest undermines informed consent and enables users or hosts to invoke a high-risk action without clear awareness of the consequence.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · dist/550w-skill.cjs (reported line 260)May include surrounding context.

js
const configRoot = process.env.XDG_CONFIG_HOME?.trim()
            || (process.platform === "win32" ? process.env.APPDATA?.trim() : null)
            || path.join(os.homedir(), ".config");
        this.storagePath = storagePath ?? path.join(configRoot, "550w-ai", "credentials.json");
        this.legacyStoragePath = path.resolve(__dirname, "../.credentials.json");
    }
    get() {

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · dist/550w-skill.cjs (reported line 261)May include surrounding context.

js
const configRoot = process.env.XDG_CONFIG_HOME?.trim()
            || (process.platform === "win32" ? process.env.APPDATA?.trim() : null)
            || path.join(os.homedir(), ".config");
        this.storagePath = storagePath ?? path.join(configRoot, "550w-ai", "credentials.json");
        this.legacyStoragePath = path.resolve(__dirname, "../.credentials.json");
    }
    get() {

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · review/sources/dist/credential-manager.js (reported line 47)May include surrounding context.

js
const configRoot = process.env.XDG_CONFIG_HOME?.trim()
            || (process.platform === "win32" ? process.env.APPDATA?.trim() : null)
            || path.join(os.homedir(), ".config");
        this.storagePath = storagePath ?? path.join(configRoot, "550w-ai", "credentials.json");
        this.legacyStoragePath = path.resolve(__dirname, "../.credentials.json");
    }
    get() {

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · review/sources/dist/credential-manager.js (reported line 48)May include surrounding context.

js
const configRoot = process.env.XDG_CONFIG_HOME?.trim()
            || (process.platform === "win32" ? process.env.APPDATA?.trim() : null)
            || path.join(os.homedir(), ".config");
        this.storagePath = storagePath ?? path.join(configRoot, "550w-ai", "credentials.json");
        this.legacyStoragePath = path.resolve(__dirname, "../.credentials.json");
    }
    get() {

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · scripts/550w-upload.cjs (reported line 8960)May include surrounding context.

js
if (!(key in state.jobs)) {
          return;
        }
        delete state.jobs[key];
        if (error) {
          abort(state);
        } else {

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill explicitly describes network access, environment-variable credential use, and local Node.js/ffprobe execution, yet it declares no explicit tool scope or allowed-tools boundary. That creates a permission-model mismatch where a host or reviewer may underestimate the skill's ability to access secrets, exfiltrate media, or invoke local binaries.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution, suspicious.env_credential_access

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
dist/550w-mcp.cjs:36944

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
review/sources/node_modules/ajv/dist/compile/index.js:89

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
dist/550w-mcp.cjs:43450