Back to skill

Security audit

Generate a 3x3 grid (9-square) travel blogger style collage based on user photos and a specific destination.

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently helps generate travel-photo collages from user-provided photos and destinations, with no evidence of hidden code, persistence, credential use, or destructive behavior.

Before installing, be aware that the skill may analyze uploaded personal photos to preserve appearance across generated images and may search the web for destination landmarks. The publisher should declare web_search in the metadata and make follow-up questions match the user's language.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger condition is broad enough to activate on common combinations of photo uploads and destination mentions, which can cause the skill to run in situations where the user did not explicitly request this specific functionality. Over-broad triggering increases the chance of inappropriate processing of user photos and unintended tool usage.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill hardcodes a Chinese-language prompt when asking for a missing destination, regardless of the user's language. While not a direct security exploit, this can override user preference, create confusion, and contribute to unsafe automation behavior by reducing informed consent and clarity around what the skill is doing.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest declares only the image-generation tool, but the workflow explicitly requires web_search to research landmarks. This mismatch can cause the agent to act outside the declared capability boundary, undermining least-privilege assumptions and making review, policy enforcement, and user expectations inaccurate.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill directly instructs the agent to perform web searches without that capability being justified in the manifest context. This expands data access and external interaction beyond what reviewers and operators may expect, increasing the risk of unintended browsing, policy bypass, or exfiltration through search queries.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The instruction hard-codes a Japanese search phrase ("必去景点") as part of the recommended query without offering a language choice or explaining why that locale-specific phrasing is required. This can violate language/locale policy because it imposes a specific language in natural-language guidance rather than letting the user choose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.