Back to skill

Security audit

Alibaba Quark Scan Free

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly an image/document scanning integration, but its broad activation language and conflicting batch-processing claims create a real risk of unintended file upload to an external service.

Review before installing. Use this only for explicit image or document scan requests, avoid sensitive documents unless you accept third-party processing, and treat the batch/export and broad Security trigger language as unclear until the publisher narrows the scope.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

Medium
Confidence
79% confidence
Finding
The skill says it must ignore conversation history and operate only on the current instruction, yet later claims it auto-activates for broad 'Security' tasks that are unrelated to its narrow image-scanning purpose. This ambiguity can cause the agent to invoke the skill in unintended contexts, increasing the chance of inappropriate file handling or external data transfer to the Quark service.

Intent-Code Divergence

High
Confidence
92% confidence
Finding
The document both advertises batch scanning/export and states that only a single image is supported with no batch processing. Conflicting execution semantics are dangerous because an agent may attempt multi-file processing despite the boundary, causing accidental bulk transmission of documents to an external server or misuse of local file operations.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger condition says the skill should activate for broad 'Security' tasks, even though the skill is for image enhancement and document scanning. Overly broad activation criteria can cause unintended execution, unnecessary command invocation, and accidental sharing of user-provided files with a third-party service outside user expectations.

Static analysis

No suspicious patterns detected.