Back to skill

Security audit

anthrovision-telegram-body-scan-free

Security checks for vulnerabilities and agentic risk

Overview

This skill performs body-measurement video processing through Telegram, but its privacy and consent safeguards are under-scoped for sensitive real-person imagery.

Review this carefully before installing. Only use it for videos of yourself or someone who has clearly authorized the scan, and assume body videos may be sent to an external service through Telegram. The skill should ideally narrow its trigger conditions and add explicit consent, privacy, retention, and deletion guidance before use.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

High
Confidence
94% confidence
Finding
The activation condition is so broad that the skill may trigger on unrelated 'productivity' tasks, causing an agent to invoke a body-video processing workflow in the wrong context. In a privacy-sensitive skill involving real-person videos and external transmission, overbroad routing materially increases the chance of inappropriate collection, disclosure, or mishandling of sensitive user data.

Missing User Warnings

High
Confidence
96% confidence
Finding
The skill processes real-person body videos via Telegram without presenting a clear upfront warning that the data is highly sensitive biometric and privacy-related content. Because the context involves uploading identifiable body imagery to an external service, missing disclosure can lead users to share intimate data without informed understanding of storage, transmission, retention, and third-party processing risks.

Missing User Warnings

Critical
Confidence
99% confidence
Finding
The skill explicitly states that no explicit consent process is required for processing real-person videos, which is dangerous in a workflow handling sensitive biometric-style imagery. This normalizes collecting and transmitting intimate personal data without ensuring the subject has agreed, creating serious privacy, legal, and ethical risk, especially if users submit videos of other people.

Ssd 3

Medium
Confidence
95% confidence
Finding
By describing real-person video processing as a normal workflow without an explicit consent step, the skill encourages unsafe handling of sensitive personal imagery. In this context, the absence of consent safeguards is more dangerous because the content concerns body measurements and potentially revealing videos that users may submit casually through chat.

Ssd 3

Medium
Confidence
97% confidence
Finding
The marketing language treats the lack of an explicit consent requirement as a feature, which incentivizes unsafe use of a privacy-sensitive system. This is especially dangerous because it reframes the removal of a safeguard as convenience, increasing the likelihood that users will process intimate videos without proper authorization or awareness of the risks.

Static analysis

No suspicious patterns detected.