Back to skill

Security audit

Yq Gif Sticker Generator

Security checks for vulnerabilities and agentic risk

Overview

This sticker skill does what it says, but it requires publishing image-derived GIFs online without clear consent, visibility, or deletion controls.

Install only if you are comfortable with uploaded images and generated stickers being processed by media tools and potentially made available through an online preview link. Avoid personal or sensitive photos unless you first direct the agent to keep outputs local or confirm the deployment visibility and deletion path.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill instructs users to upload photos, generates derivative media, writes outputs to disk, and explicitly deploys them for online preview/download, but it does not warn users about this processing or publication flow. In a photo-handling skill, this omission creates a meaningful privacy and consent risk because users may unknowingly expose personal or sensitive images through retained local artifacts and deployed public assets.

Static analysis

No suspicious patterns detected.