T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/smart_image_loader.py:102- Finding
Arbitrary Local File Access Outside the Workspace Boundary
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill has a coherent image-loading purpose, but its URL downloading, unrestricted local path handling, and shell-based cleanup create material review risks.
Review before installing. Use only with trusted image URLs and known workspace image paths, and avoid following the documented `rm <file_path>` cleanup pattern. The publisher should constrain downloads, validate images and file sizes, confine local paths to the workspace, and perform cleanup through a safe non-shell API.
scripts/smart_image_loader.py:102Arbitrary Local File Access Outside the Workspace Boundary
scripts/smart_image_loader.py:46Unrestricted URL Fetching Enables SSRF and Resource Exhaustion
SKILL.md:96Shell Command Injection Risk in Documented Temporary-File Cleanup
The documented behavior claims the skill displays images using the read tool, but the described implementation primarily resolves paths or downloads files and leaves display and cleanup to follow-on actions. This mismatch is risky because reviewers and users may trust the skill description while overlooking the actual execution flow, including extra script execution, network retrieval, and deletion steps.
The skill instructs network access and file operations but does not declare any tool scope or permissions boundaries. This is dangerous because it obscures the skill's effective capabilities from reviewers and users, increasing the chance that network fetches and filesystem side effects occur without explicit authorization or oversight.
The skill tells the agent to download remote images and later delete temporary files without warning the user that network access and local filesystem changes will occur. This is dangerous because it can cause silent outbound requests to attacker-controlled URLs and unexpected file operations, which can leak metadata or create trust and safety issues even if the downloaded content is only an image.
Recommending rm <file_path> as cleanup without strong constraints or user warning creates a command-injection and unintended-deletion risk if the path is malformed, attacker-influenced, or points outside the intended temporary directory. In this skill's context, downloaded filenames may derive from untrusted URLs, making deletion behavior more dangerous than ordinary local cleanup guidance.
No suspicious patterns detected.