Back to skill

Security audit

Makaron

Security checks for vulnerabilities and agentic risk

Overview

The skill appears purpose-aligned for Makaron media generation, but its broad activation and under-disclosed upload of prompts and media to an external service warrant Review.

Install only if you are comfortable sending prompts and selected media files to Makaron for processing. Avoid using it with private, regulated, or third-party confidential images, videos, or audio unless you have reviewed Makaron's privacy and retention terms and intend the upload.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger description is very broad ('creative media production' including photo editing, video generation/editing, music composition, and design creation), which can cause the skill to activate in many ambiguous situations. Because the skill sends prompts and user-provided media to an external CLI/service, unintended invocation can lead to unnecessary data transfer, accidental use of API credits, and unexpected processing of sensitive files.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill description does not clearly warn that user prompts, images, videos, and audio may be transmitted to Makaron via an external CLI/API. In this skill, the core workflow explicitly uploads local media and sends user content to a third-party service, so missing disclosure increases the risk of privacy violations, unintended sharing of sensitive data, and use in contexts where external transmission is not acceptable.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:42