Back to skill

Security audit

Byted Kickart Ai Beauty

Security checks for vulnerabilities and agentic risk

Overview

This image-beauty skill performs plausible remote image processing, but its credential handling and input processing are risky enough to require careful review before installation.

Install only if you are comfortable sending images to the remote Volcengine/Kickart service and can provide tightly scoped, disposable credentials through a safe secret mechanism. Do not paste long-lived AK/SK secrets into chat, do not run the credential-echo preflight as written, and avoid untrusted image URLs or archives until URL allowlisting, size limits, log redaction, and safe archive extraction are added.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:33
Finding

Mandatory Authentication Check Exposes Cloud Credentials

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/core/api/iccp/client.py:105
Finding

HTTP Request Logging Records Authorization Credentials

Content
View full analysis
>> {method.upper()} {url} {headers} {body}") response = requests.request( method=method.upper(), url=url, headers=headers, data=body, timeout=30 ) logging.info(f"<<< {response.headers} {response.text}") ``` The bearer-token client uses the same logging pattern: ```python headers["Authorization"] = f"Bearer {self.token}" headers["Content-Type"] = "application/json" logging.info(f">>> {method.upper()} {url} {headers} {body}") response = requests.request( method=method.upper(), url=url, headers=headers, data=body, timeout=30 ) ``` The media client also logs the complete header collection: ```python logging.info( f"[http] <<< {headers} " f"{json.dumps(body or {}, ensure_ascii=False)}" ) resp = requests.post(url, data=body_bytes, headers=headers, timeout=30) ``` ### Technical Analysis The logged `headers` objects contain the `Authorization` header. Under API-key authentication, this includes the complete bearer token. Under AK/SK authentication, it includes the access-key identifier, credential scope, signed-header list, and request signature. Request bodies are also logged. Depending on the operation, these bodies may contain task identifiers, user image URLs, media identifiers, owner identifiers, and processing metadata. Returned responses may contain signed result URLs or other account-related data. Logging authentication data is not required for normal operation or troubleshooting. It creates a persistent secondary copy of sensitive information in a location that commonly has broader access and longer retention than the original process environment. ### Attack Path 1. The Skill initializes either the bear ...[truncated 1099 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/beauty.py:454
Finding

Arbitrary Image URL Fetching Enables SSRF and Resource Exhaustion

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/beauty.py:395
Finding

TAR Link Entries Can Cause Unauthorized External File Upload

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (75)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill advertises beauty-enhancement triggers, but the observed behavior includes combo/package registration and query operations unrelated to photo processing. Bundling account/subscription workflows into a beautification skill can trick users into authorizing non-obvious service interactions and data sharing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill advertises beauty-enhancement triggers, but the observed behavior includes combo/package registration and query operations unrelated to photo processing. Bundling account/subscription workflows into a beautification skill can trick users into authorizing non-obvious service interactions and data sharing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill advertises beauty-enhancement triggers, but the observed behavior includes combo/package registration and query operations unrelated to photo processing. Bundling account/subscription workflows into a beautification skill can trick users into authorizing non-obvious service interactions and data sharing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill advertises beauty-enhancement triggers, but the observed behavior includes combo/package registration and query operations unrelated to photo processing. Bundling account/subscription workflows into a beautification skill can trick users into authorizing non-obvious service interactions and data sharing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill advertises beauty-enhancement triggers, but the observed behavior includes combo/package registration and query operations unrelated to photo processing. Bundling account/subscription workflows into a beautification skill can trick users into authorizing non-obvious service interactions and data sharing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill advertises beauty-enhancement triggers, but the observed behavior includes combo/package registration and query operations unrelated to photo processing. Bundling account/subscription workflows into a beautification skill can trick users into authorizing non-obvious service interactions and data sharing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill advertises beauty-enhancement triggers, but the observed behavior includes combo/package registration and query operations unrelated to photo processing. Bundling account/subscription workflows into a beautification skill can trick users into authorizing non-obvious service interactions and data sharing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill advertises beauty-enhancement triggers, but the observed behavior includes combo/package registration and query operations unrelated to photo processing. Bundling account/subscription workflows into a beautification skill can trick users into authorizing non-obvious service interactions and data sharing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill advertises beauty-enhancement triggers, but the observed behavior includes combo/package registration and query operations unrelated to photo processing. Bundling account/subscription workflows into a beautification skill can trick users into authorizing non-obvious service interactions and data sharing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill advertises beauty-enhancement triggers, but the observed behavior includes combo/package registration and query operations unrelated to photo processing. Bundling account/subscription workflows into a beautification skill can trick users into authorizing non-obvious service interactions and data sharing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill advertises beauty-enhancement triggers, but the observed behavior includes combo/package registration and query operations unrelated to photo processing. Bundling account/subscription workflows into a beautification skill can trick users into authorizing non-obvious service interactions and data sharing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill advertises beauty-enhancement triggers, but the observed behavior includes combo/package registration and query operations unrelated to photo processing. Bundling account/subscription workflows into a beautification skill can trick users into authorizing non-obvious service interactions and data sharing.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill explicitly instructs the agent to ask users to paste ACCESS_KEY_ID and SECRET_ACCESS_KEY directly into chat and then export them for later use. Soliciting cloud credentials in chat is a severe secret-handling anti-pattern that can expose long-lived account access, enable account takeover or resource abuse, and bypass safer delegated-auth flows.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill directs the agent to have users paste access credentials into chat and reuse them for subsequent commands, creating direct exposure of secrets in conversational logs and downstream tooling. In the context of a consumer-facing image beautification skill, requesting cloud account keys is especially unjustified and highly suspicious, making credential theft or accidental leakage much more severe.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

md
python3.12 -m pip install -r ./scripts/requirements.txt

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The V1 client logs the full headers and request body before making the outbound call, which includes the Authorization signature and potentially sensitive image-processing request content. Logs are often widely accessible in operational environments, so this creates a direct credential and data exposure path without needing to compromise the application itself.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The V2 client logs the Bearer token in the Authorization header together with the request body before sending the request. Exposure of a bearer token is especially dangerous because possession alone is sufficient for reuse against the target API until the token expires or is revoked.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code calls IAM ListUsers and selects an admin user ID, then uses owner identities for media operations. For an image beautification skill, enumerating tenant users and implicitly acting under an admin account is unnecessary privilege expansion and can enable unauthorized access to or association with higher-privileged resources if the API credentials permit it.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest says this skill analyzes user-provided images and performs intelligent beauty enhancement, outputting beautified images. This file instead validates arbitrary media, uploads files to a remote material system, and stores metadata in CSV records; there is no image beautification, portrait enhancement, or transformed-image output logic here.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code’s actual behavior is unrelated to the declared image beautification skill: it instantiates a service and calls a remote registration endpoint for an 'Ark Claw' package. This mismatch is dangerous because users or downstream systems may invoke the skill expecting local image processing, while it instead performs an undisclosed account/service registration action over the network.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill declares executable behaviors that involve environment-variable access, filesystem reads/writes, and network activity, but it does not declare any explicit tool scope or allowed-tools boundary. This weakens sandboxing and review because the agent may exercise broader capabilities than users would reasonably expect from an image beautification skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad beauty-related terms likely to appear in ordinary conversation, which raises the likelihood of over-triggering the skill on unintended requests. In context, over-triggering is more dangerous because the skill also invokes networked processing and credential-dependent workflows beyond simple local formatting.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The command set includes a subscription/package query command unrelated to the declared beautification purpose. While not necessarily malicious by itself, it broadens the skill's operational scope into account/service management without clear disclosure, increasing the chance of unintended data access and user confusion.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill processes local image paths, URLs, and archives and may transmit them to remote services, but the description does not clearly warn users about external transfer, archive handling, or privacy implications. This undermines informed consent, especially for personal portrait images that may contain sensitive biometric or identifying information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The file prescribes fixed Chinese response templates and examples for all returned user messages, but does not provide user opt-in for language selection or explain a legitimate region-specific constraint. This can violate language/locale policy when a skill forces one language by default regardless of user preference.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.