Back to skill

Security audit

Byted Kickart Saliency Segmenter

Security checks for vulnerabilities and agentic risk

Overview

This image cutout skill performs the expected remote image workflow, but it also exposes cloud credentials, can execute server-supplied update commands, logs authorization data, and mutates account/package state with weak user control.

Only install this after the publisher removes chat-based secret collection, stops printing or logging credentials, pins or locks dependencies, constrains update execution to a verified updater, documents the account registration behavior, and limits API credentials to least-privilege scopes. Do not paste cloud AK/SK secrets into chat for this skill.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:74
Finding

Execution of a Server-Controlled Update Command

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:29
Finding

Disclosure of Long-Lived Credentials Through Chat and Command Output

Content
View full analysis
export SECRET_ACCESS_KEY= ``` ### Technical Analysis The mandatory authentication check prints complete API credentials and cloud access keys rather than testing only whether they are configured. It also uses the chat channel as a secret-input mechanism. Chat transcripts and tool output are commonly retained in conversation history, execution logs, telemetry systems, debugging records, or audit platforms. Consequently, credentials can remain exposed beyond the intended session even if the environment variables themselves are temporary. Embedding a secret directly in an `export` command can also disclose it through shell history, process instrumentation, command auditing, or captured tool invocations. ### Attack Path 1. A user invokes the Skill without preconfigured authentication. 2. The Skill requests long-lived cloud credentials in the chat. 3. The user sends the access key and secret key as plaintext. 4. The credentials become part of the retained conversation and agent context. 5. The preflight command prints configured credential values into command output. 6. A person or system with access to transcripts, telemetry, logs, or tool records recovers the credentials. 7. The recovered credentials are used to authenticate to permitted cloud services. ### Impact Assessment The obtainable privileges are those assigned to the exposed bearer token or AK/SK ...[truncated 484 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/core/api/meida/chunks.py:116
Finding

Authentication Headers and Sensitive Request Data Written to Logs

Content
View full analysis
>> {method.upper()} {url} {headers} {body}") response = requests.request( method=method.upper(), url=url, headers=headers, data=body, timeout=30 ) logging.info(f"<<< {response.headers} {response.text}") ``` The bearer-token ICCP client repeats the same behavior: ```python logging.info(f">>> {method.upper()} {url} {headers} {body}") response = requests.request( method=method.upper(), url=url, headers=headers, data=body, timeout=30 ) logging.info(f"<<< {response.headers} {response.text}") ``` The logged header dictionaries contain one of the following authorization values: ```python "Authorization": f"Bearer {self.token}" ``` ```python headers["Authorization"] = authorization ``` ### Technical Analysis The HTTP clients serialize complete request headers into informational logs. In bearer-token mode, this directly records the reusable plaintext API token. In AK/SK mode, it records credential identifiers, signing scope, signed headers, and request signatures. The clients also log complete request bodies and response bodies. These may contain image URLs, task identifiers, media identifiers, account information, processing results, and other user-related data. Informational logs are often enabled in normal deployments and may be forwarded to centralized collectors. Logging credentials therefore expands secret access from the active proc ...[truncated 1228 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/core/api/meida/chunks.py:168
Finding

Bearer Token and User Media Can Be Sent to an Untrusted Environment-Controlled Host

Content
View full analysis
Dict[str, str]: return { "ServiceName": service, "Authorization": f"Bearer {self.token}", "Content-Type": "application/octet-stream" if is_binary else "application/json", } ``` From the ICCP client: ```python def __init__(self): self.addr = os.getenv("ARK_SKILL_API_BASE") self.token = os.getenv("ARK_SKILL_API_KEY") or "" def do_request(self, method: str, queries: dict, body: bytes, action: str) -> dict: queries["Action"] = action queries["Version"] = self.VERSION query_string = urlencode(queries).replace("+", "%20") url = f"{self.addr}?{query_string}" headers = defaultdict(str) headers["Authorization"] = f"Bearer {self.token}" headers["Content-Type"] = "application/json" headers["ServiceName"] = V2IccpClient.SERVICE ``` ### Technical Analysis The destination host is taken directly from `ARK_SKILL_API_BASE`. The client does not verify that: - The scheme is HTTPS. - The hostname belongs to an approved Volcengine or Ark domain. - The URL has no embedded user information. - The port is expected. - The destination is not an IP literal or local-network endpoint. - Redirects remain on the trusted origin. The same client attaches the bearer token to requests sent to that destination. The binary upload path also ...[truncated 1484 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/requirements.txt:1
Finding

Mandatory Installation of Unpinned and Open-Ended Dependencies

Content
View full analysis
=2.31.0 qrcode>=8.2 jsonpath>=0.82.2 Pillow>=10.1.0 urllib3>=2.1.0 pydantic==2.12.5 pandas==2.3.3 python-dotenv>=1.1.1 click>=8.3.2 ``` ### Technical Analysis An open-ended `>=` constraint allows any later package release satisfying the minimum version. The exact code installed during future Skill executions can therefore differ from the code present during the audit. No artifact hashes, lock file, trusted package-index configuration, or transitive dependency pins are provided. Python package installation may execute build backends or package setup behavior, and imported dependencies execute with the agent's privileges. Because installation is part of the mandatory preflight workflow, exposure occurs even before the core image-segmentation operation. The manifest also includes dependencies whose necessity is not apparent in the reviewed primary workflow, unnecessarily increasing supply-chain attack surface. ### Attack Path 1. A direct or transitive dependency account, release process, or package index is compromised. 2. A malicious later version is published while still satisfying an open-ended version constraint. 3. The user invokes the Skill. 4. The mandatory preflight runs `pip install`. 5. The resolver selects and installs the malicious or compromised release. 6. Malicious code executes during installation or when the package is imported. 7. The code gains access to the same files, environment variables, credentials, and network resources available to the Skill. ### Impact Assessment A compromised dependency can execute arbitrar ...[truncated 500 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (86)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Uploading images, validating size/resolution, and extracting metadata are substantial behaviors not equivalent to performing segmentation itself. Without clear disclosure and consent, users may expose private media to remote services while the advertised core function is absent or secondary.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Uploading images, validating size/resolution, and extracting metadata are substantial behaviors not equivalent to performing segmentation itself. Without clear disclosure and consent, users may expose private media to remote services while the advertised core function is absent or secondary.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Uploading images, validating size/resolution, and extracting metadata are substantial behaviors not equivalent to performing segmentation itself. Without clear disclosure and consent, users may expose private media to remote services while the advertised core function is absent or secondary.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Uploading images, validating size/resolution, and extracting metadata are substantial behaviors not equivalent to performing segmentation itself. Without clear disclosure and consent, users may expose private media to remote services while the advertised core function is absent or secondary.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Uploading images, validating size/resolution, and extracting metadata are substantial behaviors not equivalent to performing segmentation itself. Without clear disclosure and consent, users may expose private media to remote services while the advertised core function is absent or secondary.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Uploading images, validating size/resolution, and extracting metadata are substantial behaviors not equivalent to performing segmentation itself. Without clear disclosure and consent, users may expose private media to remote services while the advertised core function is absent or secondary.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Uploading images, validating size/resolution, and extracting metadata are substantial behaviors not equivalent to performing segmentation itself. Without clear disclosure and consent, users may expose private media to remote services while the advertised core function is absent or secondary.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Uploading images, validating size/resolution, and extracting metadata are substantial behaviors not equivalent to performing segmentation itself. Without clear disclosure and consent, users may expose private media to remote services while the advertised core function is absent or secondary.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Uploading images, validating size/resolution, and extracting metadata are substantial behaviors not equivalent to performing segmentation itself. Without clear disclosure and consent, users may expose private media to remote services while the advertised core function is absent or secondary.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Uploading images, validating size/resolution, and extracting metadata are substantial behaviors not equivalent to performing segmentation itself. Without clear disclosure and consent, users may expose private media to remote services while the advertised core function is absent or secondary.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Uploading images, validating size/resolution, and extracting metadata are substantial behaviors not equivalent to performing segmentation itself. Without clear disclosure and consent, users may expose private media to remote services while the advertised core function is absent or secondary.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instructions direct the agent to reveal, collect, and reuse sensitive credentials without adequate safety warnings or secure handling. In context, this is highly dangerous because a benign-seeming image task becomes a mechanism for harvesting cloud secrets and propagating them into shell commands and logs.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill explicitly instructs the agent to ask users to paste ACCESS_KEY_ID and SECRET_ACCESS_KEY directly into chat and then export them into the shell environment. Collecting long-lived cloud credentials in conversational text is a severe secret-handling flaw because they can be logged, retained, replayed, or exposed to other tooling, enabling compromise of the user's cloud account.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill tells the agent to have users paste AK/SK secrets into chat and then reuse those secrets in subsequent commands. This creates a direct path for credential theft, accidental logging, replay, and privilege abuse, and is especially severe because it is unnecessary for a normal user-facing image cutout workflow.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

md
python3.12 -m pip install -r ./scripts/requirements.txt

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code explicitly logs headers and body for outbound HTTP requests, and those headers include HMAC authorization material in V1 and bearer tokens in V2. Anyone with log access could replay or abuse credentials and inspect user-submitted content, making this a direct confidentiality and possible account-compromise issue.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code calls IAM ListUsers and selects an admin user ID to act as the owner for later media operations, which is unrelated to simple image cutout. This unnecessarily grants the workflow access to privileged identity data and risks performing uploads or asset creation under an administrator context, increasing blast radius if the skill is abused or compromised.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill’s declared purpose is image saliency segmentation/background removal, but the implementation instead instantiates a service and calls RegisterArkClawCombo over the network. This is a strong functionality mismatch that can cause unauthorized account/package registration under the guise of an unrelated image-processing action, making the behavior deceptive and potentially abusive.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill declares broad capabilities to read environment variables, access files, write output, and make network requests, but does not constrain them with an explicit tool scope. In a skill that handles user-supplied file paths, URLs, and credentials, missing scope boundaries increases the chance of unintended secret access, arbitrary file handling, or network exfiltration beyond the stated task.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger definition uses broad keyword matching and 'equivalent intent' language, causing the skill to activate in loosely related contexts. Because the skill can access files, network resources, and credentials, overbroad triggering increases the risk of invoking sensitive behavior without clear user intent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation expands the skill from image cutout into account/package checks, upgrade execution, and credential onboarding. This broadening is risky because it mixes sensitive account administration and software maintenance into a content-processing workflow, increasing opportunities for credential mishandling and unintended code execution.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill includes a self-update flow that may execute an install_command returned from a remote version-check response. Executing installation commands supplied by a network service is effectively remote code execution, and in this context it is unrelated to the user's image-editing request.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The client reads ACCESS_KEY_ID and SECRET_ACCESS_KEY from environment variables to authenticate outbound requests, and the alternate client reads ARK_SKILL_API_KEY as a bearer token. This is sensitive credential access, but the file provides no confirmation, warning comment, or user-facing notice explaining that credentials will be consumed for remote API calls.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Both client implementations log full request metadata and bodies before transmission, and full response headers and bodies after transmission. This can expose Authorization credentials, bearer tokens, signed headers, image-related payloads, and possibly returned sensitive data to application logs, which are often widely accessible and retained longer than intended.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Both client implementations send request bodies to external HTTP endpoints using requests.request, which can include user or system data. The file contains no confirmation prompt, warning comment, or explanatory docstring to disclose that data will be sent off-host.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.