T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:74- Finding
Execution of a Server-Controlled Update Command
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This image cutout skill performs the expected remote image workflow, but it also exposes cloud credentials, can execute server-supplied update commands, logs authorization data, and mutates account/package state with weak user control.
Only install this after the publisher removes chat-based secret collection, stops printing or logging credentials, pins or locks dependencies, constrains update execution to a verified updater, documents the account registration behavior, and limits API credentials to least-privilege scopes. Do not paste cloud AK/SK secrets into chat for this skill.
SKILL.md:74Execution of a Server-Controlled Update Command
SKILL.md:29Disclosure of Long-Lived Credentials Through Chat and Command Output
scripts/core/api/meida/chunks.py:116Authentication Headers and Sensitive Request Data Written to Logs
scripts/core/api/meida/chunks.py:168Bearer Token and User Media Can Be Sent to an Untrusted Environment-Controlled Host
scripts/requirements.txt:1Mandatory Installation of Unpinned and Open-Ended Dependencies
Uploading images, validating size/resolution, and extracting metadata are substantial behaviors not equivalent to performing segmentation itself. Without clear disclosure and consent, users may expose private media to remote services while the advertised core function is absent or secondary.
Uploading images, validating size/resolution, and extracting metadata are substantial behaviors not equivalent to performing segmentation itself. Without clear disclosure and consent, users may expose private media to remote services while the advertised core function is absent or secondary.
Uploading images, validating size/resolution, and extracting metadata are substantial behaviors not equivalent to performing segmentation itself. Without clear disclosure and consent, users may expose private media to remote services while the advertised core function is absent or secondary.
Uploading images, validating size/resolution, and extracting metadata are substantial behaviors not equivalent to performing segmentation itself. Without clear disclosure and consent, users may expose private media to remote services while the advertised core function is absent or secondary.
Uploading images, validating size/resolution, and extracting metadata are substantial behaviors not equivalent to performing segmentation itself. Without clear disclosure and consent, users may expose private media to remote services while the advertised core function is absent or secondary.
Uploading images, validating size/resolution, and extracting metadata are substantial behaviors not equivalent to performing segmentation itself. Without clear disclosure and consent, users may expose private media to remote services while the advertised core function is absent or secondary.
Uploading images, validating size/resolution, and extracting metadata are substantial behaviors not equivalent to performing segmentation itself. Without clear disclosure and consent, users may expose private media to remote services while the advertised core function is absent or secondary.
Uploading images, validating size/resolution, and extracting metadata are substantial behaviors not equivalent to performing segmentation itself. Without clear disclosure and consent, users may expose private media to remote services while the advertised core function is absent or secondary.
Uploading images, validating size/resolution, and extracting metadata are substantial behaviors not equivalent to performing segmentation itself. Without clear disclosure and consent, users may expose private media to remote services while the advertised core function is absent or secondary.
Uploading images, validating size/resolution, and extracting metadata are substantial behaviors not equivalent to performing segmentation itself. Without clear disclosure and consent, users may expose private media to remote services while the advertised core function is absent or secondary.
Uploading images, validating size/resolution, and extracting metadata are substantial behaviors not equivalent to performing segmentation itself. Without clear disclosure and consent, users may expose private media to remote services while the advertised core function is absent or secondary.
The instructions direct the agent to reveal, collect, and reuse sensitive credentials without adequate safety warnings or secure handling. In context, this is highly dangerous because a benign-seeming image task becomes a mechanism for harvesting cloud secrets and propagating them into shell commands and logs.
The skill explicitly instructs the agent to ask users to paste ACCESS_KEY_ID and SECRET_ACCESS_KEY directly into chat and then export them into the shell environment. Collecting long-lived cloud credentials in conversational text is a severe secret-handling flaw because they can be logged, retained, replayed, or exposed to other tooling, enabling compromise of the user's cloud account.
The skill tells the agent to have users paste AK/SK secrets into chat and then reuse those secrets in subsequent commands. This creates a direct path for credential theft, accidental logging, replay, and privilege abuse, and is especially severe because it is unnecessary for a normal user-facing image cutout workflow.
Referenced artifact was not completely inspected
python3.12 -m pip install -r ./scripts/requirements.txt
The code explicitly logs headers and body for outbound HTTP requests, and those headers include HMAC authorization material in V1 and bearer tokens in V2. Anyone with log access could replay or abuse credentials and inspect user-submitted content, making this a direct confidentiality and possible account-compromise issue.
The code calls IAM ListUsers and selects an admin user ID to act as the owner for later media operations, which is unrelated to simple image cutout. This unnecessarily grants the workflow access to privileged identity data and risks performing uploads or asset creation under an administrator context, increasing blast radius if the skill is abused or compromised.
The skill’s declared purpose is image saliency segmentation/background removal, but the implementation instead instantiates a service and calls RegisterArkClawCombo over the network. This is a strong functionality mismatch that can cause unauthorized account/package registration under the guise of an unrelated image-processing action, making the behavior deceptive and potentially abusive.
The skill declares broad capabilities to read environment variables, access files, write output, and make network requests, but does not constrain them with an explicit tool scope. In a skill that handles user-supplied file paths, URLs, and credentials, missing scope boundaries increases the chance of unintended secret access, arbitrary file handling, or network exfiltration beyond the stated task.
The trigger definition uses broad keyword matching and 'equivalent intent' language, causing the skill to activate in loosely related contexts. Because the skill can access files, network resources, and credentials, overbroad triggering increases the risk of invoking sensitive behavior without clear user intent.
The documentation expands the skill from image cutout into account/package checks, upgrade execution, and credential onboarding. This broadening is risky because it mixes sensitive account administration and software maintenance into a content-processing workflow, increasing opportunities for credential mishandling and unintended code execution.
The skill includes a self-update flow that may execute an install_command returned from a remote version-check response. Executing installation commands supplied by a network service is effectively remote code execution, and in this context it is unrelated to the user's image-editing request.
The client reads ACCESS_KEY_ID and SECRET_ACCESS_KEY from environment variables to authenticate outbound requests, and the alternate client reads ARK_SKILL_API_KEY as a bearer token. This is sensitive credential access, but the file provides no confirmation, warning comment, or user-facing notice explaining that credentials will be consumed for remote API calls.
Both client implementations log full request metadata and bodies before transmission, and full response headers and bodies after transmission. This can expose Authorization credentials, bearer tokens, signed headers, image-related payloads, and possibly returned sensitive data to application logs, which are often widely accessible and retained longer than intended.
Both client implementations send request bodies to external HTTP endpoints using requests.request, which can include user or system data. The file contains no confirmation prompt, warning comment, or explanatory docstring to disclose that data will be sent off-host.
No suspicious patterns detected.