Back to skill

Security audit

screenshot-organizer

Security checks for vulnerabilities and agentic risk

Overview

This is a legitimate local screenshot organizer, but it needs review because it can move files and persist searchable OCR text from private screenshots without strong safeguards.

Install only if you are comfortable with local scripts scanning your screenshot folder and creating searchable text records from screenshots. Run report or dry-run modes first, back up the target folder before using --execute, avoid cloud-synced output paths for OCR indexes, and treat generated JSON files as sensitive because they may contain messages, financial details, URLs, emails, and phone numbers.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/screenshot_organizer.py:254
Finding

Silent File Overwrite During Screenshot Organization

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/ocr_extractor.py:365
Finding

Sensitive OCR Data Written to Plaintext Files Without Restrictive Permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill indicates it can move or rename files when executed, but that destructive filesystem behavior is not clearly and prominently declared in the top-level behavior description and may be inferred only from workflow text. In the context of large personal screenshot collections, unclear execute-mode semantics can lead to accidental reorganization, overwrites, loss of user context, or unintended changes in sensitive directories.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill indicates it can move or rename files when executed, but that destructive filesystem behavior is not clearly and prominently declared in the top-level behavior description and may be inferred only from workflow text. In the context of large personal screenshot collections, unclear execute-mode semantics can lead to accidental reorganization, overwrites, loss of user context, or unintended changes in sensitive directories.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding

The skill indicates it can move or rename files when executed, but that destructive filesystem behavior is not clearly and prominently declared in the top-level behavior description and may be inferred only from workflow text. In the context of large personal screenshot collections, unclear execute-mode semantics can lead to accidental reorganization, overwrites, loss of user context, or unintended changes in sensitive directories.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

md
### 1. Deduplication Engine (`scripts/dedup_scanner.py`)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README explicitly promotes OCR extraction, indexing, and entity detection over screenshots, which commonly contain highly sensitive data such as bank transfers, receipts, tracking numbers, chats, emails, and phone numbers. Presenting these capabilities without any privacy warning, consent guidance, retention limits, or secure handling recommendations increases the likelihood that users will process personal or regulated data unsafely and create a searchable sensitive-data index that could be exposed.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill describes capabilities that read from and write to the local filesystem, including generating indexes and moving or renaming screenshot files, but it does not declare any explicit tool scope or permissions. This creates a least-privilege and transparency problem: an agent or reviewer cannot easily bound what file access is intended, increasing the chance of unsafe invocation against sensitive directories or unintended file modification.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The message tells users 'Run without --dry-run to execute,' implying the tool has a real destructive execution mode. However, the 'plan' command only generates and prints a deletion plan and never calls any file-deletion operation, so the inline documentation/output contradicts actual behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest describes organizing screenshots through OCR, tagging, search, deduplication, grouping, and indexing. This file additionally performs structured entity extraction of potentially sensitive data and provides a dedicated command to enumerate those entities, which is a materially broader behavior than simple organization/search.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The extractor writes full OCR text and detected entities for every screenshot to a JSON file, which can persist highly sensitive data such as financial details, messages, emails, and phone numbers. In the context of screenshot organization, users may expect indexing metadata, but this implementation stores raw extracted content wholesale, increasing privacy and disclosure risk if the file is accessed by other local users, backups, or synced storage.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script saves potentially sensitive OCR output and extracted entities to disk without warning, confirmation, or privacy controls. Because screenshots often contain credentials, personal messages, receipts, and account information, silent persistence materially increases the chance of unintended exposure through local compromise, shared machines, or cloud-synced folders.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.