Back to skill

Security audit

vision-fallback

Security checks for vulnerabilities and agentic risk

Overview

This image fallback skill has a coherent purpose, but it can send sensitive image data and API credentials to configurable endpoints with insufficient safeguards.

Install only if you are comfortable sending image contents, OCR text, and prior model output to the configured vision provider. Use HTTPS-only endpoints, avoid running it with elevated privileges, do not rely on `/root/.env_vars`, prefer explicit `VISION_API_KEY` or a user-owned env file, and pin or review the installer version before using the documented `npx` path.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T08 · Insecure Dependencies

Warning
Location
README.md:36
Finding

Unpinned Third-Party Package Execution During Installation

Content
View full analysis
Remediation
View remediation
add vst93/vision-fallback-skill ``` 2. Document the expected package publisher, version, and integrity hash. 3. Prefer installation through a lockfile-backed package manager workflow where feasible. 4. Provide a verified manual installation option using a signed release archive or a commit-specific repository URL. 5. Recommend reviewing installer changes before upgrading to newer versions. 6. If the installer supports signature or checksum verification, require that verification in the documented workflow. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
scripts/call-api.sh:99
Finding

Bearer Credentials and Sensitive Vision Data Can Be Sent Over Plaintext HTTP

Content
View full analysis
Remediation
View remediation
&2 exit 1 } ;; *) echo "ERROR: VISION_BASE_URL must use HTTPS" >&2 exit 1 ;; esac ``` 2. Restrict curl protocols for ordinary remote calls: ```bash curl --proto '=https' --tlsv1.2 ... ``` 3. If local HTTP endpoints such as vLLM must be supported, allow only loopback addresses and require a clearly named explicit opt-in. 4. Validate the URL with a robust parser rather than relying only on shell pattern matching. 5. Document that images, OCR text, prior model output, and credentials are transmitted to the configured provider. 6. Warn users that custom endpoints receive the selected API key and all submitted content. 7. Consider endpoint allowlisting or requiring user confirmation when sending credentials to a non-default hostname. ]]>

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/resolve-config.sh:83
Finding

Automatic Root Credential-File Lookup Exceeds Least-Privilege Requirements

Content
View full analysis
/dev/null | \ head -1 | \ sed -E "s/^\s*${key}=//; s/^\"(.*)\"$/\1/; s/^'(.*)'$/\1/" } # Check VISION_API_KEY first _val="$(_parse_env "$f" VISION_API_KEY)" if [ -n "$_val" ]; then VF_API_KEY="$_val" VF_KEY_SOURCE="$f:VISION_API_KEY" break fi # Then provider-specific _val="$(_parse_env "$f" "$KEY_ENV")" if [ -n "$_val" ]; then VF_API_KEY="$_val" VF_KEY_SOURCE="$f:$KEY_ENV" break fi done ``` Equivalent root-path lookup is duplicated in `scripts/check.sh`. ### Technical Analysis The scripts automatically inspect `/root/.env_vars` regardless of whether `/root` is the current user's home directory. Accessing the current user's configured dotenv file or an explicitly selected `VISION_ENV_FILE` is sufficient for the Skill's functionality. An unconditional absolute root fallback is therefore broader than the minimum necessary access scope. The parser limits extraction to provider and vision-related keys and does not source or execute the file. No evidence was found that it searches for unrelated credentials. However, when the Skill runs with sufficient permissions—or when `/root/.env_vars` has unsafe permissions—it can silently select a root-owned API credential without the operator explicitly choosing that file. Because `VISION_BASE_URL`, `VISION_PROVIDER`, and `VISION_MODEL` are also pre-parsed from the same file list elsewhere in both scripts, a root dotenv file m ...[truncated 1381 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (20)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a complete image-understanding skill that invokes a vision API and returns structured results. The supplied code chunk is only a support/configuration script for selecting provider settings and resolving credentials. While this behavior may be part of implementing such a skill, by itself it does not match the claimed primary purpose because it neither accepts images nor calls any model endpoint nor returns analysis output. It also accesses local dotenv files to obtain configuration and API keys, which is an implementation/resource access detail absent from the description. Therefore this code chunk materially differs from the declared end-user functionality.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill routes images, OCR text, failure reasons, and model outputs to an external vision API, but the description does not prominently warn users that potentially sensitive image content and context will leave the local environment. This creates a material privacy and data-governance risk, especially for screenshots, IDs, medical images, or internal documents.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
./scripts/check.sh

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

md
./scripts/check.sh

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

md
./scripts/check.sh

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README explicitly states that the skill sends images, OCR text, and prior model output to an OpenAI-compatible third-party vision API, but it does not prominently warn that these inputs may contain sensitive data and will leave the local environment. In the context of agent skills handling screenshots, terminal output, and app UIs, this increases the risk of unintended disclosure of secrets, personal data, or proprietary information to external providers.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.zh-CN.md (reported line 38)May include surrounding context.

npx skills add vst93/vision-fallback-skill

text

> ℹ️ `npx skills add` 会安装到对应工具的 skill 目录(如 `~/.claude/skills/`)。
> 其他工具如果扫描不同路径则不会自动发现——参见下方的专项说明。

### ClawHub

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.zh-CN.md (reported line 38)May include surrounding context.

npx skills add vst93/vision-fallback-skill

text

> i️ `npx skills add` 会安装到对应工具的 skill 目录(如 `~/.claude/skills/`)。
> 其他工具如果扫描不同路径则不会自动发现——参见下方的专项说明。

### ClawHub

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill invokes shell scripts and relies on environment-provided credentials, but the manifest does not declare any tool scope or permission boundaries. That makes the skill harder to safely govern and review, and can lead to unintended shell or environment access when the agent executes it.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger language is broad enough to encourage automatic use whenever an image 'must be understood' or when the model appears uncertain. In practice, that can cause unnecessary transmission of images and associated context to an external provider without a narrowly scoped user-approved decision point.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 96)May include surrounding context.

If image is already an http(s):// URL or a data: URL, use it directly.

Minimal curl example

bash
curl -sS "$VF_ENDPOINT" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/call-api.sh (reported line 99)May include surrounding context.

sh
# --- POST ---
# SECURITY: $VF_API_KEY is the resolved key from resolve-config.sh.
# It is never logged or echoed - only used in the Authorization header.
curl -sS "$VF_ENDPOINT" \
  -H "Authorization: Bearer $VF_API_KEY" \
  -H "Content-Type: application/json" \
  -d "$PAYLOAD"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 11)May include surrounding context.

md
KEY_ENV="ARK_API_KEY"
    ;;
  openai)
    : "${VISION_BASE_URL:=https://api.openai.com/v1}"
    : "${VISION_MODEL:=gpt-4o-mini}"
    KEY_ENV="OPENAI_API_KEY"
    ;;

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/configuration.md (reported line 10)May include surrounding context.

md
KEY_ENV="ARK_API_KEY"
    ;;
  openai)
    : "${VISION_BASE_URL:=https://api.openai.com/v1}"
    : "${VISION_MODEL:=gpt-4o-mini}"
    KEY_ENV="OPENAI_API_KEY"
    ;;

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/check.sh (reported line 82)May include surrounding context.

sh
KEY_ENV="ARK_API_KEY"
    ;;
  openai)
    : "${VISION_BASE_URL:=https://api.openai.com/v1}"
    : "${VISION_MODEL:=gpt-4o-mini}"
    KEY_ENV="OPENAI_API_KEY"
    ;;

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/resolve-config.sh (reported line 47)May include surrounding context.

sh
KEY_ENV="ARK_API_KEY"
    ;;
  openai)
    : "${VISION_BASE_URL:=https://api.openai.com/v1}"
    : "${VISION_MODEL:=gpt-4o-mini}"
    KEY_ENV="OPENAI_API_KEY"
    ;;

Static analysis

No suspicious patterns detected.