Back to skill

Security audit

Eps

Security checks for vulnerabilities and agentic risk

Overview

This skill is a documented EPS conversion helper that sends user-selected files to a disclosed external API, with no hidden local code or persistence.

Install only if you are comfortable sending selected EPS/PS/EPSF files to eps.futrixdev.com for processing. Avoid uploading confidential, regulated, or proprietary artwork unless you trust that service and its privacy and retention practices.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill instructs users to upload EPS/PS/EPSF files to a third-party service, but it does not clearly warn that complete file contents and embedded metadata are transmitted off-system. EPS/PS files often contain sensitive artwork, document metadata, creator information, and potentially proprietary content, so users may unknowingly disclose confidential data by following the documented workflow.

Static analysis

No suspicious patterns detected.