Back to skill

Security audit

BitSoul AI Face Beauty 人像AI美颜

Security checks for vulnerabilities and agentic risk

Overview

This skill needs Review because it downloads and runs an external program to edit images, using an insecure token-based download flow.

Install only if you are comfortable running an externally downloaded native program that was not included for review. The publisher should replace the HTTP token exchange, stop putting tokens in URLs, pin and verify the executable, disclose the remote setup behavior prominently, and require explicit user approval before download and execution.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
BitSoulFaceBeautySkill/init.py:31
Finding

Unsigned Remote Native Binary Download and Execution

Content
View full analysis
str: url = f"{BASE_URL}/api/download_file" params = { "file_name": file_name, "token_key": token_key } try: response = requests.get(url, params=params) if response.status_code == 200: data = response.json() download_url = data.get("download_url", "") return download_url else: return "" except Exception as e: print(f"request_download_url error: {e}") return "" def download_data_file(file_name: str, output_path: str, max_retries: int = 3) -> bool: token = get_token() if not token: print("Error: No token set, cannot download data file.") return False for retry in range(max_retries): try: download_url = request_download_url(file_name, token) if not download_url: print(f"Error: Failed to get download url for {file_name}, please check if your token is valid.") return False print(f"Starting to download {file_name} ...") print(f"Download url: {download_url}") with requests.get(download_url, stream=True, timeout=300) as response: if response.status_code != 200: print(f"Download failed, HTTP status code: {response.status_code}") if retry < max_retries - 1: print(f"Retrying {retry + 1}/{max_retries} ...") continue return False total_size = int(response.headers.get('content-length', 0)) downloaded = 0 chunk_size ...[truncated 4899 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
BitSoulFaceBeautySkill/init.py:6
Finding

Authentication Token Transmitted in a Plaintext HTTP Query String

Content
View full analysis
str: url = f"{BASE_URL}/api/download_file" params = { "file_name": file_name, "token_key": token_key } try: response = requests.get(url, params=params) if response.status_code == 200: data = response.json() download_url = data.get("download_url", "") return download_url else: return "" except Exception as e: print(f"request_download_url error: {e}") return "" ``` ### Technical Analysis The authentication token is included in the query parameters of a request made to an `http://` endpoint. HTTP provides neither transport encryption nor server authentication. Anyone able to observe or modify traffic between the runtime and the endpoint can obtain the token and tamper with the response. Placing credentials in a URL also increases exposure because complete URLs are commonly retained by: - Web server access logs. - Forward and reverse proxies. - Network monitoring systems. - Debugging or tracing infrastructure. - HTTP client instrumentation. The initial `requests.get` call also has no explicit timeout, permitting an unresponsive endpoint to hold the initialization process indefinitely. This issue compounds the remote-payload vulnerability: an on-path attacker can both capture the token and modify the plaintext JSON response so that `download_url` points to a malicious executable. ### Attack Path 1. The user sets `BITSOUL_TOKEN` directly or through the configured environment file. 2. Initialization calls `request_download_url`. 3. The token is encoded into a URL similar to: `http://info.aicodingyard.com/ ...[truncated 1121 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (12)

Tainted flow: 'download_url' from os.environ.get (line 58, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
91% confidence
Finding

The code retrieves a download URL from a remote service and then fetches it directly, while the authentication flow is rooted in environment-controlled token input and uses insecure HTTP for the broker service. This creates a dangerous trust chain where a manipulated server response, intercepted traffic, or token misuse can cause the skill to download attacker-controlled content.

Content

Scanner excerpt · BitSoulFaceBeautySkill/init.py (reported line 66)May include surrounding context.

python
print(f"Starting to download {file_name} ...")
            print(f"Download url: {download_url}")

            with requests.get(download_url, stream=True, timeout=300) as response:
                if response.status_code != 200:
                    print(f"Download failed, HTTP status code: {response.status_code}")
                    if retry < max_retries - 1:

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The base service URL uses plain HTTP, and the token is sent as a request parameter when requesting the download URL. This exposes the token to interception and tampering in transit, allowing an attacker on the network path to steal credentials or alter the returned download URL to point to malicious content.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

During initialization, the skill silently downloads a platform-specific executable into the local skill directory if it is missing. A remote binary download at startup is highly dangerous because it introduces a code execution supply-chain path with no integrity verification, provenance enforcement, or sandboxing.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The manifest presents a simple beautification skill, but the instructions reveal materially different behavior: fetching or initializing external software, consuming an auth token, and performing network-dependent installation steps. This mismatch is dangerous because users and orchestrators may grant trust appropriate for image editing while unknowingly allowing software download and execution from an external source.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file claims photos are processed entirely locally and not uploaded, yet it also requires a remote token and directs users to an external service for authorization. Even if images are not uploaded, this is a misleading privacy representation that can cause users to share sensitive photos under false assumptions and obscures the skill's external dependency chain.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill reads an authentication token either from the environment or from an arbitrary file path supplied via an environment variable, then uses it to authorize remote download behavior. This expands the trust boundary and makes secret handling and download control dependent on untrusted local configuration, increasing the chance of secret exposure or abuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill writes a remotely obtained executable to disk during initialization without explicit user consent or a clear warning. In the context of an image beautification skill, this behavior is unexpected and increases user deception and supply-chain risk because users would not reasonably anticipate binary installation as part of simple image processing.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares no explicit tool scope or permission boundaries even though its documented operation requires environment access, file reads, shell execution, and network activity. That increases the chance an agent invokes powerful capabilities without clear policy constraints or user awareness, especially because the skill also runs an external executable and initialization script.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is described as beautifying faces or portraits, but its documented parameters include body-shaping functions such as chest, waist, legs, arms, hips, and full-body slimming. This scope expansion is risky because it can surprise users, trigger the skill for broader image-editing tasks than intended, and increase misuse potential around deceptive or sensitive body modification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The invocation guidance is broad enough to match many ordinary image-processing requests, which can cause over-selection of this skill in contexts where users did not ask for beautification or where safer tools would suffice. Because this skill also carries hidden network and execution behaviors, ambiguous routing raises the risk of unintended activation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The markdown emphasizes safety and local processing but omits a prominent warning that token-based remote verification is involved. This omission undermines informed consent and can lead users or agents to operate the skill without understanding its external trust and privacy implications.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

A substantial portion of the skill description and operating guidance is presented only in Chinese, with no indication that the user can choose language or locale. This may violate language/locale policy expectations where skills should not force a specific language without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.