Back to skill

Security audit

今日水印相机-照片验真

Security checks for vulnerabilities and agentic risk

Overview

This photo-verification skill mostly does what it says, but it can send photo URLs to an external verification API too automatically and a bundled Feishu implementation logs sensitive photo and location data.

Review before installing. This skill sends photo URLs to openapi.xhey.top for verification and may return precise time and location metadata, so do not use it on private, signed, internal, or sensitive image links unless you intend that external processing. Prefer using it only after an explicit verification request, and avoid the bundled Feishu implementation until its sensitive logging and weak default authorization config are removed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:129
Finding

Mandatory Tool Invocation Causes Non-Consensual Disclosure of Photo URLs

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
feishu-trutu-verify/src/index.ts:128
Finding

Sensitive Attachment, Credential Identifier, Context, and Location Data Written to Logs

Content
View full analysis
; groupKey: string; groupSecret: string; }, context, ) => { // 日志工具(每次修改版本号方便定位) function debugLog(arg: any, showContext = false) { if (!showContext) { console.log(JSON.stringify({ arg, logID: context.logID }), '\n'); return; } console.log(JSON.stringify({ formItemParams: { ...formItemParams, groupSecret: '***' }, context, arg }), '\n'); } debugLog('=====trutu-verify=====v1', true); // 封装 fetch:先取 text 再 parse,自动记日志 const safeFetch = async (url: string, init: RequestInit): Promise => { try { const res = await context.fetch(url, init); const resText = await res.text(); debugLog({ [`fetch ${url}`]: resText.slice(0, 2000) }); return JSON.parse(resText); } catch (e) { debugLog({ [`fetch error ${url}`]: String(e) }); throw e; } }; ``` ### Technical Analysis The initial `debugLog(..., true)` serializes all of `formItemParams` after masking only `groupSecret`. The resulting log still contains: - `groupKey`, which is an account or team credential identifier. - Attachment names, sizes, and MIME types. - Temporary attachment URLs. - The complete execution `context`, whose structure and sensitivity are not constrained by this code. - A log correlation identifier. The `safeFetch()` wrapper also logs the first 2,000 characters of every API response. Verification responses can contain the original photo URL, latitude, longitude, capture time, physical address, and anti-fraud code. These values are not redacted before being written to standard output. Masking onl ...[truncated 1959 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
feishu-trutu-verify/config.json:2
Finding

Hardcoded Predictable Plaintext Authorization Credentials

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (35)

Known Vulnerable Dependency: babel-traverse==6.26.0 — 1 advisory(ies): CVE-2023-45133 (Babel vulnerable to arbitrary code execution when compiling specifically crafted)

Critical
Category
Supply Chain
Confidence
90% confidence
Finding

babel-traverse 6.26.0 has a reported arbitrary code execution issue when processing specially crafted input during compilation/transformation. Although this appears in a dev/tooling dependency path, compromise of build or development workflows can still lead to code execution on developer or CI systems, which is a serious supply-chain exposure.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 33)May include surrounding context.

npm install

3. 配置凭证

cp .env.example .env

编辑 .env,填入您的真实 TRUTU_GROUP_KEY 和 TRUTU_GROUP_SECRET

text

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · README.md (reported line 50)May include surrounding context.

-- node /absolute/path/to/Claude_verify/mcp_server.js

text

### 方式二:手动编辑 `~/.claude/settings.json`

```json
{

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill presents itself as narrowly verifying photos, but the documented workflow includes forwarding user-provided URLs to a remote service and supporting asynchronous task creation/polling. While async operation is not inherently unsafe, combining it with claims that no content is forwarded creates a misleading trust boundary and expands the amount of state and identifiers exposed to the vendor. Users may not realize a third-party service receives both access URLs and verification task metadata.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill presents itself as narrowly verifying photos, but the documented workflow includes forwarding user-provided URLs to a remote service and supporting asynchronous task creation/polling. While async operation is not inherently unsafe, combining it with claims that no content is forwarded creates a misleading trust boundary and expands the amount of state and identifiers exposed to the vendor. Users may not realize a third-party service receives both access URLs and verification task metadata.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill presents itself as narrowly verifying photos, but the documented workflow includes forwarding user-provided URLs to a remote service and supporting asynchronous task creation/polling. While async operation is not inherently unsafe, combining it with claims that no content is forwarded creates a misleading trust boundary and expands the amount of state and identifiers exposed to the vendor. Users may not realize a third-party service receives both access URLs and verification task metadata.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill presents itself as narrowly verifying photos, but the documented workflow includes forwarding user-provided URLs to a remote service and supporting asynchronous task creation/polling. While async operation is not inherently unsafe, combining it with claims that no content is forwarded creates a misleading trust boundary and expands the amount of state and identifiers exposed to the vendor. Users may not realize a third-party service receives both access URLs and verification task metadata.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: brace-expansion==2.0.2 — 4 advisory(ies): CVE-2026-13149 (brace-expansion: DoS via exponential-time expansion of consecutive non-expanding); CVE-2026-33750 (brace-expansion: Zero-step sequence causes process hang and memory exhaustion); CVE-2026-14257 (brace-expansion: DoS via unbounded expansion length causing an out-of-memory pro) +1 more

High
Category
Supply Chain
Confidence
91% confidence
Finding

The lockfile includes brace-expansion 2.0.2, which is flagged for multiple denial-of-service issues involving pathological brace patterns that can trigger excessive CPU or memory consumption. Even though this is a transitive dependency and likely only used during tooling or file-matching operations, keeping a known vulnerable version in the dependency graph is a real supply-chain risk.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: axios==1.13.6 — 16 advisory(ies): CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more

High
Category
Supply Chain
Confidence
83% confidence
Finding

Axios 1.13.6 is identified with multiple advisories including SSRF and prototype-pollution-related request handling risks. In this skill context, HTTP requests are core functionality, so a vulnerable HTTP client is more concerning because any weakness in proxy handling, redirects, or polluted configuration objects could affect outbound request integrity or leak credentials.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: brace-expansion==1.1.12 — 4 advisory(ies): CVE-2026-13149 (brace-expansion: DoS via exponential-time expansion of consecutive non-expanding); CVE-2026-33750 (brace-expansion: Zero-step sequence causes process hang and memory exhaustion); CVE-2026-14257 (brace-expansion: DoS via unbounded expansion length causing an out-of-memory pro) +1 more

High
Category
Supply Chain
Confidence
90% confidence
Finding

brace-expansion 1.1.12 is separately present and carries the same class of expansion-based denial-of-service issues as other vulnerable brace-expansion releases. Multiple vulnerable copies in the tree increase the chance that at least one reachable code path remains exploitable even after partial upgrades.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: extract-zip==2.0.1 — 2 advisory(ies): CVE-2026-19693 (extract-zip allows arbitrary file writes through symlink archive entries); CVE-2026-56876 (extract-zip unvalidated symlink path traversal)

High
Category
Supply Chain
Confidence
88% confidence
Finding

extract-zip 2.0.1 is flagged for arbitrary file write and symlink traversal issues during archive extraction. Even as a dev dependency, this is dangerous in developer or CI environments because processing a malicious archive can overwrite files outside the intended directory and potentially enable further compromise.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill sends each attachment's tmp_url to the external service in photoUrlList, which means user-supplied photo resources are disclosed to a third party for processing. This directly contradicts the metadata claim that no image content is retained or forwarded to any third party, creating a significant privacy and transparency issue, especially because signed temporary URLs may grant direct access to the underlying image bytes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

该文档整体以中文编写,且未说明该技能仅面向中文用户或中国大陆合规场景,也未提供其他语言选项。根据规则,若技能在自然语言层面隐含强制特定语言/locale 而无用户选择或明确合理说明,可构成语言/区域政策问题。

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares network access and use of sensitive environment credentials but does not define an explicit permission or allowed-tools scope. That increases the chance of overbroad execution and makes it harder for users or hosts to understand and constrain what the skill can access. In a skill that sends user-supplied photo URLs and handles API secrets, missing scope declarations materially weakens least-privilege controls.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description does not clearly warn users that submitted photo URLs and resulting metadata such as capture time and GPS location will be sent to the vendor for verification. This undermines informed consent for sensitive personal and location data processing. Because photo URLs may reveal or grant access to the image itself, the omission is more dangerous than a minor documentation gap.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The invocation rule requires immediate tool use whenever a user provides a watermark-photo URL, even if the user did not request authenticity verification. That can cause unsolicited transmission of photo URLs and derived metadata to the vendor, creating privacy and consent issues and increasing the chance of unnecessary data disclosure. In a compliance-oriented skill, automatic exfiltration to a remote verifier without a clear user ask is especially problematic.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill requires users to enter a GroupSecret credential, but there is no user-facing warning or explanatory text about its sensitive nature or how it will be used. For code files, access to credentials should have some form of disclosure when no README or inline user warning is present.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code logs broad execution context and verification outputs, including context, form parameters with only groupSecret masked, API responses, and final photo verification results. In this skill, those values can contain sensitive metadata such as temporary photo URLs, timestamps, locations, and operational identifiers, which contradicts the stated no-retention/no-forwarding privacy posture and increases risk of unauthorized internal disclosure through logs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code sends attachment temporary URLs in request bodies to https://openapi.xhey.top for verification, which is a network operation involving user data. While the code logs activity, it does not provide a user-facing disclosure, confirmation, or inline warning that photo data will be sent to an external service.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
76% confidence
Finding

The local domain allowlist only constrains where this skill can send direct HTTP requests, but the code passes arbitrary attachment tmp_url values to the external API, which can then fetch those URLs server-side. This creates an indirect data egress path outside the apparent whitelist boundary and may expose internal or sensitive file URLs to the third-party verifier.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code transmits photo URLs to an external verification API without any visible consent flow or warning in this file, despite the operation involving sensitive user media and potentially location/time-bearing images. In this skill context, photo authenticity verification is legitimate, but silent third-party transfer of user photos and metadata increases privacy risk and can violate user expectations or policy requirements.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The tool sends user-supplied photo URLs to an external service (openapi.xhey.top) as part of verification, but the user-facing tool behavior does not clearly disclose this data transfer at invocation time. Because photo URLs can contain sensitive information, signed links, internal hostnames, or access tokens, undisclosed transmission can cause privacy leaks or unintended sharing with a third party.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Natural-language strings in the server instructions require behavior entirely in Chinese, including a mandated tone for warnings, and the broader tool text is also Chinese-only. The file does not offer language selection or state that the skill is intentionally limited to Chinese-speaking users or a China-specific compliance context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.