Back to skill

Security audit

TencentCloud FaceID CompareFace

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says: it compares two face images through Tencent Cloud, with privacy-sensitive cloud processing that users should understand before use.

Install only if you are comfortable sending the selected face images or image URLs to Tencent Cloud for biometric comparison, and use it only with appropriate consent and lawful authority. Provide Tencent Cloud credentials with the minimum permissions needed for this API and avoid using sensitive third-party faces unless the privacy and compliance implications are clear.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill requires access to environment variables containing Tencent Cloud credentials, but it does not declare any explicit tool scope or permissions boundary. This creates an unnecessary trust gap: an agent or reviewer cannot easily verify what sensitive resources the skill expects to access, increasing the risk of over-privileged execution or unintended secret exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This skill processes highly sensitive biometric data by sending face images or image URLs to a third-party cloud face recognition service, yet it provides no privacy warning, consent guidance, retention notice, or handling limitations. In context, this is more dangerous than ordinary image processing because biometric comparison can expose immutable personal identifiers and may violate privacy, compliance, or user-expectation boundaries if used without explicit informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script sends highly sensitive biometric data (face images or their URLs) to Tencent Cloud for remote processing, but it provides no explicit runtime notice, consent prompt, or data-handling warning to the user. In the context of a face-comparison skill, this matters because users may not realize their images are transmitted to a third-party cloud service, creating privacy, compliance, and trust risks rather than a code-execution flaw.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

All user-facing docstrings, help text, warnings, and output descriptions are in Chinese, which effectively forces a specific language for interaction. There is no opt-in, alternate locale, or documented justification that this tool is intended only for a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.