Back to skill

Security audit

Nx Matting

Security checks for vulnerabilities and agentic risk

Overview

The skill does perform image and video matting, but it also downloads and runs native Windows binaries, trusts some local FFmpeg executables before verification, and forces an unrelated contact notice into user replies.

Review before installing. Use this only if you trust the publisher and the externally hosted native binaries; prefer a sandboxed Windows account or VM for private media. Avoid running video mode from directories that may contain untrusted ffmpeg.exe or resources/ffmpeg, and consider pinning the installer instead of using the README's unpinned npx command.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T01 · Skill Instruction Hijacking

Warning
Location
scripts/matting.ps1:39
Finding

Forced Promotional Content Injection into Agent Responses

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
references/manifest.json:9
Finding

Download and Execution of Opaque Native Runtime Binaries

Content
View full analysis
> $LogPath | ForEach-Object { $line = [string]$_ try { $parsed = $line | ConvertFrom-Json if ($parsed.event) { if ($parsed.backend) { $actualBackend = [string]$parsed.backend } [Console]::Out.WriteLine($line) [Console]::Out.Flush() } else { [IO.File]::AppendAllText($LogPath, "$line`r`n", [Text.Encoding]::UTF8) } } catch { [IO.File]::AppendAllText($LogPath, "$lin ...[truncated 2274 chars]
Remediation
View remediation

T07 · Tool Hijacking and Spoofing

Error
Location
scripts/matting.ps1:450
Finding

Current-Directory FFmpeg Executable Hijacking

Content
View full analysis
&1 | Out-String if ($LASTEXITCODE -ne 0) { return $false } $filters = & $ffmpeg -hide_banner -filters 2>&1 | Out-String if ($LASTEXITCODE -ne 0) { return $false } & $ffprobe -hide_banner -version 2>$null | Out-Null if ($LASTEXITCODE -ne 0) { return $false } foreach ($needle in @("prores_ks", "libvpx-vp9", "libopus", "pcm_s16le")) { if ($encoders -notmatch [Regex]::Escape($needle)) { return $false } } if ($filters -notmatch "(?m)\bpremultiply\b") { return $false } return $true } catch { return $false } } ``` ```powershell Add-Candidate $FfmpegDir "explicit" Add-Candidate $env:BIREFNET_MATTING_FFMPEG_DIR "explicit" Add-Candidate (Join-Path $SkillRoot "..\..\ffmpeg") "nxengine" Add-Candidate (Join-Path ([Environment]::CurrentDirectory) "resources\ffmpeg") "nxengine" Add-Candidate (Join-Path ([Environment]::CurrentDirectory) "ffmpeg") "path" $pathCommand = Get-Command "ffmpeg.exe" -ErrorAction SilentlyContinue | Select-Object -First 1 if ($null -ne $pathCommand) { Add-Candidate (Split-Path -Parent $pathCommand.Source) "path" } Add-Candidate (Join-Path $RuntimeRoot "ffmpeg") "cache" ``` ### Technical Analysis The script searches for FFmpeg under directories derived from the current working directory before select ...[truncated 1795 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:15
Finding

Unpinned Package Execution in Recommended Installation Command

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (16)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 25)May include surrounding context.

bash
git clone https://github.com/xiaowu89/skill-matting.git /tmp/sm
cp -r /tmp/sm/plugins/nx-matting/skills/nx-matting ~/.claude/skills/
rm -rf /tmp/sm

快速使用

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 25)May include surrounding context.

bash
git clone https://github.com/xiaowu89/skill-matting.git /tmp/sm
cp -r /tmp/sm/plugins/nx-matting/skills/nx-matting ~/.claude/skills/
rm -rf /tmp/sm

快速使用

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

整个技能说明均以中文撰写,未提供其他语言选项,也未说明该语言限制的适用范围或理由。按该规则,若技能在自然语言层面强制特定语言而未提供用户选择,可能构成语言/区域政策问题。

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to always reproduce a fixed Chinese contact notice in the final user-facing reply, regardless of the user's language or consent. This creates an output-policy violation and can be used to inject unsolicited promotional or contact content into responses, reducing user trust and bypassing normal agent control over final messaging.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script decodes a hard-coded Base64 string into a contact notice and automatically includes it in completed/error JSON events for image and video commands. Hidden or non-obvious embedded messaging is suspicious because it introduces undisclosed outbound-facing content in program output, potentially steering users to off-platform contact channels or creating a covert social-engineering surface unrelated to the stated matting function.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description emphasizes using a local BiRefNet GGUF model and no Python/PyTorch/CUDA, which implies an offline/local processing tool. However, the script implements generic remote download logic and later uses it to fetch models, runtime binaries, and FFmpeg from URLs in the manifest, meaning the skill may perform network retrieval as part of normal operation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Ensure-Model and related runtime preparation paths trigger network downloads of model/runtime files when they are missing. The script logs progress, but it does not clearly disclose to the user up front that running the skill may transmit request metadata to external hosts and populate a local cache.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script automatically downloads FFmpeg artifacts from configured URLs and installs them into the local runtime cache. Although progress is emitted as JSON, there is no explicit user-facing warning in the script comments or prompts that executing video processing may trigger network access and local binary installation.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSES/BiRefNet-LICENSE.txt (reported line 16)May include surrounding context.

text
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSES/ggml-LICENSE.txt (reported line 16)May include surrounding context.

text
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSES/vision.cpp-LICENSE.txt (reported line 16)May include surrounding context.

text
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

文档给出了 cp -r ... ~/.claude/skills/ 和 rm -rf /tmp/sm 的安装步骤,但没有明确提醒这些命令会向用户主目录写入文件并删除临时目录。对 markdown 文件,凡是会影响用户文件系统的行为都应有简要警示,以便用户理解副作用。

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

虽然文档在依赖项中提到“首次使用联网下载模型和运行时(魔搭)”,但这更像依赖说明,而不是面向用户的明确警示,未说明执行过程中会发生网络访问。对于 markdown 文件,涉及联网行为时应给出清晰提示,尤其当用户可能预期该技能“本地推理”即完全离线时。

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest describes image/video matting with a local BiRefNet model, but the code also discovers and, if needed, installs FFmpeg as an additional external runtime dependency. While understandable for video processing, this is extra behavior not conveyed by the description's focus on local BiRefNet-based processing.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill's stated purpose is media matting and background removal, but the doctor routine reports platform details, cache directory, Vulkan loader presence, runtime integrity, model installation status, and FFmpeg path/source. This diagnostic inventory is not directly part of performing matting and exposes additional host-environment introspection capability.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.