Back to skill

Security audit

Long Image Slicer

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently processes user-supplied long images into slices and PDFs, with ordinary file and dependency risks users should control.

Install in an isolated virtual environment, review or pin dependency versions, and only provide trusted image URLs or local paths. Choose an output directory where generated JPG, ZIP, DOCX, and PDF files can be written without overwriting important files.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:80
Finding

Unpinned Third-Party Dependencies Installed from an Uncontrolled Package Index

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 80 and 94
Vulnerability Type: Unpinned and unverifiable third-party dependencies
Risk Level: Medium

Vulnerable Code

bash
pip3 install Pillow numpy python-docx
bash
pip3 install reportlab

Technical Analysis

The installation instructions retrieve third-party packages without version constraints, cryptographic hashes, a lock file, or an explicitly trusted package index. Package versions and their transitive dependencies can therefore change independently of the reviewed Skill.

When an operator follows these instructions, pip resolves mutable package artifacts from its configured index. A compromised package release, compromised package index, dependency-confusion condition, or malicious transitive dependency could introduce code that was not included in this audit. Python packages can execute code during installation and subsequently when imported by scripts/slice_processor.py or scripts/create_pdf.py.

The audited scripts import these dependencies directly:

  • Pillow through PIL
  • numpy
  • python-docx through docx
  • reportlab

This finding does not establish that any currently published dependency is malicious. The vulnerability is the absence of controls ensuring that future installations use the exact reviewed artifacts.

Attack Path

  1. An attacker compromises a named dependency, one of its transitive dependencies, or a package source configured for pip.
  2. The Agent or operator follows the dependency installation commands in SKILL.md.
  3. pip resolves and downloads the attacker-controlled or compromised artifact because no reviewed version or hash is required.
  4. Malicious package code executes during installation or when one of the scripts imports the package.
  5. The payload runs with the privileges of the Agent user and can access resources available to that account.

Impact Assessment

Successful exploitation could allow arbitrary cod ...[truncated 661 chars]

Remediation
View remediation

Remediation Suggestions

  1. Create a reviewed dependency file containing exact versions for all direct and transitive dependencies.
  2. Generate and record cryptographic hashes for every accepted distribution artifact.
  3. Install dependencies with hash verification:
bash
python3 -m pip install --require-hashes -r requirements.txt
  1. Configure pip to use an explicitly trusted package index or an internally controlled artifact repository.
  2. Prefer an isolated virtual environment rather than installing packages into the Agent's global Python environment.
  3. Review dependency updates before changing pinned versions and regenerate hashes only after validation.
  4. Add automated dependency vulnerability and provenance checks to the release process.
  5. Avoid running package installation as root or with administrative privileges.
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明描述的是一个完整的“长截图智能切片工具”,其主要目的应是对超长图片进行分析和切分,并支持多种输出格式。实际代码却只是一个 PDF 生成脚本:它假设切片图片已经存在,从目录中读取 .jpg 文件,然后生成带页码的 A4 PDF。代码没有任何图像切片、版面分析、文字区域保护、9:16 比例裁切或 ZIP 打包逻辑。因此,代码行为仅覆盖声明中的一个次级输出环节(PDF 生成),而未体现声明的主要功能,属于描述与实际行为的实质性不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

代码的核心行为整体上与“长截图智能切片、尽量避免切到文字、输出切片和压缩包”这一描述基本一致:它确实分析图像内容密度、寻找内容区之间的间隙、在目标高度附近选择切点,并输出切片 JPG 与 ZIP。但存在实质性描述偏差。第一,声明称输出 PDF,而代码没有任何 PDF 生成逻辑,实际是使用 python-docx 生成 Word 文档(DOCX)。第二,声明写的是按 9:16 比例切片,而代码设置 TARGET_WIDTH=781、ASPECT_RATIO=16/9,并以 height = width * 16/9 计算目标高度,这与文字表述存在方向/比例不一致。由于输出格式和比例表述都属于用户可感知的重要能力,因此应判定为描述与实际行为不完全匹配。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill instructs reading local files and using user-supplied local paths/temporary files, but it declares no explicit tool scope or permissions. This creates ambiguity about what filesystem access is expected and can enable broader-than-necessary file access when the agent executes the workflow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill tells the agent to fetch a user-provided URL with curl and save files locally, and also to write results to output directories, without any safety checks or warnings. In an agent context this can enable SSRF-style access to internal resources, retrieval of untrusted content, and unintended local file writes or overwrites if paths are not constrained.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest states the skill outputs "PDF/ZIP/切片图片", implying PDF generation is a supported result. In this file, the implementation creates slice images, a Word document (.docx), and a ZIP archive, but contains no PDF export path or conversion logic.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The natural-language description and examples are entirely Chinese and do not indicate that users may interact in other languages or choose a preferred locale. For policy compliance, language constraints should be optional or explicitly justified rather than implicitly forced.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and command-line usage text are entirely in Chinese, and the script continues to print user-facing status and error messages only in Chinese. This creates a language/locale policy issue because the skill imposes a specific language on users without opt-in or any stated region-specific justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and usage instructions are written entirely in Chinese, and all user-facing console output in the file follows the same language choice. This imposes a specific language/locale on users without any opt-in, alternative, or documented region-specific justification, which matches the language policy violation category.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.