Back to skill

Security audit

文章配图调研

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed article image research helper that uses expected web and image-provider searches with attribution and risk checks.

Before installing, expect the skill to use web/image search and possibly provider API keys for image lookup. Review image licenses on the original landing pages before publication, and avoid sending private article drafts as search queries unless you are comfortable with those terms being sent to search providers.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

描述强调的是一个较完整的“配图调研与评估”工作流,不仅要搜图,还要判断图片是否适合支撑特定文本内容,并记录来源、授权、归因、风险和推荐用途。实际代码的核心功能只是从多个图片提供方检索候选图片并标准化返回结果。虽然它确实收集了部分可追溯信息(如来源、作者、许可证、归因字段),与“生成图片候选池”这一部分相符,但缺少描述中更关键的分析能力:没有输入文章段落或网页内容进行匹配,没有进行证据性/解释性/对比性适配判断,也没有做风险评级、授权审查或使用建议生成。因此,代码行为只覆盖了声明用途的一部分,且主要目的明显更窄,构成描述与实际行为不一致。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill explicitly instructs the agent to use networked capabilities, browsers, image search, scripts, and environment-supported tools, but it does not declare any tool scope or allowed-tools boundary. This creates a governance and least-privilege gap: the runtime may permit broader network or environment access than users expect, increasing the chance of unintended external requests, data exposure, or unsafe tool invocation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire skill documentation, prompts, and output templates are written to require Chinese-language operation, including a fixed Chinese search-plan template and Chinese field guidance, with no indication that users may choose another language. This creates a locale/language policy concern because the skill appears to enforce a specific language by default rather than offering opt-in or alternatives.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The entire policy file is written only in Chinese and does not indicate that users may choose another language or that the skill is limited to a Chinese-language or region-specific context. Under the language/locale policy rule, forcing a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The entire rubric is written in Chinese and includes example output that assumes Chinese-language recommendations and rejections. There is no indication that the skill offers a language/locale choice or that the Chinese-only constraint is justified as a region-specific requirement, which can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/search_images.py (reported line 45)May include surrounding context.

python
def search_openverse(query: str, limit: int, page: int, include_raw: bool) -> list[dict[str, Any]]:
    url = build_url(
        "https://api.openverse.org/v1/images/",
        {
            "q": query,
            "page_size": limit,

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/search_images.py (reported line 82)May include surrounding context.

python
if not api_key:
        raise SearchError("PEXELS_API_KEY is required for provider=pexels")
    url = build_url(
        "https://api.pexels.com/v1/search",
        {
            "query": query,
            "per_page": limit,

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/search_images.py (reported line 119)May include surrounding context.

python
if not api_key:
        raise SearchError("UNSPLASH_ACCESS_KEY is required for provider=unsplash")
    url = build_url(
        "https://api.unsplash.com/search/photos",
        {
            "query": query,
            "per_page": limit,

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/search_images.py (reported line 161)May include surrounding context.

python
raise SearchError("BRAVE_SEARCH_API_KEY is required for provider=brave")
    offset = max(page - 1, 0) * limit
    url = build_url(
        "https://api.search.brave.com/res/v1/images/search",
        {
            "q": query,
            "count": limit,

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all operational guidance exclusively in Chinese, which effectively forces a specific language on readers. The file does not indicate that the language is optional, user-selectable, or required for a documented region-specific purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instructions explicitly require generating Chinese queries and then English queries as part of the base workflow. This imposes a language behavior on users without opt-in or any note that the skill is intended only for a bilingual or region-specific use case.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.