Back to skill

Security audit

zodiac-claymote

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent sticker-pack generator, but it includes an explicit batch watermark-removal workflow that could hide provider, ownership, or provenance marks before publication.

Install only if you are comfortable with a skill that includes a local watermark-removal utility. Use it only on images you created and are licensed to modify; do not remove third-party, platform, attribution, copyright, or provenance marks. Prefer generating or sourcing watermark-free assets under terms that allow publication.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (37)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The documentation presents the skill as an original sticker generator, but it explicitly includes watermark removal from existing images. That hidden or downplayed editing capability materially changes the risk profile because it can facilitate deceptive reuse of third-party or tool-restricted content.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
The documentation presents the skill as an original sticker generator, but it explicitly includes watermark removal from existing images. That hidden or downplayed editing capability materially changes the risk profile because it can facilitate deceptive reuse of third-party or tool-restricted content.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
The documentation presents the skill as an original sticker generator, but it explicitly includes watermark removal from existing images. That hidden or downplayed editing capability materially changes the risk profile because it can facilitate deceptive reuse of third-party or tool-restricted content.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The documentation presents the skill as an original sticker generator, but it explicitly includes watermark removal from existing images. That hidden or downplayed editing capability materially changes the risk profile because it can facilitate deceptive reuse of third-party or tool-restricted content.

Intent-Code Divergence

High
Confidence
98% confidence
Finding
The document claims strict non-infringement rules and bans watermarks/signatures, but later tells users to clear generator watermarks before submission. This contradiction is dangerous because it gives a false impression of compliance while enabling concealment of provenance or license restrictions.

Ae1

High
Category
analysis-evasion
Content
python scripts/build_prompt.py --zodiac 龙 --job 工程师 --emotion 崩溃 --scene 线上出Bug
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
python scripts/build_prompt.py --zodiac 龙 --job 工程师 --emotion 崩溃 --scene 线上出Bug
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
python scripts/build_prompt.py --zodiac 龙 --job 工程师 --emotion 崩溃 --scene 线上出Bug
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
python scripts/build_prompt.py --zodiac 龙 --job 工程师 --emotion 崩溃 --scene 线上出Bug
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Context-Inappropriate Capability

High
Confidence
99% confidence
Finding
The skill explicitly instructs users to remove tool-added watermarks before submission. Watermark removal is commonly used to evade attribution, licensing, or platform restrictions, and here it is normalized as part of the standard workflow despite the skill claiming originality and compliance.

Missing User Warnings

High
Confidence
98% confidence
Finding
The skill instructs users to remove generated-image watermarks without clear compliance or licensing warnings. In context, this omission materially increases the chance that users will strip attribution or restrictions from outputs and submit or commercialize them deceptively.

Ae1

High
Category
analysis-evasion
Content
目录结构已对齐主流平台(WorkBuddy / 扣子 Coze·豆包 / Claude)的约定:根目录一份 `SKILL.md` + 可选 `scripts/ references/ assets/`。
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
目录结构已对齐主流平台(WorkBuddy / 扣子 Coze·豆包 / Claude)的约定:根目录一份 `SKILL.md` + 可选 `scripts/ references/ assets/`。
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The file explicitly implements a watermark-removal tool and even frames it as removing service-added corner marks before submission, which materially diverges from the declared sticker-generation purpose of the skill. In this context, the mismatch is dangerous because it adds functionality that can facilitate bypassing attribution, platform restrictions, or copyright controls while hiding behind a narrow disclaimer.

Context-Inappropriate Capability

High
Confidence
99% confidence
Finding
These code paths operationalize watermark stripping by detecting likely watermark regions and then removing them via inpainting, color fill, or cropping across single images or batches. The presence of automated and batch-capable removal makes the functionality directly usable for removing copyright or service marks at scale, which exceeds any stated sticker-generation need and increases misuse potential.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The file states that images will 'automatically overlay Chinese copy' and elsewhere describes Chinese captions as the default workflow, but it does not present this as an opt-in choice or explain that the skill is intentionally China/WeChat-specific. Under the policy, forcing a specific language without user choice is a natural-language locale violation unless the restriction is clearly documented and justified.

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
The README explicitly advertises a `remove_watermark.py` capability as part of the normal workflow, even though watermark removal is not necessary for benign prompt generation or sticker packaging. Watermark stripping can facilitate copyright circumvention, violation of generator terms, and laundering of AI-generated provenance, which makes this a genuine abuse-enabling feature in the skill context.

Missing User Warnings

Medium
Confidence
98% confidence
Finding
The README provides step-by-step commands for previewing and removing watermarks, including automated detection and inpainting/fill methods, but gives no legal or ethical warning at the point of use. That omission lowers friction for misuse and normalizes removal of ownership or provenance markers, increasing the likelihood of copyright abuse and deceptive redistribution.

Lp3

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding
The skill describes shell commands and file-processing scripts but does not declare any explicit tool scope or permissions boundary. In agent environments, this increases the risk of overbroad execution, unintended file access, or misuse of shell/file capabilities beyond the user’s expectations.

Vague Triggers

Medium
Confidence
94% confidence
Finding
L003 的触发词包含“表情包”“生成一套表情包”等高频泛化表达,未限定必须是生肖、黏土风或微信表情包场景,容易与大量普通创作请求重叠。该描述虽有若干较具体词汇,但同时混入宽泛短语,降低了触发边界的清晰度。

Ssd 4

Medium
Confidence
97% confidence
Finding
The workflow frames watermark removal as routine cleanup, which normalizes concealment of content origin and may encourage deceptive submissions to platforms. In a skill centered on producing allegedly original packs for publication, that context makes the behavior more dangerous because it directly supports misrepresentation.

Context-Inappropriate Capability

Medium
Confidence
97% confidence
Finding
The file explicitly recommends using a script to remove watermarks from generated images, which can facilitate bypassing attribution, license, or provider-imposed usage restrictions. In a sticker-generation skill, this guidance is not necessary for core functionality and increases the risk of downstream copyright, terms-of-service, and provenance abuse.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The document states that meaning words should '使用普通话', text information should '尽量用中文', and discourages other forms without presenting this as an optional user choice. Under the policy, forcing a specific language or locale without opt-in is a natural-language policy violation unless clearly justified as region-specific, which is not explicitly documented here.

Ssd 2

Medium
Confidence
96% confidence
Finding
The introductory text uses compliance language to present the tool as acceptable while still providing concrete instructions for removing watermarks, including recommended workflows and methods. This kind of benign framing can reduce operator suspicion and normalize misuse, making it easier to deploy rights-removal functionality under the guise of routine image cleanup.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The manifest presents the skill name and description entirely in Chinese, indicating the skill is designed to operate in a specific language/locale without offering any user choice or documenting an opt-in. This matches the policy category for language or locale constraints that are not explicitly optional or justified as region-specific.

Static analysis

No suspicious patterns detected.