Back to skill

Security audit

AI Photos

Security checks for vulnerabilities and agentic risk

Overview

The skill’s photo-album purpose is coherent, but it automatically installs an unverified latest-release executable and under-discloses sensitive photo processing risks.

Review this skill before installing. It works on local photo libraries and may send prepared images to a vision model for captioning. The largest concern is that it downloads and runs the latest GitHub release binary without integrity verification; install only if you trust the publisher and are comfortable with that update path. Use separate OS accounts or workspaces for shared machines, and approve automatic indexing only if periodic background scanning of the chosen folders is acceptable.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:165
Finding

Unpinned Remote Executable Downloaded and Run Without Integrity Verification

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 165–174
Vulnerability Type: Mutable remote payload retrieval and execution
Risk Level: High

Vulnerable Code

bash
archive_name="ai-photos_${goos}_${goarch}.tar.gz"
archive_url="https://github.com/${AI_PHOTOS_REPO}/releases/latest/download/${archive_name}"
tmp_dir="$(mktemp -d)"
had_existing_binary=0
if [ -x "$AI_PHOTOS_BIN" ]; then
  had_existing_binary=1
fi

if curl -fL "${archive_url}" -o "$tmp_dir/${archive_name}" \
  && tar -xzf "$tmp_dir/${archive_name}" -C "$tmp_dir" \
  && install -m 0755 "$tmp_dir/ai-photos" "$AI_PHOTOS_BIN"; then

Technical Analysis

The bootstrap process downloads an executable archive through the mutable GitHub releases/latest URL. It then extracts and installs the contained ai-photos binary with executable permissions without verifying a cryptographic checksum or signature.

Because the URL does not pin a reviewed version or immutable asset digest, the effective code executed by the Skill can change after the Skill itself has been audited. HTTPS protects transport integrity but does not protect against compromise of the upstream repository, maintainer account, release workflow, or release artifact.

The installed executable is subsequently used for operations including photo discovery, image preparation, backend setup, record import, search, local web serving, and recurring synchronization. Consequently, a substituted executable would run in a context with access to the user's photo sources and other resources available to the Agent's operating-system account.

Attack Path

  1. An attacker compromises the upstream repository, maintainer credentials, release workflow, or GitHub release assets.
  2. The attacker publishes or replaces the archive selected by the mutable releases/latest/download/... URL.
  3. At the beginning of an ai-photos task, the mandated bootstrap process downloads the attacker-controlled archive.
  4. The process extracts ...[truncated 1230 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the CLI to a specific reviewed release version rather than using releases/latest.
  2. Publish SHA-256 hashes through a separately protected release process and embed or securely obtain the expected platform-specific digest.
  3. Verify the archive before extraction, for example with sha256sum -c or shasum -a 256, and fail closed on any mismatch.
  4. Prefer cryptographically signed artifacts and verify the signature against a pinned, trusted public key.
  5. Do not install or execute an artifact when integrity or authenticity verification fails.
  6. Download to a private temporary directory and validate that the archive contains only the expected file paths before extraction.
  7. Extract using protections against path traversal and reject symbolic links, absolute paths, unexpected entries, and duplicate executable entries.
  8. Verify the extracted file's type and expected metadata before atomically replacing the cached binary.
  9. Retain a previously verified binary only if its version and digest are recorded and revalidated before use.
  10. Document a controlled update procedure so new releases undergo review and digest updates before deployment.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Session Persistence

Medium
Category
Rogue Agent
Confidence
78% confidence
Finding

The reconnect flow relies on a saved default album profile and instructs the agent to reuse stored connection information automatically, which is a form of session persistence that can expose previously configured data sources or backend access without a fresh authorization check. In a shared or multi-user environment, this could let a later user query or reconnect to another user's photo album or backend state.

Content

Scanner excerpt · SKILL.md (reported line 207)May include surrounding context.

md
User-facing:

- Ask whether the user wants to create a new photo album, reconnect an existing one, or search an already configured album.
- If they want to reconnect, explain that you will try the saved connection first and only ask for more details if needed.

`[AGENT]` Branching:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly directs the agent to send user photo content to a vision-capable model during caption generation, but it does not require clear user consent or a user-facing privacy disclosure before transmitting potentially sensitive images. Because personal photo libraries commonly contain faces, locations, documents, and other private data, this creates a meaningful privacy and data-handling risk even if the feature is core to the skill's purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.