Skip to content

Inspect skill image text layers; inventory image references #698

Description

@Yoseph-Zuskin

Problem

No analyzer looks at image content bundled or cited in skills:
references.py treats markdown images as passive grammar,
mcp_tool_poisoning flags base64 blobs in metadata only, and the
LLM path is text-only (no image_url in any provider). SVG is
already visible to static patterns as text; PNG/JPG cited or bundled
are unscanned hiding places for payload text in metadata layers.

Proposed scope

  • Per-skill inventory of LOCAL image files (markdown targets plus
    loose files) in the inspection ledger, no verdicts. Remote-cited
    URLs are inventoried but never fetched: no network access
    mid-scan, by design.
  • Stdlib-only extraction of embedded text layers (PNG text chunks
    and EXIF, JPEG comments and EXIF, GIF comments) routed through
    the existing static prompt-injection patterns, with findings
    attributed to the image path. Bounded, never raises, no pixels,
    no new dependencies.
  • Omitted deliberately: pixel decoding (no OCR), remote
    fetching, GIF plain-text extensions, WebP EXIF, BMP/WebP text
    layers. Rendered QR payloads and steganography need a vision-LLM
    design, proposed separately — not claimed here.

Acceptance

  • Inventory present in the ledger for local files; remote URLs
    cited-but-unfetched.
  • Extracted image text flows through static patterns with tests;
    textless images keep existing skip accounting.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions