Back to skill

Security audit

三剪客 · 数字人自动剪辑(网页版)

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent guide for a digital-human video web service, but it needs review because it handles face and voice media and includes API-key guidance without enough privacy, retention, or secret-handling detail.

Review the provider's privacy and retention terms before installing or using this skill. Only upload images, videos, and voice samples when you have clear consent from the person depicted or recorded, avoid public figures or third-party media, and keep any API key out of chats, logs, screenshots, and shared scripts.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README instructs users to upload portrait photos/videos and even clone a personal voice, but it does not clearly warn about privacy, consent, retention, or downstream data handling. In this context, users may submit highly sensitive biometric and identity data without understanding how it is stored, processed, shared, or deleted, creating meaningful privacy and abuse risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs users to upload highly sensitive personal data including face images, videos, voice recordings, and cloned voice samples, but it does not provide a clear privacy warning explaining that this data is transmitted to and processed by a third-party web service and may carry biometric/privacy risks. Because the content explicitly promotes voice cloning and digital-human generation, users may unknowingly expose biometric identifiers without informed consent or retention/transmission awareness.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The document hardcodes Chinese as the basis for core functionality, stating '中文语速实测约 5.6 字/秒' and using Chinese character counts as the default timing model, without indicating support for other languages or giving users a choice. Under the policy, language/locale constraints should be optional or explicitly justified when they are imposed.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document expands a browser-oriented user guide into direct API and scripting instructions, which materially lowers the barrier to automated use of a paid third-party service and contradicts the stated product framing. In a skill distributed as an operational guide, this can cause users or agents to transmit data and use credentials in ways they did not expect, increasing the risk of misuse and unauthorized automation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file explicitly targets people who want to write scripts and provides authentication and API usage details despite claiming to only document what the web app uses. That scope creep makes the skill more dangerous because it encourages repurposing a simple browser workflow into direct scripted access without corresponding safety controls, warnings, or trust boundaries.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · LICENSE.md (reported line 27)May include surrounding context.

md
| 项 | 值 |
|---|---|
| 根地址 | `https://api.a7w.cn/api/v1` |
| 鉴权 | 请求头 `Authorization: Bearer <你的 Key>` |
| 取 Key | 到 https://api.a7w.cn/ 注册创建(1 元 = 100 点) |
| 计费单位 | 点(`rate: 100` ⇒ 1 元 = 100 点) |

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 421)May include surrounding context.

md
| 项 | 值 |
|---|---|
| 根地址 | `https://api.a7w.cn/api/v1` |
| 鉴权 | 请求头 `Authorization: Bearer <你的 Key>` |
| 取 Key | 到 https://api.a7w.cn/ 注册创建(1 元 = 100 点) |
| 计费单位 | 点(`rate: 100` ⇒ 1 元 = 100 点) |

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/接口速查.md (reported line 15)May include surrounding context.

md
| 项 | 值 |
|---|---|
| 根地址 | `https://api.a7w.cn/api/v1` |
| 鉴权 | 请求头 `Authorization: Bearer <你的 Key>` |
| 取 Key | 到 https://api.a7w.cn/ 注册创建(1 元 = 100 点) |
| 计费单位 | 点(`rate: 100` ⇒ 1 元 = 100 点) |

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/接口速查.md (reported line 17)May include surrounding context.

md
| 项 | 值 |
|---|---|
| 根地址 | `https://api.a7w.cn/api/v1` |
| 鉴权 | 请求头 `Authorization: Bearer <你的 Key>` |
| 取 Key | 到 https://api.a7w.cn/ 注册创建(1 元 = 100 点) |
| 计费单位 | 点(`rate: 100` ⇒ 1 元 = 100 点) |

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document instructs use of a Bearer API key but does not warn against exposing that secret in logs, screenshots, shared prompts, client-side code, or browser tools. Because Bearer tokens are sufficient for account access and paid API consumption, omission of basic secret-handling guidance can directly lead to credential leakage and unauthorized charges or data access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The documentation is fully Chinese-language and does not indicate that the skill is Chinese-only by design, nor does it offer any language or locale choice. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.