Back to skill

Security audit

三剪客 · a7w 全量协议桥

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real local API bridge, but it handles paid API credentials and runs a broad unauthenticated proxy with some unsafe credential-sharing guidance.

Install only if you intend to route your AI traffic through api.a7w.cn and any embedding provider you configure. Use your own API key, set spending quotas, do not accept shared keys from the author or third parties, keep the bridge bound to localhost, and stop it when not in use; do not expose it to a LAN or public network without adding authentication and access controls.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (24)

Tainted flow: 'req' from os.environ.get (line 679, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/a7w_bridge.py (reported line 111)May include surrounding context.

python
elif data is not None:
        req.add_header("Content-Type", "application/json")
    try:
        with urllib.request.urlopen(req, timeout=timeout) as r:
            return r.status, dict(r.headers), r.read()
    except urllib.error.HTTPError as e:
        return e.code, dict(e.headers), e.read()

Tainted flow: 'req' from os.environ.get (line 679, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/a7w_bridge.py (reported line 521)May include surrounding context.

python
req.add_header("Authorization", "Bearer " + (self._key() or ""))
        req.add_header("Content-Type", "application/json")
        try:
            r = urllib.request.urlopen(req, timeout=300)
        except urllib.error.HTTPError as e:
            return self._send(e.code, e.read(), "application/json; charset=utf-8")
        self.send_response(200)

Tainted flow: 'req' from os.environ.get (line 679, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

The embeddings proxy forwards request bodies and an environment-sourced API key to EMBED_BASE, which is fully controlled by an environment variable. If that variable is misconfigured or maliciously set, sensitive embedding inputs and credentials can be sent to an arbitrary external service, creating a real exfiltration path beyond the documented a7w upstream.

Content

Scanner excerpt · scripts/a7w_bridge.py (reported line 684)May include surrounding context.

python
if EMBED_KEY:
            req.add_header("Authorization", "Bearer " + EMBED_KEY)
        try:
            with urllib.request.urlopen(req, timeout=120) as r:
                return self._send(r.status, r.read(), "application/json; charset=utf-8")
        except urllib.error.HTTPError as e:
            return self._send(e.code, e.read(), "application/json; charset=utf-8")

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The author states users can contact them to receive a '配套的 API Key', which normalizes off-platform credential sharing and bypasses normal account ownership and audit controls. Even though earlier text warns against using others' keys, this later offer directly undermines that guidance and can expose users to credential theft, billing abuse, revoked access, or shared-account compromise.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README explicitly instructs users to route chat, audio transcription, speech synthesis, image generation, and application requests through a local bridge to the external service api.a7w.cn, but it does not provide a clear privacy or data-handling warning. This is risky because users may unknowingly transmit prompts, uploaded media, generated content, API keys, or sensitive business data to a third party.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill explicitly describes capabilities that read environment variables, access local files, and send network requests, but it does not declare any tool scope or permission boundaries. That creates an authorization and transparency gap: a user may invoke a skill with broader runtime powers than are obvious from metadata, increasing the chance of unintended data access or outbound transmission.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 143)May include surrounding context.

全量应用(21 个都走这个口)

bash
curl -s http://127.0.0.1:8788/a7w/voice_tts/list_voices \
     -H 'Content-Type: application/json' -d '{}'

# 加 "_wait": true 自动轮询到任务完成

Ssd 3

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

Offering API keys via private contact encourages out-of-band secret distribution, which defeats standard security controls such as per-user issuance, rotation, logging, and revocation. This is especially risky in a skill that brokers many AI capabilities, because a shared key may grant broad API access and make abuse attribution difficult.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents all operational instructions in Chinese, which effectively forces a specific language for users consuming the skill documentation. The policy allows fixed locale only when the constraint is explicitly justified or users are offered a choice, neither of which appears here.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/integrate.md (reported line 14)May include surrounding context.

bash
# 桥之前
OPENAI_BASE_URL=https://api.openai.com/v1

# 桥之后
OPENAI_BASE_URL=http://127.0.0.1:8788/v1

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/integrate.md (reported line 109)May include surrounding context.

bash
# 提交 + 自动轮询(_wait: true)
curl -s http://127.0.0.1:8788/a7w/flashvsr/submit \
  -H 'Content-Type: application/json' \
  -d '{"video_url":"https://...","_wait":true}'

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code file contains extensive natural-language descriptions and runtime messages entirely in Chinese, including setup guidance and error/help text. Because the skill does not offer user opt-in for language selection or state that it is intentionally limited to a Chinese-speaking context, it violates the language/locale policy for natural-language behavior.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 133)May include surrounding context.

md
"  2) 写配置文件:%s\n"
                "                内容 {'key': 'sk-...'}\n"
                "  3) 用配套技能:python client.py login --key sk-...\n"
                "Key 在 https://api.a7w.cn/ 用户中心 → API 密钥 创建(需实名认证)。\n"
                "上游原始信息:" % os.path.join(os.path.expanduser("~"), ".a7w", "config.json")
                ) + upstream_msg
    return upstream_msg

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 150)May include surrounding context.

md
"  2) 写配置文件:%s\n"
                "                内容 {'key': 'sk-...'}\n"
                "  3) 用配套技能:python client.py login --key sk-...\n"
                "Key 在 https://api.a7w.cn/ 用户中心 → API 密钥 创建(需实名认证)。\n"
                "上游原始信息:" % os.path.join(os.path.expanduser("~"), ".a7w", "config.json")
                ) + upstream_msg
    return upstream_msg

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 151)May include surrounding context.

md
"  2) 写配置文件:%s\n"
                "                内容 {'key': 'sk-...'}\n"
                "  3) 用配套技能:python client.py login --key sk-...\n"
                "Key 在 https://api.a7w.cn/ 用户中心 → API 密钥 创建(需实名认证)。\n"
                "上游原始信息:" % os.path.join(os.path.expanduser("~"), ".a7w", "config.json")
                ) + upstream_msg
    return upstream_msg

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

md
"  2) 写配置文件:%s\n"
                "                内容 {'key': 'sk-...'}\n"
                "  3) 用配套技能:python client.py login --key sk-...\n"
                "Key 在 https://api.a7w.cn/ 用户中心 → API 密钥 创建(需实名认证)。\n"
                "上游原始信息:" % os.path.join(os.path.expanduser("~"), ".a7w", "config.json")
                ) + upstream_msg
    return upstream_msg

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 234)May include surrounding context.

md
"  2) 写配置文件:%s\n"
                "                内容 {'key': 'sk-...'}\n"
                "  3) 用配套技能:python client.py login --key sk-...\n"
                "Key 在 https://api.a7w.cn/ 用户中心 → API 密钥 创建(需实名认证)。\n"
                "上游原始信息:" % os.path.join(os.path.expanduser("~"), ".a7w", "config.json")
                ) + upstream_msg
    return upstream_msg

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 251)May include surrounding context.

md
"  2) 写配置文件:%s\n"
                "                内容 {'key': 'sk-...'}\n"
                "  3) 用配套技能:python client.py login --key sk-...\n"
                "Key 在 https://api.a7w.cn/ 用户中心 → API 密钥 创建(需实名认证)。\n"
                "上游原始信息:" % os.path.join(os.path.expanduser("~"), ".a7w", "config.json")
                ) + upstream_msg
    return upstream_msg

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 252)May include surrounding context.

md
"  2) 写配置文件:%s\n"
                "                内容 {'key': 'sk-...'}\n"
                "  3) 用配套技能:python client.py login --key sk-...\n"
                "Key 在 https://api.a7w.cn/ 用户中心 → API 密钥 创建(需实名认证)。\n"
                "上游原始信息:" % os.path.join(os.path.expanduser("~"), ".a7w", "config.json")
                ) + upstream_msg
    return upstream_msg

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/a7w_bridge.py (reported line 149)May include surrounding context.

python
"  2) 写配置文件:%s\n"
                "                内容 {'key': 'sk-...'}\n"
                "  3) 用配套技能:python client.py login --key sk-...\n"
                "Key 在 https://api.a7w.cn/ 用户中心 → API 密钥 创建(需实名认证)。\n"
                "上游原始信息:" % os.path.join(os.path.expanduser("~"), ".a7w", "config.json")
                ) + upstream_msg
    return upstream_msg

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/a7w_bridge.py (reported line 738)May include surrounding context.

python
"  2) 写配置文件:%s\n"
                "                内容 {'key': 'sk-...'}\n"
                "  3) 用配套技能:python client.py login --key sk-...\n"
                "Key 在 https://api.a7w.cn/ 用户中心 → API 密钥 创建(需实名认证)。\n"
                "上游原始信息:" % os.path.join(os.path.expanduser("~"), ".a7w", "config.json")
                ) + upstream_msg
    return upstream_msg

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file switches from the standard MIT license text to additional operational notes written only in Chinese. Because this is natural-language guidance for the skill and no alternative language or opt-in is offered, it creates a locale-specific constraint that may violate language-choice policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The README content is entirely in Chinese and does not indicate that language is fixed by design or provide an alternative language option. Under the stated policy, forcing a specific language or locale without user opt-in can be a natural-language policy violation unless the locale constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file uses Chinese as the sole instruction language, beginning with the title at L01, and continues throughout without any opt-in or alternative language. Under the policy rule for natural-language violations, forcing a specific language without user choice can be considered a locale/language policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.