Back to skill

Security audit

三剪客 · 动作迁移

Security checks for vulnerabilities and agentic risk

Overview

The skill is not malicious on inspection, but its bundled client is much broader than the advertised two-endpoint action-transfer workflow and can use the user's API key to enumerate or call arbitrary a7w apps.

Review this before installing if you only want a narrow action-transfer helper. Use a limited API key if available, avoid --host or A7W_HOST unless you fully trust the endpoint, do not upload private or non-consensual face/video media, and remember that generic client commands may expose available apps or spend account points outside the advertised workflow.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (24)

Tainted flow: 'req' from os.environ.get (line 151, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/client.py (reported line 111)May include surrounding context.

python
headers["Content-Type"] = "application/json"
    req = urllib.request.Request(url, data=data, headers=headers, method=method)
    try:
        with urllib.request.urlopen(req, timeout=timeout) as resp:
            raw = resp.read().decode("utf-8", "replace")
            status = resp.status
    except urllib.error.HTTPError as exc:

Tainted flow: 'req' from os.environ.get (line 151, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/client.py (reported line 153)May include surrounding context.

python
headers["Content-Type"] = "application/json"
    req = urllib.request.Request(url, data=data, headers=headers, method=method)
    try:
        with urllib.request.urlopen(req, timeout=timeout) as resp:
            raw = resp.read().decode("utf-8", "replace")
            status = resp.status
    except urllib.error.HTTPError as exc:

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose is a two-endpoint action-transfer skill, but the embedded client reportedly supports generic plugin enumeration, schema dumping, arbitrary API invocation, API-key storage, account inspection, and points history. That mismatch is dangerous because it hides a much broader operational surface than users expect, enabling misuse of credentials and access to unrelated APIs under the guise of a single-purpose media skill.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
description: "动作迁移,基于参考图片和输入视频生成动作迁移后的视频结果。支持 提交任务、查询任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 7)May include surrounding context.

md
description: "动作迁移,基于参考图片和输入视频生成动作迁移后的视频结果。支持 提交任务、查询任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire skill description and operational instructions are written only in Chinese, with no indication that other languages are supported or that the Chinese-only presentation is a justified region-specific constraint. This can violate a language/locale policy when users are not given an explicit opt-in or alternative.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README describes a generic client with capabilities like listing apps, viewing schemas, and calling arbitrary app APIs, which exceeds the stated action-transfer-only scope. This creates a scope-mismatch risk: users may grant trust, credentials, and network access believing the skill is narrowly scoped, while the bundled tooling appears usable as a broader API client.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The README claims the script only sends the API key to api.a7w.cn, but elsewhere documents a generic client able to interact with multiple apps and external resources. Unsupported security assurances are dangerous because they may cause users to expose credentials under false assumptions about where secrets and data can flow.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill advertises executable client commands and the package reportedly contains code with network, shell, file read/write, and environment access, but the manifest does not declare any tool scope or permission boundaries. This creates a transparency and governance gap: a user or host may treat the skill as narrow documentation for action transfer while it can operate with broader local and network capabilities.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 13)May include surrounding context.

md
name: action-transfer
slug: action-transfer
displayName: 三剪客 · 动作迁移
description: "动作迁移,基于参考图片和输入视频生成动作迁移后的视频结果。支持 提交任务、查询任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「动作迁移」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 115)May include surrounding context.

md
name: action-transfer
slug: action-transfer
displayName: 三剪客 · 动作迁移
description: "动作迁移,基于参考图片和输入视频生成动作迁移后的视频结果。支持 提交任务、查询任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「动作迁移」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 124)May include surrounding context.

md
name: action-transfer
slug: action-transfer
displayName: 三剪客 · 动作迁移
description: "动作迁移,基于参考图片和输入视频生成动作迁移后的视频结果。支持 提交任务、查询任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「动作迁移」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
name: action-transfer
slug: action-transfer
displayName: 三剪客 · 动作迁移
description: "动作迁移,基于参考图片和输入视频生成动作迁移后的视频结果。支持 提交任务、查询任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「动作迁移」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 7)May include surrounding context.

md
name: action-transfer
slug: action-transfer
displayName: 三剪客 · 动作迁移
description: "动作迁移,基于参考图片和输入视频生成动作迁移后的视频结果。支持 提交任务、查询任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「动作迁移」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

md
name: action-transfer
slug: action-transfer
displayName: 三剪客 · 动作迁移
description: "动作迁移,基于参考图片和输入视频生成动作迁移后的视频结果。支持 提交任务、查询任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「动作迁移」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-query.md (reported line 40)May include surrounding context.

}

text

## cURL 示例

```bash
curl -X POST "https://你的域名/api/v1/apps/action_transfer/query" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation instructs users to submit reference images and input videos to a third-party platform but does not warn that these media may contain sensitive biometric, personal, or private contextual data. Because the API explicitly processes face images and videos, omission of a privacy/transmission warning can lead users to unknowingly upload sensitive data off-platform, increasing privacy, compliance, and consent risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The cURL example demonstrates sending externally hosted image/video URLs and an API key to a remote service, which is a real external data transmission pattern. In this skill’s context, that behavior is expected for the advertised functionality, but it still carries security risk because users may disclose sensitive media and credentials to a third-party endpoint without sufficient guardrails or warnings.

Content

Scanner excerpt · references/api-submit.md (reported line 81)May include surrounding context.

}

text

## cURL 示例

```bash
curl -X POST "https://你的域名/api/v1/apps/action_transfer/submit" \

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The bundled client is advertised for an action-transfer skill, but it is actually a marketplace-wide generic client capable of operating on any plugin. That scope expansion violates least privilege and increases the chance an agent or user will invoke unrelated capabilities, exposing data or incurring unintended charges beyond the skill's declared purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The module docstring, CLI descriptions, help text, and runtime messages are entirely in Chinese, which effectively constrains use to a single language/locale. The file does not indicate that language selection is optional or configurable, nor does it document a justified region-specific limitation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The schema-dump functionality enables bulk discovery of all apps and their interfaces, which materially exceeds the manifest's stated submit/query scope. In an agent setting, this broad introspection can be abused to enumerate available capabilities and facilitate misuse of other plugins not intended by the skill author or platform policy.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The call command allows arbitrary app and API selection, effectively turning this skill into a generic authenticated marketplace executor. In skill context, this is more dangerous because a user expecting only action-transfer functionality may unknowingly grant the agent a broad capability to invoke any available plugin with their API key, causing unauthorized actions, data exposure, or billing abuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The entire skill document is presented only in Chinese, including headings, parameter descriptions, and examples, with no indication that language choice is optional or that the skill is intentionally limited to a Chinese-speaking audience. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The top-level usage text says whoami verifies the key and shows '账号与余额' and points queries balance, but cmd_whoami actually calls /api/v1/apps and returns app metadata, while cmd_points sums recent task usage because no balance endpoint exists. This is an active mismatch between documentation and implemented behavior, even though later docstrings partially clarify the limitation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.