Back to skill

Security audit

三剪客 · AI 短剧创作台

Security checks for vulnerabilities and agentic risk

Overview

This is mainly an offline Chinese documentation skill with a local cost calculator; it includes vendor links and privileged deployment examples users should review, but I found no hidden execution, exfiltration, or deceptive behavior.

Before installing or using it, understand that the guide is Chinese-focused and includes optional vendor links. Do not share existing secrets over WeChat or any chat channel, verify any API-key provider independently, and review all sudo/systemctl/database commands before running them on a real server.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (22)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
description: "短剧创作台的选型评估与私有化搭建指南。包内含完整操作文档(`SKILL.md` + `references/`)。更多 AI 算力与插件见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 7)May include surrounding context.

md
description: "短剧创作台的选型评估与私有化搭建指南。包内含完整操作文档(`SKILL.md` + `references/`)。更多 AI 算力与插件见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
77% confidence
Finding

The skill title and the entire README are presented only in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific audience. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 128)May include surrounding context.

md
## 联系我们

- **技术微信:9872659** —— 加好友时说一下是从哪个 Skill 找过来的,直接给你配套的 API Key 与能跑的示例。
- **要算力 / 要 API Key**:[算力集市 · 注册领 API Key](https://api.a7w.cn/) —— 一个 Key 调用全部 AI 算力,注册、充值、创建 Key 都在这里。
- **更多 AI 插件与接口**:[AI 插件市场](https://aigc.a7w.cn/)。

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 137)May include surrounding context.

md
## 联系我们

- **技术微信:9872659** —— 加好友时说一下是从哪个 Skill 找过来的,直接给你配套的 API Key 与能跑的示例。
- **要算力 / 要 API Key**:[算力集市 · 注册领 API Key](https://api.a7w.cn/) —— 一个 Key 调用全部 AI 算力,注册、充值、创建 Key 都在这里。
- **更多 AI 插件与接口**:[AI 插件市场](https://aigc.a7w.cn/)。

---

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The skill metadata display name is entirely in Chinese, and the document content is written exclusively in Chinese without any indication that users may choose another language or that the locale restriction is intentional. This can violate language/locale policy when a skill implicitly forces one language for all users without opt-in or documented justification.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The manifest metadata embeds an external service URL in the description, encouraging users toward a third-party site from what is presented as an offline documentation package. In context, this is risky because it is not merely a citation; it is part of promotional routing to external infrastructure and API-key acquisition.

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
name: sanjianke-drama-studio-kit
slug: sanjianke-drama-studio-kit
displayName: 三剪客 · AI 短剧创作台
description: "短剧创作台的选型评估与私有化搭建指南。包内含完整操作文档(`SKILL.md` + `references/`)。更多 AI 算力与插件见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.2
summary: "面向要自建 AI 短剧创作台的技术负责人:先做五维选型打分与自建/采购决策,再按 B/S 全栈架构完成环境准备、依赖安装、AI 供应商与对象存储配置、前端构建与联调,最后给出上线检查、成本构成与故障排查路径。附 Python 离线测算脚本。包内含完整操作文档(`SKILL.md` + `references/`)。更多 AI 算力与插件见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The summary field repeats an external service URL, reinforcing undisclosed external dependency/marketing inside package metadata. Users may treat metadata as trusted package information and be nudged off-platform without clear security or privacy disclosures.

Content

Scanner excerpt · SKILL.md (reported line 7)May include surrounding context.

md
displayName: 三剪客 · AI 短剧创作台
description: "短剧创作台的选型评估与私有化搭建指南。包内含完整操作文档(`SKILL.md` + `references/`)。更多 AI 算力与插件见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.2
summary: "面向要自建 AI 短剧创作台的技术负责人:先做五维选型打分与自建/采购决策,再按 B/S 全栈架构完成环境准备、依赖安装、AI 供应商与对象存储配置、前端构建与联调,最后给出上线检查、成本构成与故障排查路径。附 Python 离线测算脚本。包内含完整操作文档(`SKILL.md` + `references/`)。更多 AI 算力与插件见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT
tags:
  - 三剪客

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document asserts the skill is fully offline and does not access external addresses, but elsewhere it promotes external sites for API keys and related services. This creates a trust-boundary mismatch: users may rely on the offline claim and later be funneled to third-party services, increasing phishing, data-sharing, or supply-chain risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The contact section instructs users to add a private WeChat contact to receive API keys and runnable examples. Off-platform credential distribution and direct-contact onboarding bypass normal trust controls, provenance checks, and auditability, which increases social-engineering and supply-chain risk.

Content

Scanner excerpt · SKILL.md (reported line 221)May include surrounding context.

md
## 联系我们

- **技术微信:9872659** —— 加好友时说一下是从哪个 Skill 找过来的,直接给你配套的 API Key 与能跑的示例。
- **要算力 / 要 API Key**:[算力集市 · 注册领 API Key](https://api.a7w.cn/) —— 一个 Key 调用全部 AI 算力,注册、充值、创建 Key 都在这里。
- **更多 AI 插件与接口**:[AI 插件市场](https://aigc.a7w.cn/)。

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

The related-links table advertises multiple external products and services unrelated to the minimal offline guide function. In this context, the danger is the cumulative redirection to a broader vendor ecosystem, increasing the chance of unnecessary data sharing, dependency sprawl, and user confusion about what is actually required.

Content

Scanner excerpt · SKILL.md (reported line 230)May include surrounding context.

md
| 链接 | 地址 | 说明 |
|---|---|---|
| [算力集市 · 注册领 API Key](https://api.a7w.cn/) | api.a7w.cn | 一个 Key 调用全部 AI 算力;注册、充值、创建 Key 都在这 |
| [AI 插件市场](https://aigc.a7w.cn/) | aigc.a7w.cn | 浏览全部 AI 插件与接口说明 |
| [三剪客 · 一句话批量出片](https://ks.a7w.cn/) | ks.a7w.cn | 短剧二创 / 影视解说 / 矩阵号批量混剪桌面客户端 |
| [视频超清 · 在线批量超分](https://vr.a7w.cn/) | vr.a7w.cn | 网页版视频超分,批量处理,最高 4K |

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/deploy-and-configure.md (reported line 74)May include surrounding context.

bash
# 系统包方式装数据库、缓存与多媒体工具
sudo apt update
sudo apt install -y mysql-server redis-server ffmpeg

# 验证三件套

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/deploy-and-configure.md (reported line 75)May include surrounding context.

bash
# 系统包方式装数据库、缓存与多媒体工具
sudo apt update
sudo apt install -y mysql-server redis-server ffmpeg

# 验证三件套

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/deploy-and-configure.md (reported line 269)May include surrounding context.

bash
# 系统包方式装数据库、缓存与多媒体工具
sudo apt update
sudo apt install -y mysql-server redis-server ffmpeg

# 验证三件套

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/deploy-and-configure.md (reported line 270)May include surrounding context.

bash
# 系统包方式装数据库、缓存与多媒体工具
sudo apt update
sudo apt install -y mysql-server redis-server ffmpeg

# 验证三件套

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/deploy-and-configure.md (reported line 271)May include surrounding context.

bash
# 系统包方式装数据库、缓存与多媒体工具
sudo apt update
sudo apt install -y mysql-server redis-server ffmpeg

# 验证三件套

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/deploy-and-configure.md (reported line 270)May include surrounding context.

bash
sudo systemctl daemon-reload
sudo systemctl enable --now drama-studio
sudo systemctl status drama-studio

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The explanatory section is written only in Chinese ('说明' and following sentences), which can effectively force a specific language for users reading the skill metadata. The policy allows locale-specific constraints only when explicitly justified or offered as a choice, which is not present here.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The skill says it does not read credentials, yet it directs users to contact the author to receive API keys and examples. While not a direct secret-exfiltration mechanism, this weakens the stated security posture and can normalize off-platform credential distribution without clear provenance or handling controls.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest presents the package as a documentation-only evaluation/deployment guide, but the body includes promotional links to multiple external AI services and products. This broadens the effective scope from neutral documentation to marketing-driven redirection, which can bias user decisions and increase exposure to third-party ecosystems not required for the documented task.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

该文档在连接参数中直接要求使用 serverTimezone=Asia/Shanghai,并说明“必须显式指定”,属于对特定地区/时区的固定约束。文中未说明该技能仅适用于中国区部署,也未提供按用户或部署地区调整时区的选项,可能违反语言/locale 相关的组织策略。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The entire skill content is written as prescriptive guidance in Chinese and includes direct instruction text such as '给用户结论时按这个结构讲', but it does not indicate that Chinese is optional or user-selected. Under the policy, forcing a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.