Back to skill

Security audit

三剪客 · Grok 视频生成

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a legitimate a7w/Grok video client, but its bundled CLI can use the same API key to inspect and call any a7w marketplace app, which is broader than the video-only framing.

Review before installing. Use this only if you are comfortable giving the bundled client an a7w API key that can potentially access more than Grok video. Prefer invoking only grok_video submit/query, avoid untrusted --host/A7W_HOST values, and monitor account usage or charges.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (18)

Tainted flow: 'req' from os.environ.get (line 151, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/client.py (reported line 111)May include surrounding context.

python
headers["Content-Type"] = "application/json"
    req = urllib.request.Request(url, data=data, headers=headers, method=method)
    try:
        with urllib.request.urlopen(req, timeout=timeout) as resp:
            raw = resp.read().decode("utf-8", "replace")
            status = resp.status
    except urllib.error.HTTPError as exc:

Tainted flow: 'req' from os.environ.get (line 151, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/client.py (reported line 153)May include surrounding context.

python
headers["Content-Type"] = "application/json"
    req = urllib.request.Request(url, data=data, headers=headers, method=method)
    try:
        with urllib.request.urlopen(req, timeout=timeout) as resp:
            raw = resp.read().decode("utf-8", "replace")
            status = resp.status
    except urllib.error.HTTPError as exc:

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared purpose is narrowly framed as Grok video task submission/query, but the bundled client reportedly supports broader marketplace enumeration, arbitrary app inspection, arbitrary API calls, schema dumping, and local API key storage. That mismatch is dangerous because operators may grant trust and permissions appropriate for a narrow media skill while the actual behavior enables much wider data access and outbound interactions.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
description: "Grok 视频生成应用,支持快速视频生成和标准生成视频。支持 创建视频任务、查询视频任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 7)May include surrounding context.

md
description: "Grok 视频生成应用,支持快速视频生成和标准生成视频。支持 创建视频任务、查询视频任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The call command accepts arbitrary app and api identifiers and submits arbitrary JSON/parameters, effectively turning the skill into a universal broker for the entire a7w marketplace rather than a Grok video tool. In the skill context this is more dangerous because users and agents will reasonably trust the declared narrow purpose, while the implementation permits unrelated remote actions, unexpected charges, and interaction with unknown third-party capabilities using the user's API key.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The user-facing guidance section is entirely written in Chinese, which imposes a specific language on users without any opt-in or alternative language option. Under the policy, locale or language constraints should either be optional for the user or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill advertises executable client functionality with capabilities including environment access, filesystem reads/writes, network access, and shell usage, but it declares no explicit tool scope or permission boundaries. In an agent setting, this makes the skill harder to sandbox and review, increasing the risk of overbroad execution, unintended side effects, or misuse of local secrets and system resources.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 11)May include surrounding context.

md
name: grok-video
slug: grok-video
displayName: 三剪客 · Grok 视频生成
description: "Grok 视频生成应用,支持快速视频生成和标准生成视频。支持 创建视频任务、查询视频任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「Grok 视频生成」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 95)May include surrounding context.

md
name: grok-video
slug: grok-video
displayName: 三剪客 · Grok 视频生成
description: "Grok 视频生成应用,支持快速视频生成和标准生成视频。支持 创建视频任务、查询视频任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「Grok 视频生成」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 104)May include surrounding context.

md
name: grok-video
slug: grok-video
displayName: 三剪客 · Grok 视频生成
description: "Grok 视频生成应用,支持快速视频生成和标准生成视频。支持 创建视频任务、查询视频任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「Grok 视频生成」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
name: grok-video
slug: grok-video
displayName: 三剪客 · Grok 视频生成
description: "Grok 视频生成应用,支持快速视频生成和标准生成视频。支持 创建视频任务、查询视频任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「Grok 视频生成」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 7)May include surrounding context.

md
name: grok-video
slug: grok-video
displayName: 三剪客 · Grok 视频生成
description: "Grok 视频生成应用,支持快速视频生成和标准生成视频。支持 创建视频任务、查询视频任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「Grok 视频生成」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

md
name: grok-video
slug: grok-video
displayName: 三剪客 · Grok 视频生成
description: "Grok 视频生成应用,支持快速视频生成和标准生成视频。支持 创建视频任务、查询视频任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「Grok 视频生成」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill description does not define when the skill should activate, what user intents it is limited to, or what operations require explicit confirmation. Ambiguous trigger boundaries increase the chance that an agent invokes a networked, credential-using client in contexts beyond simple video generation, especially given the broader capabilities noted elsewhere.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The documentation explicitly supports sending task completion data to a user-supplied callback URL, but it does not warn about the privacy, authenticity, or SSRF-related risks of doing so. If integrators pass untrusted or misconfigured callback endpoints, task metadata and result URLs may be disclosed to third parties, and consumers may wrongly trust unsigned callbacks as authentic platform events.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill metadata presents this as a Grok video-generation integration, but the bundled client is a generic marketplace client that can enumerate and invoke any app/API on the a7w platform. This creates a scope mismatch: an agent or user enabling the skill for video generation may unknowingly grant a broad action surface well beyond the declared purpose, increasing the chance of unintended data access or costly side effects.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The dump command bulk-enumerates all available apps and exports their schemas to a local JSON file, which is unnecessary for a narrowly scoped video-generation skill. In an agent setting, this broad discovery capability can be used to map the entire external platform, reveal undocumented or sensitive integration surface, and facilitate later misuse of unrelated APIs.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.