Back to skill

Security audit

三剪客 · 数字人对口型

Security checks for vulnerabilities and agentic risk

Overview

This is a usable lipsync API wrapper, but its bundled client is broader than advertised and can send the user's API key to a user-configured host.

Review before installing. Use a dedicated, revocable, low-balance a7w API key; avoid --host, A7W_HOST, or untrusted config changes; and do not submit confidential audio or video URLs unless you accept processing by the external a7w service. Expect the bundled client to be able to call more than the lipsync endpoints if used that way.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (20)

Tainted flow: 'req' from os.environ.get (line 151, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
94% confidence
Finding

The request destination is influenced by the user-controlled host value resolved from command-line arguments, environment variables, or local config, and the client automatically attaches the Bearer API key to every outbound request. This allows credential exfiltration to an arbitrary server if A7W_HOST/--host/config is tampered with, turning the generic HTTP client into an SSRF-like secret-leaking proxy.

Content

Scanner excerpt · scripts/client.py (reported line 111)May include surrounding context.

python
headers["Content-Type"] = "application/json"
    req = urllib.request.Request(url, data=data, headers=headers, method=method)
    try:
        with urllib.request.urlopen(req, timeout=timeout) as resp:
            raw = resp.read().decode("utf-8", "replace")
            status = resp.status
    except urllib.error.HTTPError as exc:

Tainted flow: 'req' from os.environ.get (line 151, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
94% confidence
Finding

The soft-request path has the same issue as the main request path: a caller-controlled host can receive authenticated requests containing the user's API key. Because this path is used for bulk enumeration, it can leak credentials repeatedly across many requests once the host is redirected.

Content

Scanner excerpt · scripts/client.py (reported line 153)May include surrounding context.

python
headers["Content-Type"] = "application/json"
    req = urllib.request.Request(url, data=data, headers=headers, method=method)
    try:
        with urllib.request.urlopen(req, timeout=timeout) as resp:
            return json.loads(resp.read().decode("utf-8", "replace")), resp.status
    except urllib.error.HTTPError as exc:
        raw = exc.read().decode("utf-8", "replace")

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The documentation claims this is a narrow lipsync skill with two APIs, but the bundled client apparently supports generic platform-wide actions including listing apps, inspecting arbitrary schemas, calling any API, dumping schemas, and storing credentials locally. That mismatch is dangerous because users and orchestrators may grant trust or permissions based on the declared limited purpose while the actual behavior enables broader data access, persistence, and external interaction.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
description: "数字人对口型(Lipsync),任务由平台弹性部署调度。支持 提交任务、查询任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 7)May include surrounding context.

md
description: "数字人对口型(Lipsync),任务由平台弹性部署调度。支持 提交任务、查询任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file implements a platform-wide generic client rather than a lipsync-scoped client, enabling access to any plugin available to the supplied API key. In the context of a skill advertised as 'lipsync', this is dangerous because an agent or user may grant trust expecting a narrow media capability while actually exposing a broad remote-action surface.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The call command permits arbitrary application and API selection with arbitrary JSON bodies, effectively exposing a universal remote procedure client under the cover of a specialized lipsync skill. This breaks least privilege and makes the skill context more dangerous because downstream users may unknowingly enable actions far beyond media generation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The entire skill description, usage guidance, and safety information are presented only in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking audience. This can violate language/locale policy requirements when a skill imposes a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
80% confidence
Finding

The skill advertises executable client workflows that require network, file, shell, and secret-handling capabilities, but it does not declare any tool scope or permission boundaries. In an agent environment, this under-specification increases the risk that the skill is invoked with broader access than users expect, enabling unintended file writes, outbound requests, or secret usage.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The display name, description, summary, and body text are presented entirely in Chinese, and the file does not offer an alternative language or indicate that the skill is intentionally limited to Chinese-speaking users. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 11)May include surrounding context.

md
name: lipsync
slug: lipsync
displayName: 三剪客 · 数字人对口型
description: "数字人对口型(Lipsync),任务由平台弹性部署调度。支持 提交任务、查询任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.4
summary: "「数字人对口型」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 95)May include surrounding context.

md
name: lipsync
slug: lipsync
displayName: 三剪客 · 数字人对口型
description: "数字人对口型(Lipsync),任务由平台弹性部署调度。支持 提交任务、查询任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.4
summary: "「数字人对口型」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 104)May include surrounding context.

md
name: lipsync
slug: lipsync
displayName: 三剪客 · 数字人对口型
description: "数字人对口型(Lipsync),任务由平台弹性部署调度。支持 提交任务、查询任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.4
summary: "「数字人对口型」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
name: lipsync
slug: lipsync
displayName: 三剪客 · 数字人对口型
description: "数字人对口型(Lipsync),任务由平台弹性部署调度。支持 提交任务、查询任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.4
summary: "「数字人对口型」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 7)May include surrounding context.

md
name: lipsync
slug: lipsync
displayName: 三剪客 · 数字人对口型
description: "数字人对口型(Lipsync),任务由平台弹性部署调度。支持 提交任务、查询任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.4
summary: "「数字人对口型」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

md
name: lipsync
slug: lipsync
displayName: 三剪客 · 数字人对口型
description: "数字人对口型(Lipsync),任务由平台弹性部署调度。支持 提交任务、查询任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.4
summary: "「数字人对口型」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file describes an API that sends user-provided audio and video URLs to a platform for lip-sync task processing, which can affect user data and privacy. The description explains functionality and billing, but provides no warning that media URLs and referenced content will be transmitted to an external service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The entire skill documentation is written in Chinese and provides no indication that other languages are supported or that Chinese is required for a region-specific or compliance-related reason. This can violate a language/locale policy when users are not given a language choice or opt-in.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The dump command enumerates all available apps and exports their schemas, which is unrelated to the declared lipsync purpose and materially expands reconnaissance capability. In an agent setting, this helps map the wider platform for later abuse and may expose sensitive operational metadata about other plugins.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

whoami 子命令帮助为“查看当前账号”,points 子命令帮助为“查看余额”,但实现中 whoami 只是用 /api/v1/apps 验证 key 并列出应用,points 则仅汇总最近任务消耗,并在函数内注明网关未公开相关接口。帮助文案与实际行为存在主动误导,用户会以为能查询真实账号身份或余额。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.