Back to skill

Security audit

三剪客 · 音效生成、视频配音

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a real a7w audio/video API client, but it handles API keys and can redirect authenticated requests to arbitrary hosts despite documentation saying keys only go to api.a7w.cn.

Install only if you trust a7w.cn with your media URLs, prompts, generated task data, API key, and billing account. Avoid using --host or A7W_HOST unless you intentionally trust that endpoint, review ~/.a7w/config.json after login, and do not submit private/internal media links or sensitive signed URLs without understanding the provider's retention and access policies.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (20)

Tainted flow: 'req' from os.environ.get (line 151, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
96% confidence
Finding

The client allows the destination host to be overridden from an environment variable, CLI flag, or config file, then sends the Bearer API key to that host in every request. If an attacker can influence A7W_HOST or the saved config, they can redirect requests to an attacker-controlled server and exfiltrate the credential; in an agent/platform setting, environment-variable control is a realistic threat boundary issue.

Content

Scanner excerpt · scripts/client.py (reported line 111)May include surrounding context.

python
headers["Content-Type"] = "application/json"
    req = urllib.request.Request(url, data=data, headers=headers, method=method)
    try:
        with urllib.request.urlopen(req, timeout=timeout) as resp:
            raw = resp.read().decode("utf-8", "replace")
            status = resp.status
    except urllib.error.HTTPError as exc:

Tainted flow: 'req' from os.environ.get (line 151, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
96% confidence
Finding

This second request path has the same issue: request_soft() constructs authenticated requests using a host that may come from environment/config and transmits the Authorization header to that endpoint. The dump flow can amplify exposure by iterating many requests, but the core risk is credential exfiltration to an attacker-controlled host.

Content

Scanner excerpt · scripts/client.py (reported line 153)May include surrounding context.

python
headers["Content-Type"] = "application/json"
    req = urllib.request.Request(url, data=data, headers=headers, method=method)
    try:
        with urllib.request.urlopen(req, timeout=timeout) as resp:
            return json.loads(resp.read().decode("utf-8", "replace")), resp.status
    except urllib.error.HTTPError as exc:
        raw = exc.read().decode("utf-8", "replace")

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
description: "音效生成、视频配音,任务由平台弹性部署调度。支持 提交任务、查询任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 7)May include surrounding context.

md
description: "音效生成、视频配音,任务由平台弹性部署调度。支持 提交任务、查询任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README presents all user-facing instructions and operational guidance exclusively in Chinese, which can amount to a language/locale policy violation when no user choice or opt-in is offered. The policy specifically flags skills that force a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill advertises and demonstrates code-assisted operations (env, file, network, shell) but does not declare an explicit permission or allowed-tools scope. That creates a trust and containment gap: an agent may execute broader capabilities than a user expects, including handling API keys and making outbound requests to a third-party service.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
76% confidence
Finding

The skill instructs users to obtain and use an API key with an external service, which implies secrets and user data may be transmitted off-platform to api.a7w.cn. In this context, the risk is not the mere presence of a URL, but that the skill is built around sending prompts/media and credentials to a third party without an explicit security/privacy disclosure in the permission model.

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
name: mmaudio
slug: mmaudio
displayName: 三剪客 · 音效生成、视频配音
description: "音效生成、视频配音,任务由平台弹性部署调度。支持 提交任务、查询任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「音效生成、视频配音」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 11)May include surrounding context.

md
displayName: 三剪客 · 音效生成、视频配音
description: "音效生成、视频配音,任务由平台弹性部署调度。支持 提交任务、查询任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「音效生成、视频配音」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT
tags:
  - 三剪客

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 95)May include surrounding context.

md
displayName: 三剪客 · 音效生成、视频配音
description: "音效生成、视频配音,任务由平台弹性部署调度。支持 提交任务、查询任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「音效生成、视频配音」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT
tags:
  - 三剪客

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 104)May include surrounding context.

md
displayName: 三剪客 · 音效生成、视频配音
description: "音效生成、视频配音,任务由平台弹性部署调度。支持 提交任务、查询任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「音效生成、视频配音」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT
tags:
  - 三剪客

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 7)May include surrounding context.

md
displayName: 三剪客 · 音效生成、视频配音
description: "音效生成、视频配音,任务由平台弹性部署调度。支持 提交任务、查询任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「音效生成、视频配音」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT
tags:
  - 三剪客

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

The example command shows submission of externally hosted audio/video URLs and prompt content to a third-party API. In a multimedia skill this is contextually expected, but it still creates a real data-exfiltration/privacy boundary: user media, prompts, and potentially sensitive content may be sent to an external platform.

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

python3 scripts/client.py call mmaudio submit --json '{"prompt": "Generate natural cinematic sound effects and ambience for this video.", "duration": 15.695, "audio_url": "https://example.com/reference_audio.wav", "input_url": "https://example.com/silent_video.mp4"}'

text

> **没有 Key?** 见 `references/getting-started.md`——注册、充值、取 Key 的完整步骤。也可以直接去 [算力集市](https://api.a7w.cn/) 注册。

## 接口一览

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation instructs users to submit externally hosted video and optional audio URLs to a third-party API platform without any privacy, consent, or data-handling warning. This can lead to unintentional disclosure of sensitive media, internal URLs, signed links, or personal data to an external service, especially because the skill is specifically designed to transmit user-provided content off-platform for processing.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module docstring explicitly states this is a 'general client' that can call any plugin in the a7w plugin marketplace. That is broader than the manifest, which presents this skill as an MMAudio capability for sound-effect generation and video dubbing rather than a universal remote client for arbitrary plugins.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module docstring and all user-facing help and status text are written in Chinese, which effectively imposes a specific language on users of the skill. The file does not offer any language selection, fallback, or documented reason that this client must be Chinese-only.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This markdown file presents all user-facing instructions and descriptions in Chinese only, including the title, parameter descriptions, and billing notes. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document title and all user-facing instructions are written only in Chinese, with no indication that other languages are supported or that Chinese is required for a region-specific reason. This can violate language/locale policy when a skill implicitly forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes the skill as focused on audio generation/video dubbing with support for submitting tasks and querying tasks. However, the bundled client exposes broader marketplace-inspection operations such as listing all available plugins, viewing arbitrary plugin schemas, and dumping all schemas, which goes beyond the stated task-submit/task-query scope.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
99% confidence
Finding

The top-level usage text says client.py whoami verifies the key and shows account and balance. In code, cmd_whoami only calls /api/v1/apps, emits key prefix and app list/count, and explicitly notes that the gateway does not provide account/balance APIs.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
99% confidence
Finding

The usage section says client.py points means 'check balance'. But cmd_points explicitly documents that no balance API exists and instead totals points_cost from recent tasks as a reference, which is materially different from an actual balance lookup.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.