Back to skill

Security audit

三剪客 · 人物替换

Security checks for vulnerabilities and agentic risk

Overview

The skill performs the stated person-replacement workflow, but its bundled client is broader than the skill description and can send the user's API key to a configurable host.

Review this before installing if you expected a narrowly scoped person-replacement helper. Use only a trusted api.a7w.cn host, avoid --host or A7W_HOST unless you control the endpoint, consider deleting any saved host override from ~/.a7w/config.json, and do not upload sensitive face/video media to public file hosts without consent and a clear retention plan.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (19)

Tainted flow: 'req' from os.environ.get (line 151, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
96% confidence
Finding

The client allows the destination host to be overridden via command-line arguments, environment variable (A7W_HOST), or local config, then sends the Bearer API key to that URL with urllib. This creates a credential-exfiltration/SSRF class issue: if an attacker can influence the environment, config, or invocation arguments, they can redirect requests to an attacker-controlled server and capture the API key.

Content

Scanner excerpt · scripts/client.py (reported line 111)May include surrounding context.

python
headers["Content-Type"] = "application/json"
    req = urllib.request.Request(url, data=data, headers=headers, method=method)
    try:
        with urllib.request.urlopen(req, timeout=timeout) as resp:
            raw = resp.read().decode("utf-8", "replace")
            status = resp.status
    except urllib.error.HTTPError as exc:

Tainted flow: 'req' from os.environ.get (line 151, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
96% confidence
Finding

This duplicate sink has the same security property in request_soft(): the code builds an authenticated request using a host derived from args/environment/config and transmits the Authorization header to whatever endpoint is configured. In the context of an agent skill, this is more dangerous because the skill may run in automation where environment variables or config can be manipulated without the user noticing, causing silent API key leakage to an attacker-controlled endpoint.

Content

Scanner excerpt · scripts/client.py (reported line 153)May include surrounding context.

python
headers["Content-Type"] = "application/json"
    req = urllib.request.Request(url, data=data, headers=headers, method=method)
    try:
        with urllib.request.urlopen(req, timeout=timeout) as resp:
            return json.loads(resp.read().decode("utf-8", "replace")), resp.status
    except urllib.error.HTTPError as exc:
        raw = exc.read().decode("utf-8", "replace")

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose is a single media-editing workflow, but the package appears to include a generic client for invoking arbitrary a7w plugins, listing all plugins, exporting schemas, storing API keys locally, and querying task/points data. This mismatch is dangerous because users and host systems may grant trust and permissions appropriate for a narrow skill, while the embedded client enables broader platform interaction, data collection, and credential handling not disclosed in the description.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
description: "人物替换,基于参考图片和输入视频生成替换后的视频结果。支持 提交任务、查询任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 7)May include surrounding context.

md
description: "人物替换,基于参考图片和输入视频生成替换后的视频结果。支持 提交任务、查询任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README explicitly instructs users to place input images and videos at publicly accessible URLs, including temporary file-sharing services, without warning that these media may contain sensitive personal data. For a person-replacement workflow, the inputs are likely to contain faces and biometric information, so making them public materially increases the risk of privacy leakage, unauthorized reuse, and indexing by third parties.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill advertises only a narrow 'person replacement' function, yet static analysis detected capabilities for environment access, file read/write, shell, and network without any declared permissions or tool scope. In an agent environment, this makes the skill overly powerful and opaque, increasing the risk of unintended data access, local persistence, secret handling, or arbitrary outbound requests beyond the stated purpose.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 13)May include surrounding context.

md
name: person-replacement
slug: person-replacement
displayName: 三剪客 · 人物替换
description: "人物替换,基于参考图片和输入视频生成替换后的视频结果。支持 提交任务、查询任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「人物替换」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 115)May include surrounding context.

md
name: person-replacement
slug: person-replacement
displayName: 三剪客 · 人物替换
description: "人物替换,基于参考图片和输入视频生成替换后的视频结果。支持 提交任务、查询任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「人物替换」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 124)May include surrounding context.

md
name: person-replacement
slug: person-replacement
displayName: 三剪客 · 人物替换
description: "人物替换,基于参考图片和输入视频生成替换后的视频结果。支持 提交任务、查询任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「人物替换」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
name: person-replacement
slug: person-replacement
displayName: 三剪客 · 人物替换
description: "人物替换,基于参考图片和输入视频生成替换后的视频结果。支持 提交任务、查询任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「人物替换」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 7)May include surrounding context.

md
name: person-replacement
slug: person-replacement
displayName: 三剪客 · 人物替换
description: "人物替换,基于参考图片和输入视频生成替换后的视频结果。支持 提交任务、查询任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「人物替换」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

md
name: person-replacement
slug: person-replacement
displayName: 三剪客 · 人物替换
description: "人物替换,基于参考图片和输入视频生成替换后的视频结果。支持 提交任务、查询任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「人物替换」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-query.md (reported line 40)May include surrounding context.

}

text

## cURL 示例

```bash
curl -X POST "https://你的域名/api/v1/apps/person_replacement/query" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation instructs users to send reference image URLs, video URLs, and a bearer API key to a third-party service but does not include any warning about privacy, consent, retention, or handling of potentially sensitive biometric/media data. Because the skill processes person images and videos for face/person replacement, omitting these disclosures increases the risk of unsafe or non-compliant use, especially where personal data or likeness rights are involved.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-submit.md (reported line 81)May include surrounding context.

}

text

## cURL 示例

```bash
curl -X POST "https://你的域名/api/v1/apps/person_replacement/submit" \

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The document title and all user-facing instructions are written entirely in Chinese, with no indication that other languages are supported or that Chinese is required for a region-specific purpose. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The natural-language instructions throughout the README force a specific language experience for users without any opt-in or indication that the skill is intentionally limited to a Chinese-speaking audience. This can violate language or locale policy when no user choice or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The entire skill documentation is written in Chinese and does not indicate any user language choice, multilingual alternative, or explicit justification for a Chinese-only locale. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.