Back to skill

Security audit

三剪客 · 音色修改、AI翻唱

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly documents a paid a7w voice-conversion workflow, but its bundled client can use the user's API key against configurable hosts and broader marketplace APIs than the narrow skill description implies.

Review this skill before installing if you only want a tightly scoped seedsvc voice-conversion client. Use it only with audio you are allowed to send to a third-party processing service, treat the API key as a billing credential, and avoid setting --host or A7W_HOST unless you deliberately trust that endpoint to receive your key.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (19)

Tainted flow: 'req' from os.environ.get (line 151, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
96% confidence
Finding

The request destination is influenced by the user-configurable host value, which can come from the A7W_HOST environment variable or stored config, and the client always attaches the Bearer API key before sending the request. This enables credential exfiltration to an attacker-controlled endpoint if the host is overridden, making the tainted network flow a real security issue in the context of an agent skill that may run with user secrets loaded.

Content

Scanner excerpt · scripts/client.py (reported line 111)May include surrounding context.

python
headers["Content-Type"] = "application/json"
    req = urllib.request.Request(url, data=data, headers=headers, method=method)
    try:
        with urllib.request.urlopen(req, timeout=timeout) as resp:
            raw = resp.read().decode("utf-8", "replace")
            status = resp.status
    except urllib.error.HTTPError as exc:

Tainted flow: 'req' from os.environ.get (line 151, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
96% confidence
Finding

This is the same core issue in the soft-request path used for bulk schema enumeration: the host is externally controllable and the Authorization header is sent to whatever URL is constructed. An attacker who can influence environment/config/arguments can redirect authenticated traffic and harvest the user's API key or observe sensitive plugin metadata.

Content

Scanner excerpt · scripts/client.py (reported line 153)May include surrounding context.

python
headers["Content-Type"] = "application/json"
    req = urllib.request.Request(url, data=data, headers=headers, method=method)
    try:
        with urllib.request.urlopen(req, timeout=timeout) as resp:
            return json.loads(resp.read().decode("utf-8", "replace")), resp.status
    except urllib.error.HTTPError as exc:
        raw = exc.read().decode("utf-8", "replace")

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documented purpose is limited to submitting and querying voice-conversion jobs, but the detected behavior includes enumerating arbitrary plugins, dumping schemas, persisting API keys locally, viewing usage/points, and calling any marketplace plugin. This mismatch is dangerous because users and calling agents may grant trust or data based on the narrow description while the bundled client enables broader account and API activity than disclosed.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 11)May include surrounding context.

一把 api.a7w.cn 的 API Key。完整的注册、充值、取 Key 步骤见 references/getting-started.md, 或直接去 算力集市 · 注册领 API Key。

bash
python3 scripts/client.py login --key sk-你的key

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 95)May include surrounding context.

一把 api.a7w.cn 的 API Key。完整的注册、充值、取 Key 步骤见 references/getting-started.md, 或直接去 算力集市 · 注册领 API Key。

bash
python3 scripts/client.py login --key sk-你的key

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 104)May include surrounding context.

一把 api.a7w.cn 的 API Key。完整的注册、充值、取 Key 步骤见 references/getting-started.md, 或直接去 算力集市 · 注册领 API Key。

bash
python3 scripts/client.py login --key sk-你的key

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

一把 api.a7w.cn 的 API Key。完整的注册、充值、取 Key 步骤见 references/getting-started.md, 或直接去 算力集市 · 注册领 API Key。

bash
python3 scripts/client.py login --key sk-你的key

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 104)May include surrounding context.

一把 api.a7w.cn 的 API Key。完整的注册、充值、取 Key 步骤见 references/getting-started.md, 或直接去 算力集市 · 注册领 API Key。

bash
python3 scripts/client.py login --key sk-你的key

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 113)May include surrounding context.

一把 api.a7w.cn 的 API Key。完整的注册、充值、取 Key 步骤见 references/getting-started.md, 或直接去 算力集市 · 注册领 API Key。

bash
python3 scripts/client.py login --key sk-你的key

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises only a narrow media-conversion function, but the analysis indicates underlying capabilities for environment access, filesystem access, shell use, and network access without any declared tool restrictions. That creates unnecessary privilege and weakens containment, increasing the chance that a compromised or misleading skill could access secrets, modify local files, or make arbitrary outbound requests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill asks users to submit audio URLs for processing by an external service but does not clearly warn that those URLs and associated content will be transmitted to a third party. This can lead to unintended disclosure of sensitive or copyrighted media, especially if users assume processing is local or confined to the agent environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation instructs users to submit reference and source audio URLs to an external platform but does not warn that those URLs may expose user audio content or sensitive data to a third-party service. In a voice-conversion and AI cover context, audio may contain personal, copyrighted, or biometric voice data, so omission of a privacy/data-sharing warning can lead to unintended disclosure and consent issues.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is presented as a narrow voice-conversion/task client, but the code is a generic marketplace client that can enumerate apps, inspect schemas, and invoke arbitrary APIs. This scope mismatch is dangerous because it expands the agent's effective capabilities beyond what a user would reasonably expect, increasing the chance of unintended access or misuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language documentation and CLI help text that are written only in Chinese, which can force a specific language experience on users without their consent. The policy for natural-language content requires avoiding language/locale constraints unless the skill offers a choice or clearly justifies the restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

User-facing strings throughout the CLI, including errors, prompts, command descriptions, and runtime status messages, are presented only in Chinese. Because there is no locale flag, environment-based language selection, or documented opt-in, the skill enforces a single language in a way that violates the language/locale policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The file presents all user-facing instructions exclusively in Chinese, which can constitute a language/locale policy issue when no user opt-in or alternative language is offered. The document does not state that the skill is intentionally China/Chinese-only or otherwise region-specific.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The top-level docstring says 'client.py whoami # 验证 key,看账号与余额', which implies account and balance retrieval. However, cmd_whoami only calls /api/v1/apps, returns key prefix and app list, and explicitly notes that the gateway does not expose account/balance APIs.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
99% confidence
Finding

The usage text says 'client.py points # 查余额', but cmd_points explicitly states there is no public balance endpoint and instead sums recent task usage. This is an active contradiction between the advertised command behavior and the actual code.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The dump and schema-discovery features expose additional capability beyond the stated submit/query task scope. While not inherently exploit code, these features broaden the accessible attack surface and enable reconnaissance of all available plugins and parameters through the user's authenticated account.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.