Back to skill

Security audit

三剪客 · Wan 视频生成

Security checks for vulnerabilities and agentic risk

Overview

The skill is a mostly coherent Wan video API wrapper, but its bundled client can send saved API credentials to an overridden host and can invoke broader marketplace APIs than the Wan-only purpose suggests.

Review before installing. Use this only if you trust api.a7w.cn and the publisher with your prompts, media URLs, callback URLs, and API key. Avoid using --host or A7W_HOST unless you intentionally point at a trusted server, and prefer limiting agent use to 'wan query' and 'wan create' rather than the client's generic marketplace commands. Treat the a7w API key like a spending credential and revoke it if it may have been exposed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (19)

Tainted flow: 'req' from os.environ.get (line 151, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

The client allows the request destination to be overridden from CLI/config/environment via the host value, then sends the bearer API key to that URL in the Authorization header. If an attacker can influence A7W_HOST or saved config, they can redirect requests to an attacker-controlled server and exfiltrate credentials and request payloads.

Content

Scanner excerpt · scripts/client.py (reported line 111)May include surrounding context.

python
headers["Content-Type"] = "application/json"
    req = urllib.request.Request(url, data=data, headers=headers, method=method)
    try:
        with urllib.request.urlopen(req, timeout=timeout) as resp:
            raw = resp.read().decode("utf-8", "replace")
            status = resp.status
    except urllib.error.HTTPError as exc:

Tainted flow: 'req' from os.environ.get (line 151, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

This softer request path has the same issue as the main request path: user-controlled host data flows into outbound requests while attaching the bearer token. That enables silent credential disclosure during schema/app enumeration if host configuration is tampered with.

Content

Scanner excerpt · scripts/client.py (reported line 153)May include surrounding context.

python
headers["Content-Type"] = "application/json"
    req = urllib.request.Request(url, data=data, headers=headers, method=method)
    try:
        with urllib.request.urlopen(req, timeout=timeout) as resp:
            return json.loads(resp.read().decode("utf-8", "replace")), resp.status
    except urllib.error.HTTPError as exc:
        raw = exc.read().decode("utf-8", "replace")

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as a narrowly scoped Wan video-generation wrapper, but the detected behavior indicates a generic client that can enumerate apps, fetch schemas for arbitrary plugins, export data locally, manage API keys, and call arbitrary marketplace APIs. This mismatch is dangerous because users or orchestrators may grant trust based on the narrow description while the bundled client has much broader reach.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
型族视频生成应用。版本通过 model 参数选择,支持文生视频、角色参考生视频与视频编辑。支持 查询视频任务、创建视频任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.c

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 7)May include surrounding context.

md
型族视频生成应用。版本通过 model 参数选择,支持文生视频、角色参考生视频与视频编辑。支持 查询视频任务、创建视频任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.c

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill advertises executable client commands and the package reportedly includes code capabilities (env, file read/write, network, shell), but the manifest declares no explicit tool scope or permission boundaries. In an agent setting, this increases the chance of over-broad execution, unintended filesystem access, or network use without clear user-visible constraints.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 11)May include surrounding context.

md
name: wan-video
slug: wan-video
displayName: 三剪客 · Wan 视频生成
description: "Wan 模型族视频生成应用。版本通过 model 参数选择,支持文生视频、角色参考生视频与视频编辑。支持 查询视频任务、创建视频任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「Wan 视频生成」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 95)May include surrounding context.

md
name: wan-video
slug: wan-video
displayName: 三剪客 · Wan 视频生成
description: "Wan 模型族视频生成应用。版本通过 model 参数选择,支持文生视频、角色参考生视频与视频编辑。支持 查询视频任务、创建视频任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「Wan 视频生成」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 104)May include surrounding context.

md
name: wan-video
slug: wan-video
displayName: 三剪客 · Wan 视频生成
description: "Wan 模型族视频生成应用。版本通过 model 参数选择,支持文生视频、角色参考生视频与视频编辑。支持 查询视频任务、创建视频任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「Wan 视频生成」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
name: wan-video
slug: wan-video
displayName: 三剪客 · Wan 视频生成
description: "Wan 模型族视频生成应用。版本通过 model 参数选择,支持文生视频、角色参考生视频与视频编辑。支持 查询视频任务、创建视频任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「Wan 视频生成」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 7)May include surrounding context.

md
name: wan-video
slug: wan-video
displayName: 三剪客 · Wan 视频生成
description: "Wan 模型族视频生成应用。版本通过 model 参数选择,支持文生视频、角色参考生视频与视频编辑。支持 查询视频任务、创建视频任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「Wan 视频生成」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

md
name: wan-video
slug: wan-video
displayName: 三剪客 · Wan 视频生成
description: "Wan 模型族视频生成应用。版本通过 model 参数选择,支持文生视频、角色参考生视频与视频编辑。支持 查询视频任务、创建视频任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.6
summary: "「Wan 视频生成」的完整调用封装:2 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description and summary broadly describe the skill as a general Wan video generation wrapper, but they do not define specific trigger phrases, activation boundaries, or exclusion conditions. For manifest/markdown-scoped trigger review, this can cause unintended invocation because the skill's applicable user requests are not clearly delimited.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The entire user-facing document is written in Chinese and provides no indication that other languages are supported or that Chinese is a required locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file is presented as a wan-video skill, but the implementation is a generic marketplace client that can enumerate and invoke any available plugin. This scope expansion increases the attack surface and allows the skill to perform actions unrelated to the declared video-generation purpose, undermining least privilege and user expectations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The dump command enumerates all apps and exports every plugin schema to a local file, which exceeds the declared functionality of a wan-video skill. In practice this can aid reconnaissance of the wider plugin marketplace and expose metadata about capabilities the user did not intend this skill to access.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The call command permits arbitrary app and API selection, effectively turning this skill into a universal proxy for the entire a7w marketplace rather than a dedicated wan-video integration. In the skill context this is more dangerous because users and orchestrators may grant trust based on the narrow wan-video description while the code can trigger unrelated remote actions and costs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

这是一个 markdown 文件,适用缺少用户警示检查。文档说明平台会处理用户提交的图片、视频、音频 URL 并支持向 callback_url 发送任务完成/失败通知,但未明确提醒这些内容会被传输到平台及外部回调端点,涉及用户数据与系统集成行为。

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

鉴权部分展示了 Authorization: Bearer <YOUR_API_KEY>,但没有任何文字提醒 API Key 属于敏感凭证、不得泄露或嵌入公开客户端。对于会触发计费和任务操作的接口,缺少这类用户警示属于文档层面的安全提示不足。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.