Lp1
- Category
- MCP Least Privilege
- Confidence
- 75% confidence
- Finding
The skill uses 'file_read' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This skill does what it claims: it sends user prompts to Volcengine to generate a video and saves the returned video locally.
Install only if you are comfortable sending prompts, image URLs, and related generation metadata to Volcengine. Store config.json carefully because it contains a live API key, do not commit or share it, and choose an explicit output path if you want to control where generated MP4 files are written.
The skill uses 'file_read' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
The skill uses 'network' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
The README explains that prompts and optional image URLs are sent to Volcengine's external API, but it does not clearly warn users that their input data leaves the local environment and may be processed, logged, or retained by a third party. In a media-generation skill, prompts and reference images can contain sensitive business, personal, or copyrighted content, so lack of disclosure increases the chance of unintended data exposure.
The README tells users to store a live API key in a local config.json file but gives no guidance about keeping that file out of version control, restricting file permissions, or preferring environment variables/secret stores. This creates a realistic risk of accidental credential exposure through commits, backups, screenshots, or shared project directories, which could allow unauthorized use of the external API and billing abuse.
The skill documentation states that generated videos are automatically downloaded and saved locally, but the warning is only implied in workflow/notes rather than clearly surfaced as a safety warning. In an agent setting, automatic filesystem writes can surprise users, overwrite expected locations, or persist untrusted remote content without explicit informed consent, making this a real documentation-related security issue.
The script transmits user-supplied prompt content and optional image URLs to an external third-party API, and it authenticates with a bearer API key. In this skill context that transmission is expected, but it is still security-relevant because sensitive prompts or internal image URLs could be sent off-host without validation or clear minimization, and the code also prints request/response bodies that may expose sensitive data in logs.
print()
try:
response = requests.post(
self.create_task_url,
headers=self.headers,
json=payload,
This code's description and all user-visible messages are written in Chinese, and it also explicitly reconfigures stdout for UTF-8 output. For a general-purpose video generation utility, this imposes a specific language/locale on users without any opt-in or documented regional limitation.
The manifest description focuses on using the SD1.5pro API for text-to-video and image-to-video generation with asynchronous task handling. In addition to that expected API interaction, the script retrieves the returned video URL and writes the video to a local filesystem path, which is extra behavior not described in the manifest.
No suspicious patterns detected.