Back to skill

Security audit

AIsa Media Gen

Security checks for vulnerabilities and agentic risk

Overview

This media-generation skill mostly matches its stated purpose, but its video download helper can fetch and save an unvalidated URL supplied by the API, so it needs review before installation.

Review this skill before installing. Use it only if you trust AIsa with your prompts, reference image URLs, and API key. Prefer AISA_API_KEY over --api-key, avoid using --download unless you trust the returned media source, and choose output paths carefully because files may be overwritten.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/media_gen_client.py:84
Finding

Unrestricted Download of a Server-Supplied URL

Content
View full analysis
Dict[str, Any]: """ Download a (possibly signed) URL to local file. Designed for OSS signed URLs returned by video generation tasks. """ os.makedirs(os.path.dirname(out_path) or ".", exist_ok=True) req = urllib.request.Request(url, headers={"User-Agent": "OpenClaw-Media-Gen/1.0"}) try: with urllib.request.urlopen(req, timeout=timeout_s) as resp, open(out_path, "wb") as f: total = 0 while True: chunk = resp.read(1024 * 1024) # 1MB if not chunk: break f.write(chunk) total += len(chunk) return {"success": True, "saved_to": out_path, "bytes": total} except Exception as e: return {"success": False, "error": str(e), "url": url, "saved_to": out_path} ``` The download is initiated using a URL taken directly from the task-status response: ```python if status == "SUCCEEDED" and getattr(args, "download", False): video_url = (resp.get("output") or {}).get("video_url") or (resp.get("output") or {}).get("videoUrl") if video_url: out_path = args.out or _safe_filename("mp4") dl = _download_to_file(video_url, out_path) resp = {**resp, "download": dl} ``` ### Technical Analysis The client trusts `video_url` returned by the remote AIsa API and passes it directly to `urllib.request.urlopen`. It does not validate: - The URL scheme, such as requiring HTTPS. - Whether the destination belongs to an expected media-storage domain. - Whether the destination resolves to a loopback, private, link-local, or otherwise sensitive address. - Redirect destinations. - The response content t ...[truncated 2115 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/media_gen_client.py:31
Finding

API Credential Can Be Exposed Through Command-Line Arguments

Content
View full analysis
str: api_key = explicit or os.environ.get("AISA_API_KEY") if not api_key: raise ValueError("AISA_API_KEY is required (env or --api-key).") return api_key ``` The command-line option that supplies the secret is registered as follows: ```python p = argparse.ArgumentParser(description="OpenClaw Media Gen - image & video generation") p.add_argument("--api-key", help="Override AISA_API_KEY") ``` Commands subsequently retrieve the value through calls such as: ```python api_key = _get_api_key(args.api_key) ``` ### Technical Analysis The client permits the AIsa bearer credential to be supplied as `--api-key`. Command-line arguments are not an appropriate secret-transport mechanism because they may be exposed through: - Shell history files. - Process-listing utilities. - Process monitoring and observability agents. - Debug logs that record complete command lines. - Job-runner metadata or terminal-session recordings. The documented environment-variable method is safer than passing the key as an argument, but the availability of the command-line override encourages insecure use. The key is legitimately required for the declared media-generation API, so possession and network use of the credential are necessary. Exposing it through process arguments is not necessary. ### Attack Path 1. A user runs the client with a command such as `media_gen_client.py --api-key SECRET image ...`. 2. The shell records the command in its history, or the operating system exposes the active process arguments. 3. Another local user, monitoring service, support bundle, or log collector obtains the command line. 4. The observer extracts the AIsa API key. 5. The ...[truncated 735 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (18)

Tainted flow: 'req' from os.environ.get (line 65, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/media_gen_client.py (reported line 67)May include surrounding context.

python
req = urllib.request.Request(url, data=data, headers=all_headers, method=method.upper())
    try:
        with urllib.request.urlopen(req, timeout=timeout_s) as resp:
            raw = resp.read().decode("utf-8")
            return json.loads(raw) if raw else {}
    except urllib.error.HTTPError as e:

Tainted flow: 'req' from os.environ.get (line 65, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

The downloader fetches an arbitrary URL returned by the remote task response and writes the response body directly to disk without validating the scheme, host, content type, or size. If the upstream service or response is compromised, this can be abused for SSRF-like access to internal resources from the user's machine, or for untrusted file writes and disk exhaustion.

Content

Scanner excerpt · scripts/media_gen_client.py (reported line 93)May include surrounding context.

python
os.makedirs(os.path.dirname(out_path) or ".", exist_ok=True)
    req = urllib.request.Request(url, headers={"User-Agent": "OpenClaw-Media-Gen/1.0"})
    try:
        with urllib.request.urlopen(req, timeout=timeout_s) as resp, open(out_path, "wb") as f:
            total = 0
            while True:
                chunk = resp.read(1024 * 1024)  # 1MB

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares environment-variable and network-dependent behavior but does not define an explicit tool scope such as permissions or allowed-tools. This can cause the runtime to grant broader capabilities than users expect, increasing the chance of unintended outbound requests or secret exposure through the documented API calls.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The natural-language instructions and capability descriptions are presented in Chinese, but the file does not indicate that the skill is region-specific or provide an option for another language. This can violate a language/locale policy when a skill implicitly forces one language without user opt-in.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

文档:google-gemini-chat(GenerateContent)见 https://aisa.mintlify.app/api-reference/chat/chat-api/google-gemini-chat.md。

curl 示例(返回 inline_data 时为图片)

bash
curl -X POST "https://api.aisa.one/v1/models/gemini-3-pro-image-preview:generateContent" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

md
OpenClaw Media Gen - AIsa API Client

Image:
  - Gemini GenerateContent: POST https://api.aisa.one/v1/models/{model}:generateContent

Video:
  - Wan 2.6 async task:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

md
OpenClaw Media Gen - AIsa API Client

Image:
  - Gemini GenerateContent: POST https://api.aisa.one/v1/models/{model}:generateContent

Video:
  - Wan 2.6 async task:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

md
OpenClaw Media Gen - AIsa API Client

Image:
  - Gemini GenerateContent: POST https://api.aisa.one/v1/models/{model}:generateContent

Video:
  - Wan 2.6 async task:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

md
OpenClaw Media Gen - AIsa API Client

Image:
  - Gemini GenerateContent: POST https://api.aisa.one/v1/models/{model}:generateContent

Video:
  - Wan 2.6 async task:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 100)May include surrounding context.

md
OpenClaw Media Gen - AIsa API Client

Image:
  - Gemini GenerateContent: POST https://api.aisa.one/v1/models/{model}:generateContent

Video:
  - Wan 2.6 async task:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/media_gen_client.py (reported line 6)May include surrounding context.

python
OpenClaw Media Gen - AIsa API Client

Image:
  - Gemini GenerateContent: POST https://api.aisa.one/v1/models/{model}:generateContent

Video:
  - Wan 2.6 async task:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/media_gen_client.py (reported line 10)May include surrounding context.

python
OpenClaw Media Gen - AIsa API Client

Image:
  - Gemini GenerateContent: POST https://api.aisa.one/v1/models/{model}:generateContent

Video:
  - Wan 2.6 async task:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/media_gen_client.py (reported line 11)May include surrounding context.

python
OpenClaw Media Gen - AIsa API Client

Image:
  - Gemini GenerateContent: POST https://api.aisa.one/v1/models/{model}:generateContent

Video:
  - Wan 2.6 async task:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/media_gen_client.py (reported line 28)May include surrounding context.

python
OpenClaw Media Gen - AIsa API Client

Image:
  - Gemini GenerateContent: POST https://api.aisa.one/v1/models/{model}:generateContent

Video:
  - Wan 2.6 async task:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/media_gen_client.py (reported line 29)May include surrounding context.

python
OpenClaw Media Gen - AIsa API Client

Image:
  - Gemini GenerateContent: POST https://api.aisa.one/v1/models/{model}:generateContent

Video:
  - Wan 2.6 async task:

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation states that generated image data will be automatically parsed and saved to a local file, and later also describes automatic MP4 download, without a clear warning that the skill modifies the filesystem. In agent contexts, silent writes can overwrite user files or create unexpected artifacts, especially when output paths are user-controlled or defaulted.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code writes generated image data to a filesystem path supplied by --out or to an auto-generated filename, but there is no confirmation prompt or explicit user-facing warning that a local file will be created or overwritten. For a code-file SQP-2 finding, file writes that lack disclosure can be flagged when the operation is not accompanied by a warning or confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

When --download is used, the script downloads a remote video URL and saves it locally, but the code does not emit a warning or confirmation message before performing the write. Although the flag implies intent, there is no explicit disclosure in code output about the file-write side effect or overwrite possibility.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.