Back to skill

Security audit

Dygod Movies

Security checks for vulnerabilities and agentic risk

Overview

The skill does perform movie search and NAS downloading as advertised, but it ships real-looking NAS credentials and exposes privileged download actions without adequate protection.

Review before installing. Do not use this package as published with the embedded NAS credentials; rotate that password if it is real, move secrets into protected configuration, use HTTPS, restrict the service to trusted hosts, add authentication and explicit confirmation for downloads and deletions, and constrain allowed destinations.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/dygod_crawler.py:531
Finding

Hard-Coded NAS Credentials Expose Privileged DownloadStation Access

Content
View full analysis
Optional[str]: """Log in to Synology and obtain a SID.""" url = f"http://{SYNOLOGY_HOST}:{SYNOLOGY_PORT}/webapi/entry.cgi" params = { "api": "SYNO.API.Auth", "version": 6, "method": "login", "account": SYNOLOGY_USER, "passwd": SYNOLOGY_PASS, "session": session, "format": "sid" } try: resp = requests.get(url, params=params, timeout=10) data = resp.json() if data.get("success"): return data["data"]["sid"] except Exception as e: print(f"[Login failed] {e}") return None ``` The same credential is disclosed in the documentation: ```bash curl.exe -s "http://192.168.123.223:5000/webapi/entry.cgi?api=SYNO.API.Auth&version=6&method=login&account=xiaoai&passwd=Xx654321&session=DownloadStation&format=sid" ``` ### Technical Analysis A fixed NAS username, password, host address, and port are embedded directly in both executable source code and user-facing documentation. Anyone with access to the Skill package can recover the credentials without executing the application. The credentials are not installation placeholders: the script directly submits them to the Synology authentication API. Secret exposure is compounded by transmission over unencrypted HTTP and placement in URL query parameters. URLs may be retained in proxy logs, network appliance logs, debugging output, browser history, or monitoring systems. Embedding a reusable NAS credential exceeds the minimum privilege needed for movie lookup and crawling. Even for the declared optional download ...[truncated 1486 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
service/main.py:160
Finding

Unauthenticated Network Endpoint Can Create Arbitrary NAS Download Tasks

Content
View full analysis
Dict: links = movie.get("download_links", []) if not links: return {"success": False, "error": "No download link"} magnet_links = [l for l in links if l.startswith("magnet:")] ftp_links = [l for l in links if l.startswith("ftp://")] uri = magnet_links[0] if magnet_links else (ftp_links[0] if ftp_links else links[0]) result = syno_add_download(uri, destination) ``` ### Technical Analysis The `/download` endpoint performs a privileged action using the service's NAS credentials but has no authentication, authorization, user confirmation, request signing, or origin restriction. When run directly, the application listens on every network interface. The `magnet` parameter name does not impose a security boundary. If the supplied value does not start with `magnet:` or `ftp://`, `download ...[truncated 2401 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/dygod_crawler.py:547
Finding

NAS Credentials and Session Identifiers Are Transmitted over Unencrypted HTTP

Content
View full analysis
Optional[str]: url = f"http://{SYNOLOGY_HOST}:{SYNOLOGY_PORT}/webapi/entry.cgi" params = { "api": "SYNO.API.Auth", "version": 6, "method": "login", "account": SYNOLOGY_USER, "passwd": SYNOLOGY_PASS, "session": session, "format": "sid" } try: resp = requests.get(url, params=params, timeout=10) data = resp.json() if data.get("success"): return data["data"]["sid"] except Exception as e: print(f"[Login failed] {e}") return None ``` ```python def syno_logout(sid: str, session: str = "DownloadStation") -> bool: url = f"http://{SYNOLOGY_HOST}:{SYNOLOGY_PORT}/webapi/entry.cgi" params = { "api": "SYNO.API.Auth", "version": 6, "method": "logout", "session": session, "_sid": sid } try: resp = requests.get(url, params=params, timeout=10) return resp.json().get("success", False) except: return False ``` ```python def syno_add_download(uri: str, destination: str = None) -> Dict: sid = syno_login() if not sid: return {"success": False, "error": "Login failed"} url = f"http://{SYNOLOGY_HOST}:{SYNOLOGY_PORT}/webapi/DownloadStation/task.cgi" data = { "api": "SYNO.DownloadStation.Task", "version": 1, "method": "create", "uri": uri, "_sid": sid } if destination: data["destination"] = destination try: resp = requests.post(url, data=data, timeout=15) result = resp.json() # Response handling omitted. finall ...[truncated 2694 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (28)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill includes hardcoded Synology credentials and instructions to authenticate to a local NAS at 192.168.123.223, then create, list, and delete Download Station tasks. This exposes secrets, enables unauthorized access to an internal device, and expands behavior beyond simple movie lookup into privileged management of a local system.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

This skill contains authenticated NAS management capabilities beyond simple content lookup, including listing and deleting download tasks. Expanding from scraping into privileged device control increases attack surface and creates opportunities for unintended or unauthorized manipulation of a user's NAS.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file hardcodes Synology host, username, and password directly in source code, exposing reusable credentials to anyone who can read the skill or its logs/backups. The login is performed over HTTP, so the credentials and session may also be intercepted on the network, enabling full abuse of the NAS download service and possibly broader NAS access.

Content

No source excerpt is available for this finding.

Possible Typosquatting: 'uvicorn' resembles popular package 'gunicorn'

High
Category
Supply Chain
Confidence
70% confidence
Finding

Package name closely resembles a popular package, suggesting possible typosquatting. Attackers publish malicious packages with similar names to trick developers into installing them.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill documents capabilities that require network access and likely local file read/write caching, but it declares no explicit tool scope or permission boundaries. In an agent setting, this weakens reviewability and can allow broader-than-expected access, especially because the skill interacts with external sites and a local NAS.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

L005 将触发条件写为“当用户询问最近更新的电影/电视剧、高分电影、或想下载影视资源时使用此技能”。其中“想下载影视资源”范围过宽,容易覆盖普通闲聊或泛化的下载请求,且未给出明确边界或排除条件。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The documentation promotes one-click submission of magnet/FTP resources to a NAS downloader without sufficiently warning about operational and security consequences. Because this can enqueue untrusted content on a local system and manage download tasks, the lack of strong risk disclosure and approval checkpoints increases the chance of unsafe or unintended actions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The cache contains actionable download URIs (magnet, FTP via jianpian://) rather than just browse/query metadata. In the context of a skill that supports one-click NAS downloads, embedding these links enables direct acquisition of potentially untrusted or unauthorized content and expands risk from passive listing to active content delivery.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The module documentation frames the code as a crawler, but the implementation also performs authenticated NAS operations. This mismatch can mislead reviewers and users about the true privilege level and behavior of the skill, weakening informed consent and security review.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
76% confidence
Finding

The crawler extracts arbitrary text fields from a third-party site and later formats them for presentation, which can relay attacker-controlled natural-language content to downstream users or agents. In an agent setting, echoed untrusted text can carry prompt-injection instructions, misleading links, or social-engineering content that influences later actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code can create download tasks on the NAS as soon as it is invoked, without an explicit confirmation step at the point of execution. That makes it easy for ambiguous prompts, prompt injection via scraped content, or misuse of the skill to cause unwanted downloads, bandwidth consumption, or storage abuse.

Content

No source excerpt is available for this finding.

Tainted flow: 'data' from requests.get (line 561, network input) → requests.post (network output)

Medium
Category
Data Flow
Confidence
79% confidence
Finding

The NAS download request posts a URI that ultimately comes from untrusted third-party scraped content. Although the destination host is fixed to the Synology API rather than attacker-controlled, this still lets external content trigger internal side effects by causing the NAS to fetch arbitrary magnet/FTP/ed2k resources.

Content

Scanner excerpt · scripts/dygod_crawler.py (reported line 611)May include surrounding context.

python
data["destination"] = destination
    
    try:
        resp = requests.post(url, data=data, timeout=15)
        result = resp.json()
        
        if result.get("success"):

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The /download endpoint triggers a real file-affecting action on downstream infrastructure using fully user-controlled inputs, with no authentication, authorization, validation, or confirmation step visible in this file. In the context of a skill intended to download content to a Synology NAS, this is more dangerous than a generic demo action because a remote caller may be able to cause unauthorized downloads, abuse storage/bandwidth, or potentially influence destination handling depending on how download_movie processes the path.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
71% confidence
Finding

L003-L005 的描述整体以中文固定表述技能用途与交互场景,文件中未说明是否支持其他语言或允许用户选择输出语言。对于通用影视查询/下载技能,这种隐含的单一语言约束缺少显式用户选择。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This JSON dataset uses Chinese field names and titles throughout, making the content effectively tied to a single language/locale. Under the stated policy, forcing a specific language without user opt-in or a documented regional justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This JSON cache stores all human-readable titles and categories exclusively in Chinese, including locale-specific labels such as "国语版", with no indication that users can choose another language or that the dataset is intentionally region-specific. Under the policy, a language/locale constraint should either be optional for the user or clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The request headers explicitly set Accept-Language to prefer zh-CN, which imposes a specific language/locale behavior. There is no indication that the user can opt into this locale or that the locale restriction is required and documented as part of a region-specific tool.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file's natural-language descriptions and endpoint text are presented in Chinese only, including the service description and parameter descriptions. There is no indication that users can choose a language or that the locale restriction is intentional and documented as region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

On startup, the service automatically posts its internal host, port, capabilities, and endpoints to a gateway over plain HTTP by default. This exposes service metadata to interception or tampering on the network and can enable service discovery abuse, especially because the advertised base_url contains a private IP that may reveal internal topology.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The dependency is specified with a lower-bound range instead of an exact pinned version, which makes builds non-reproducible and can silently introduce vulnerable or incompatible releases over time. In a network-facing FastAPI service, this increases supply-chain risk because the actual installed version may differ across environments and may later resolve to a compromised or vulnerable release.

Content

Scanner excerpt · service/requirements.txt (reported line 1)May include surrounding context.

text
fastapi>=0.115.0
uvicorn>=0.32.0
httpx>=0.27.0
requests>=2.32.0

Unverifiable Dependency: fastapi has 3 known advisory(ies) (CVE-2021-32677 (Cross-Site Request Forgery (CSRF) in FastAPI); CVE-2021-32677 (FastAPI is a web framework for building APIs with Python 3.6+ based on standard ); CVE-2024-24762 (FastAPI is a web framework for building APIs with Python 3.8+ based on standard )), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
93% confidence
Finding

FastAPI has known advisories, and because the manifest does not pin a specific version, it is impossible to verify from this file alone whether the deployed version is affected. In a web service, unverifiable framework versions weaken assurance and can hide exposure to known server-side flaws.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

Using uvicorn>=0.32.0 leaves the runtime version unconstrained above the minimum, allowing unreviewed versions to be installed. For an internet-exposed ASGI server, this can lead to inconsistent deployments and accidental exposure to newly introduced flaws or behavioral changes.

Content

Scanner excerpt · service/requirements.txt (reported line 2)May include surrounding context.

text
fastapi>=0.115.0
uvicorn>=0.32.0
httpx>=0.27.0
requests>=2.32.0
beautifulsoup4>=4.12.0

Unverifiable Dependency: uvicorn has 4 known advisory(ies) (CVE-2020-7694 (Log injection in uvicorn); CVE-2020-7695 (HTTP response splitting in uvicorn); CVE-2020-7694 (This affects all versions of package uvicorn. The request logger provided by the) +1 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
93% confidence
Finding

Uvicorn has published advisories, but the loose version specifier prevents determining whether the installed release is vulnerable. Because uvicorn is the HTTP server for the application, unverifiable versions create unnecessary exposure in a network-facing component.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The httpx dependency is not pinned, so different environments may install different versions without code changes. Because this skill likely performs outbound HTTP requests to scrape content, that creates avoidable supply-chain and reliability risk if a later release contains a security regression.

Content

Scanner excerpt · service/requirements.txt (reported line 3)May include surrounding context.

text
fastapi>=0.115.0
uvicorn>=0.32.0
httpx>=0.27.0
requests>=2.32.0
beautifulsoup4>=4.12.0

Unverifiable Dependency: httpx has 2 known advisory(ies) (CVE-2021-41945 (Improper Input Validation in httpx); CVE-2021-41945 (Encode OSS httpx <=1.0.0.beta0 is affected by improper input validation in `http)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
91% confidence
Finding

The file does not identify an exact httpx release, so known advisories cannot be ruled out for the actual deployment. Since the skill likely makes external HTTP requests to scrape third-party sites, ambiguity in the HTTP client version increases risk and complicates incident response.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.