Back to skill

Security audit

neo-ai

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real Neodomain image/video generator, but it needs review because it handles access tokens unsafely and can upload local files to external storage without tight limits.

Review before installing. Use this only if you are comfortable sending prompts, reference media, generated outputs, and selected local storyboard images to Neodomain/OSS. Avoid passing verification codes or tokens directly on command lines, do not store long-lived bearer tokens in shell startup files, and do not use the standalone uploader on sensitive local paths. Prefer pinned dependencies and an isolated virtual environment.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/login.py:98
Finding

Access Tokens and Verification Codes Are Exposed Through Process Arguments and Terminal Output

Content
View full analysis
> ~/.zshrc source ~/.zshrc ``` ### Technical Analysis The login script accepts the one-time verification code through a command-line argument. Depending on the ope ...[truncated 1894 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/upload_oss.py:40
Finding

Arbitrary Local Files Can Be Uploaded to Externally Addressable Object Storage

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:403
Finding

Third-Party Dependencies Are Installed Without Version or Integrity Pinning

Content
View full analysis
Requires `pip install oss2` (used to upload local images to OSS). ``` ```bash # Install ClawHub CLI if unavailable npm i -g clawhub ``` The scripts then load whichever `oss2` package is present: ```python def upload_to_oss(local_file: str, token: str): """Upload file to OSS using STS token.""" import oss2 ``` ### Technical Analysis The project has no dependency manifest, lockfile, version constraint, or package hash for `oss2`. Installation documentation also recommends installing the latest available `clawhub` package globally through npm. Package versions can therefore change after the Skill is reviewed. A compromised package release, compromised registry account, malicious transitive dependency, or unexpected incompatible release could execute code during installation or at import time. Global npm installation increases the affected scope because the package is installed outside an isolated project environment. The audit found no evidence that the named packages are currently malicious. The finding concerns the unsafe and non-reproducible dependency acquisition process. ### Attack Path 1. A user follows the documented `pip install oss2` or `npm i -g clawhub` instruction. 2. The package manager resolves the latest package and transitive dependencies at installation time. 3. A compromised or unexpectedly modified release is downloaded without project-specified hash verification. 4. Installation hooks, setup code, or imported package code executes with the user's privileges. 5. Malicious dependency code can access the same local files, environment variables, network connectivity, and Neod ...[truncated 472 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate_video.py:85
Finding

Remote API Responses Can Trigger Unrestricted and Unbounded File Downloads

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (49)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill documents batch workflows that upload local files to OSS/cloud storage and generate public URLs, but this data egress behavior is not clearly reflected in the top-level description. Undisclosed upload capability is security-relevant because local user content may be exfiltrated to third-party storage, potentially exposing sensitive images, prompts, or metadata.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill documents batch workflows that upload local files to OSS/cloud storage and generate public URLs, but this data egress behavior is not clearly reflected in the top-level description. Undisclosed upload capability is security-relevant because local user content may be exfiltrated to third-party storage, potentially exposing sensitive images, prompts, or metadata.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill documents batch workflows that upload local files to OSS/cloud storage and generate public URLs, but this data egress behavior is not clearly reflected in the top-level description. Undisclosed upload capability is security-relevant because local user content may be exfiltrated to third-party storage, potentially exposing sensitive images, prompts, or metadata.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill documents batch workflows that upload local files to OSS/cloud storage and generate public URLs, but this data egress behavior is not clearly reflected in the top-level description. Undisclosed upload capability is security-relevant because local user content may be exfiltrated to third-party storage, potentially exposing sensitive images, prompts, or metadata.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill documents batch workflows that upload local files to OSS/cloud storage and generate public URLs, but this data egress behavior is not clearly reflected in the top-level description. Undisclosed upload capability is security-relevant because local user content may be exfiltrated to third-party storage, potentially exposing sensitive images, prompts, or metadata.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill documents batch workflows that upload local files to OSS/cloud storage and generate public URLs, but this data egress behavior is not clearly reflected in the top-level description. Undisclosed upload capability is security-relevant because local user content may be exfiltrated to third-party storage, potentially exposing sensitive images, prompts, or metadata.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill documents batch workflows that upload local files to OSS/cloud storage and generate public URLs, but this data egress behavior is not clearly reflected in the top-level description. Undisclosed upload capability is security-relevant because local user content may be exfiltrated to third-party storage, potentially exposing sensitive images, prompts, or metadata.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · INSTALL.md (reported line 113)May include surrounding context.

md
parser.add_argument("--scenario-type", type=int, default=1, 
                        help="Scenario type: 1-图片工具, 2-画布, 3-重绘, 4-设计, 5-分镜")
    parser.add_argument("--user-id", help="User ID for membership priority")
    parser.add_argument("--token", "--access-token", dest="token", help="Access token")
    
    args = parser.parse_args()

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/batch_video.py (reported line 132)May include surrounding context.

python
parser.add_argument("--scenario-type", type=int, default=1, 
                        help="Scenario type: 1-图片工具, 2-画布, 3-重绘, 4-设计, 5-分镜")
    parser.add_argument("--user-id", help="User ID for membership priority")
    parser.add_argument("--token", "--access-token", dest="token", help="Access token")
    
    args = parser.parse_args()

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/batch_video.py (reported line 142)May include surrounding context.

python
parser.add_argument("--scenario-type", type=int, default=1, 
                        help="Scenario type: 1-图片工具, 2-画布, 3-重绘, 4-设计, 5-分镜")
    parser.add_argument("--user-id", help="User ID for membership priority")
    parser.add_argument("--token", "--access-token", dest="token", help="Access token")
    
    args = parser.parse_args()

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/generate_image.py (reported line 102)May include surrounding context.

python
parser.add_argument("--scenario-type", type=int, default=1, 
                        help="Scenario type: 1-图片工具, 2-画布, 3-重绘, 4-设计, 5-分镜")
    parser.add_argument("--user-id", help="User ID for membership priority")
    parser.add_argument("--token", "--access-token", dest="token", help="Access token")
    
    args = parser.parse_args()

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/generate_image.py (reported line 111)May include surrounding context.

python
parser.add_argument("--scenario-type", type=int, default=1, 
                        help="Scenario type: 1-图片工具, 2-画布, 3-重绘, 4-设计, 5-分镜")
    parser.add_argument("--user-id", help="User ID for membership priority")
    parser.add_argument("--token", "--access-token", dest="token", help="Access token")
    
    args = parser.parse_args()

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/generate_image_ref.py (reported line 102)May include surrounding context.

python
parser.add_argument("--scenario-type", type=int, default=1, 
                        help="Scenario type: 1-图片工具, 2-画布, 3-重绘, 4-设计, 5-分镜")
    parser.add_argument("--user-id", help="User ID for membership priority")
    parser.add_argument("--token", "--access-token", dest="token", help="Access token")
    
    args = parser.parse_args()

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/generate_image_ref.py (reported line 111)May include surrounding context.

python
parser.add_argument("--scenario-type", type=int, default=1, 
                        help="Scenario type: 1-图片工具, 2-画布, 3-重绘, 4-设计, 5-分镜")
    parser.add_argument("--user-id", help="User ID for membership priority")
    parser.add_argument("--token", "--access-token", dest="token", help="Access token")
    
    args = parser.parse_args()

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/generate_video.py (reported line 136)May include surrounding context.

python
parser.add_argument("--scenario-type", type=int, default=1, 
                        help="Scenario type: 1-图片工具, 2-画布, 3-重绘, 4-设计, 5-分镜")
    parser.add_argument("--user-id", help="User ID for membership priority")
    parser.add_argument("--token", "--access-token", dest="token", help="Access token")
    
    args = parser.parse_args()

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/generate_video.py (reported line 145)May include surrounding context.

python
parser.add_argument("--scenario-type", type=int, default=1, 
                        help="Scenario type: 1-图片工具, 2-画布, 3-重绘, 4-设计, 5-分镜")
    parser.add_argument("--user-id", help="User ID for membership priority")
    parser.add_argument("--token", "--access-token", dest="token", help="Access token")
    
    args = parser.parse_args()

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/image_models.py (reported line 42)May include surrounding context.

python
parser.add_argument("--scenario-type", type=int, default=1, 
                        help="Scenario type: 1-图片工具, 2-画布, 3-重绘, 4-设计, 5-分镜")
    parser.add_argument("--user-id", help="User ID for membership priority")
    parser.add_argument("--token", "--access-token", dest="token", help="Access token")
    
    args = parser.parse_args()

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/image_models.py (reported line 52)May include surrounding context.

python
parser.add_argument("--scenario-type", type=int, default=1, 
                        help="Scenario type: 1-图片工具, 2-画布, 3-重绘, 4-设计, 5-分镜")
    parser.add_argument("--user-id", help="User ID for membership priority")
    parser.add_argument("--token", "--access-token", dest="token", help="Access token")
    
    args = parser.parse_args()

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/motion_control.py (reported line 106)May include surrounding context.

python
parser.add_argument("--scenario-type", type=int, default=1, 
                        help="Scenario type: 1-图片工具, 2-画布, 3-重绘, 4-设计, 5-分镜")
    parser.add_argument("--user-id", help="User ID for membership priority")
    parser.add_argument("--token", "--access-token", dest="token", help="Access token")
    
    args = parser.parse_args()

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/motion_control.py (reported line 115)May include surrounding context.

python
parser.add_argument("--scenario-type", type=int, default=1, 
                        help="Scenario type: 1-图片工具, 2-画布, 3-重绘, 4-设计, 5-分镜")
    parser.add_argument("--user-id", help="User ID for membership priority")
    parser.add_argument("--token", "--access-token", dest="token", help="Access token")
    
    args = parser.parse_args()

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/upload_oss.py (reported line 76)May include surrounding context.

python
parser.add_argument("--scenario-type", type=int, default=1, 
                        help="Scenario type: 1-图片工具, 2-画布, 3-重绘, 4-设计, 5-分镜")
    parser.add_argument("--user-id", help="User ID for membership priority")
    parser.add_argument("--token", "--access-token", dest="token", help="Access token")
    
    args = parser.parse_args()

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/upload_oss.py (reported line 84)May include surrounding context.

python
parser.add_argument("--scenario-type", type=int, default=1, 
                        help="Scenario type: 1-图片工具, 2-画布, 3-重绘, 4-设计, 5-分镜")
    parser.add_argument("--user-id", help="User ID for membership priority")
    parser.add_argument("--token", "--access-token", dest="token", help="Access token")
    
    args = parser.parse_args()

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/video_models.py (reported line 58)May include surrounding context.

python
parser.add_argument("--scenario-type", type=int, default=1, 
                        help="Scenario type: 1-图片工具, 2-画布, 3-重绘, 4-设计, 5-分镜")
    parser.add_argument("--user-id", help="User ID for membership priority")
    parser.add_argument("--token", "--access-token", dest="token", help="Access token")
    
    args = parser.parse_args()

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/video_models.py (reported line 66)May include surrounding context.

python
parser.add_argument("--scenario-type", type=int, default=1, 
                        help="Scenario type: 1-图片工具, 2-画布, 3-重绘, 4-设计, 5-分镜")
    parser.add_argument("--user-id", help="User ID for membership priority")
    parser.add_argument("--token", "--access-token", dest="token", help="Access token")
    
    args = parser.parse_args()

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · INSTALL.md (reported line 62)May include surrounding context.

md
#!/usr/bin/env python3
"""
Neodomain AI - Authentication Script
Send verification code and login to get access token.
"""

import argparse

Static analysis

No suspicious patterns detected.