Back to skill

Security audit

AI短视频脚本生成器

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent short-video script generator, but its payment and AI web app ships exposed credentials and unsafe payment/session controls that users should review before running.

Do not run this as-is with real users or real billing. Require rotated provider keys loaded from secrets, server-side payment verification per billable action, explicit disclosure before sending prompts to SiliconFlow, safe DOM rendering, debug disabled, and private binding or production deployment controls.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/app.py:18
Finding

Hard-Coded Payment and AI Provider Credentials

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/app.py:13
Finding

Payment Verification Bypass Through a Forgeable Flask Session

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
templates/index.html:119
Finding

Stored and AI-Sourced DOM Cross-Site Scripting

Content
View full analysis
{ const item = document.createElement('a'); item.className = 'list-group-item list-group-item-action'; item.href = 'javascript:;'; item.innerHTML = ` ${script.topic}
${script.platform} | ${script.duration} seconds | ${new Date(script.created_at).toLocaleString()} `; item.onclick = () => loadScript(script.id); list.appendChild(item); }); ``` Generated and persisted script fields are also rendered as HTML: ```javascript function renderScript(script) { const result = document.getElementById('result'); result.innerHTML = `
Golden 3-Second Hook

${script.hook}

Shot Script
${script.shots.map(shot => `
${shot.time}: ${shot.description}
`).join('')}
Voiceover

${script.voiceover}

Subtitle Copy

${script.subtitle}

Background Music Recommendation

${script.bgm}

Closing CTA

${script.cta}

`; } ``` The topic is accepted and persisted without output-safe encoding: ```python data = request.get_json() topic = data.get('topic', '') platform = data.get('platform', '' ...[truncated 2857 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/app.py:243
Finding

Flask Development Debugger Exposed on All Network Interfaces

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill description understates important behaviors: external AI API calls, payment interactions, and persistent local storage. This mismatch is dangerous because users and reviewers may authorize a simple script generator without realizing it performs billing and stores user data, creating consent, privacy, and financial risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The documentation contains a live-looking payment API key in plaintext. Embedded secrets can be harvested from the repository or package and abused for unauthorized charges, fraudulent payment operations, or account takeover of the payment integration.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill declares no explicit tool scope or permissions even though its documented behavior requires network access for AI generation and payment processing. Missing permission boundaries reduces transparency and can allow unexpected external communications, making review and user consent harder.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill advertises save, delete, and export functionality without clearly warning users that their data will be persisted and modified. In a content-generation context, this can lead to silent storage of user-provided ideas or business content and unexpected destructive actions on saved scripts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The text explicitly states '全中文界面' (Chinese-only interface), which is a language constraint. The file does not indicate user opt-in, optional language selection, or a documented region-specific justification for restricting the skill to Chinese.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
99% confidence
Finding

The file contains a hardcoded API key for the external AI provider. Embedded secrets in source code are easily leaked through repository access, deployments, logs, or package distribution, allowing unauthorized use of the account, billing abuse, and potential access to associated data.

Content

Scanner excerpt · scripts/app.py (reported line 34)May include surrounding context.

python
# 硅基流动API配置
SILICONFLOW_API_KEY = 'sk-ggfjehtmwgthcdyajhpipxhurytmnmqsnvpfzoripdgdmzar'
SILICONFLOW_API_URL = 'https://api.siliconflow.cn/v1/chat/completions'
AI_MODEL = 'Doubao-ai/doubao-seed-v2-18k'

# 初始化数据库

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The prompt hard-codes Chinese instructions and output expectations for generated scripts, which imposes a language choice without user opt-in. The file does not indicate that this is a region-specific or Chinese-only skill, nor does it provide an option to select another language.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/app.py (reported line 105)May include surrounding context.

python
'max_tokens': 2000,
            'response_format': {"type": "json_object"}
        }
        resp = requests.post(SILICONFLOW_API_URL, headers=headers, json=payload, timeout=30)
        data = resp.json()
        content = data['choices'][0]['message']['content']
        return json.loads(content)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The generate_script flow sends the user-provided topic and platform data to the SiliconFlow API via an outbound HTTP request. Although there is error logging, there is no confirmation prompt, user-facing notice, or explanatory comment/docstring warning that user content will leave the local system and be processed by a third-party service.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

This code transmits billing requests to an external payment service automatically using a generated session user_id, without stronger user binding or explicit transaction confirmation in the charge path. In context, the danger is not the transmission itself but unauthorized or surprise charging behavior caused by how it is invoked.

Content

Scanner excerpt · scripts/app.py (reported line 131)May include surrounding context.

python
if TEST_MODE:
        return {"ok": True, "balance": 1000}
    try:
        resp = requests.post(f"{BILLING_URL}/charge", headers=HEADERS, json={
            "user_id": user_id, "skill_id": SKILL_ID, "amount": 0.001,
        }, timeout=10)
        data = resp.json()

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The before_request hook automatically attempts to charge the user before most routes, including API actions, based only on session state and without an explicit per-action confirmation in this code path. This can lead to surprise billing, repeated charge attempts across sessions, and user harm if requests are triggered unintentionally or cross-site.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/app.py (reported line 172)May include surrounding context.

python
if TEST_MODE:
        return redirect(url_for('index', test_payment='success'))
    try:
        resp = requests.post(f"{BILLING_URL}/payment-link", headers=HEADERS, json={
            "user_id": user_id, "amount": 0.001,
        }, timeout=10)
        payment_url = resp.json().get("payment_url")

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document language is hard-coded to zh-CN and the visible interface text is entirely Chinese, with no indication that users can choose another language or that the skill is intentionally region-specific. This can violate language/locale policy when a skill imposes a specific locale without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Backend-provided script fields are interpolated directly into innerHTML in renderScript(), including topic, hook, voiceover, subtitle, bgm, cta, and shot descriptions. If any of that content is attacker-controlled or model-generated with embedded HTML/JavaScript, it can trigger stored or reflected XSS when viewed from history or immediately after generation; in this skill context, user input and generated content flow through the backend, making this especially plausible.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The DELETE route permanently removes stored script records from the database. The code contains no confirmation step, user-visible warning, or explanatory comment indicating that the action is destructive and irreversible.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The HTML document explicitly sets lang="zh-CN", and all visible UI text is presented only in Chinese. This creates a natural-language locale restriction without any opt-in, alternative language path, or documented region-specific justification in the file.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.