Back to skill

Security audit

video-workflow-builder

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent video-workflow generator, but it needs review before installation because it routes agents through its own broad network fetchers, handles credentials, and persists/propagates generated workflow state.

Install only if you trust the publisher and are comfortable with a skill that uses local network fetching instead of built-in web tools. Use dedicated low-privilege API keys, verify every configured gateway hostname, avoid HTTP endpoints except intentional localhost hotlist use, keep Douyin session files and .env files out of shared repos/backups, and do not let generated finance workflows produce personalized trading advice without compliance review.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:58
Finding

Mandatory bypass of built-in network safety controls

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/web_search.py:196
Finding

Unrestricted full-page fetch permits server-side request forgery and local file access

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/web_search.py:66
Finding

Credentials and user content can be transmitted to arbitrary configured gateway origins

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/scrape_douyin.py:113
Finding

Reusable Douyin browser authentication state is persisted without adequate protection

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/requirements-douyin.txt:4
Finding

Unpinned packages and unverified external executable code create supply-chain exposure

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (141)

Tainted flow: 'req' from os.environ.get (line 60, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

The script builds the request URL from DAILYHOT_API_BASE sourced from an environment variable or local .env file and then performs a network request without validating the scheme, host, or destination. If an attacker can influence that configuration, they can redirect requests to arbitrary internal or external endpoints, creating an SSRF-style primitive and causing the tool to trust attacker-controlled JSON responses.

Content

Scanner excerpt · scripts/fetch_hotlist.py (reported line 61)May include surrounding context.

python
"""拉单个平台热榜,返回 (title, [items])。失败抛异常,绝不吞掉。"""
    url = "%s/%s" % (base, platform)
    req = urllib.request.Request(url, headers={"User-Agent": "peanutcut-hotlist/1.0"})
    with urllib.request.urlopen(req, timeout=timeout) as resp:
        payload = json.loads(resp.read().decode("utf-8"))
    # DailyHotApi 正常返回 {"code":200,"title":...,"data":[{title,hot,...}]}
    if payload.get("code") not in (200, "200", None):

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · .env.example (reported line 1)May include surrounding context.

text
# 复制本文件为 .env 并填入你自己的凭证;.env 已在 .gitignore 中,勿提交。
# 值只是占位符,请替换为你自己的真实凭证。

# ---- 生成器已有 ----

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · .env.example (reported line 1)May include surrounding context.

text
.env
__pycache__/
*.pyc
.DS_Store

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · .gitignore (reported line 1)May include surrounding context.

text
.env
__pycache__/
*.pyc
.DS_Store

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill directs the agent to perform generic web and image search, fetch full webpage content from arbitrary URLs, and use external gateway credentials, while presenting itself mainly as a narrow three-question workflow generator. This mismatch matters because arbitrary content retrieval and external service interaction increase exposure to malicious content, data exfiltration, and policy bypass scenarios.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill directs the agent to perform generic web and image search, fetch full webpage content from arbitrary URLs, and use external gateway credentials, while presenting itself mainly as a narrow three-question workflow generator. This mismatch matters because arbitrary content retrieval and external service interaction increase exposure to malicious content, data exfiltration, and policy bypass scenarios.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill directs the agent to perform generic web and image search, fetch full webpage content from arbitrary URLs, and use external gateway credentials, while presenting itself mainly as a narrow three-question workflow generator. This mismatch matters because arbitrary content retrieval and external service interaction increase exposure to malicious content, data exfiltration, and policy bypass scenarios.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill directs the agent to perform generic web and image search, fetch full webpage content from arbitrary URLs, and use external gateway credentials, while presenting itself mainly as a narrow three-question workflow generator. This mismatch matters because arbitrary content retrieval and external service interaction increase exposure to malicious content, data exfiltration, and policy bypass scenarios.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill directs the agent to perform generic web and image search, fetch full webpage content from arbitrary URLs, and use external gateway credentials, while presenting itself mainly as a narrow three-question workflow generator. This mismatch matters because arbitrary content retrieval and external service interaction increase exposure to malicious content, data exfiltration, and policy bypass scenarios.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill directs the agent to perform generic web and image search, fetch full webpage content from arbitrary URLs, and use external gateway credentials, while presenting itself mainly as a narrow three-question workflow generator. This mismatch matters because arbitrary content retrieval and external service interaction increase exposure to malicious content, data exfiltration, and policy bypass scenarios.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill directs the agent to perform generic web and image search, fetch full webpage content from arbitrary URLs, and use external gateway credentials, while presenting itself mainly as a narrow three-question workflow generator. This mismatch matters because arbitrary content retrieval and external service interaction increase exposure to malicious content, data exfiltration, and policy bypass scenarios.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill directs the agent to perform generic web and image search, fetch full webpage content from arbitrary URLs, and use external gateway credentials, while presenting itself mainly as a narrow three-question workflow generator. This mismatch matters because arbitrary content retrieval and external service interaction increase exposure to malicious content, data exfiltration, and policy bypass scenarios.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill directs the agent to perform generic web and image search, fetch full webpage content from arbitrary URLs, and use external gateway credentials, while presenting itself mainly as a narrow three-question workflow generator. This mismatch matters because arbitrary content retrieval and external service interaction increase exposure to malicious content, data exfiltration, and policy bypass scenarios.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill directs the agent to perform generic web and image search, fetch full webpage content from arbitrary URLs, and use external gateway credentials, while presenting itself mainly as a narrow three-question workflow generator. This mismatch matters because arbitrary content retrieval and external service interaction increase exposure to malicious content, data exfiltration, and policy bypass scenarios.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill directs the agent to perform generic web and image search, fetch full webpage content from arbitrary URLs, and use external gateway credentials, while presenting itself mainly as a narrow three-question workflow generator. This mismatch matters because arbitrary content retrieval and external service interaction increase exposure to malicious content, data exfiltration, and policy bypass scenarios.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill directs the agent to perform generic web and image search, fetch full webpage content from arbitrary URLs, and use external gateway credentials, while presenting itself mainly as a narrow three-question workflow generator. This mismatch matters because arbitrary content retrieval and external service interaction increase exposure to malicious content, data exfiltration, and policy bypass scenarios.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill directs the agent to perform generic web and image search, fetch full webpage content from arbitrary URLs, and use external gateway credentials, while presenting itself mainly as a narrow three-question workflow generator. This mismatch matters because arbitrary content retrieval and external service interaction increase exposure to malicious content, data exfiltration, and policy bypass scenarios.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill directs the agent to perform generic web and image search, fetch full webpage content from arbitrary URLs, and use external gateway credentials, while presenting itself mainly as a narrow three-question workflow generator. This mismatch matters because arbitrary content retrieval and external service interaction increase exposure to malicious content, data exfiltration, and policy bypass scenarios.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill directs the agent to perform generic web and image search, fetch full webpage content from arbitrary URLs, and use external gateway credentials, while presenting itself mainly as a narrow three-question workflow generator. This mismatch matters because arbitrary content retrieval and external service interaction increase exposure to malicious content, data exfiltration, and policy bypass scenarios.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill directs the agent to perform generic web and image search, fetch full webpage content from arbitrary URLs, and use external gateway credentials, while presenting itself mainly as a narrow three-question workflow generator. This mismatch matters because arbitrary content retrieval and external service interaction increase exposure to malicious content, data exfiltration, and policy bypass scenarios.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill directs the agent to perform generic web and image search, fetch full webpage content from arbitrary URLs, and use external gateway credentials, while presenting itself mainly as a narrow three-question workflow generator. This mismatch matters because arbitrary content retrieval and external service interaction increase exposure to malicious content, data exfiltration, and policy bypass scenarios.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The invocation description is broad enough to capture common finance-content requests, causing the skill to trigger in many situations where the user may only want generic discussion or harmless drafting help. In this context, over-broad routing is dangerous because it can steer users into a high-risk finance workflow that fetches data, creates files, and generates actionable market content without deliberate opt-in.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The exemplar directs the generated skill to produce explicit buy/sell/hold advice and price levels, which materially exceeds a workflow-builder's stated role and pushes the agent into personalized financial-advice behavior. In context, this is dangerous because downstream skills may inherit these instructions and present high-stakes investment recommendations without proper authorization, suitability checks, or compliance controls.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill explicitly instructs the agent to provide buy/sell recommendations and key price levels without any meaningful consent, suitability, jurisdiction, or compliance gate. Because financial decisions can cause direct monetary harm, this turns a content-creation exemplar into a mechanism for delivering unvetted actionable investment advice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description is written to define a Chinese-language video creation workflow for account content, but it does not offer a language choice or indicate that Chinese is optional. This can violate language/locale policy if the skill forces a specific language without explicit user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tests/test_generate_cover.py:9