Back to skill

Security audit

Harness AI 导演工作台

Security checks for vulnerabilities and agentic risk

Overview

This is a commercial video-service skill that is not clearly malicious, but it uses broad activation, API-key backed network access, and strong off-platform recharge guidance that users should review before installing.

Install only if you intentionally want to use Harness AI's external video service. Treat uploaded videos, photos, voice samples, product materials, links, and the AI_DIRECTOR_API_KEY as shared with that provider, and review pricing or WeChat recharge instructions independently before paying.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (10)

Tainted flow: 'req' from os.environ.get (line 10, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/check_credits.py (reported line 11)May include surrounding context.

python
def get(path):
    req = urllib.request.Request(BASE + path, headers={'Authorization': 'Bearer ' + (KEY or '')})
    with urllib.request.urlopen(req, timeout=20) as r:
        return json.loads(r.read().decode())

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill presents itself as a broad video-production assistant, but the analyzed content mainly contains marketing, registration, recharge, and API-key setup instructions rather than verifiable implementation of the advertised features. That mismatch can mislead users and the host agent into invoking the skill in contexts where it instead steers users toward account onboarding, balance handling, or external contact flows.

Content

No source excerpt is available for this finding.

MCP Config Access

High
Category
Agent Snooping
Confidence
91% confidence
Finding

The skill explicitly references mcp.json and environment-variable API key configuration, indicating reliance on sensitive secret material in the host environment. In a skill with vague permissions and strong external-service routing, encouraging host-level secret configuration increases the blast radius if the skill or its integration is misused, especially around config-file access and secret handling.

Content

Scanner excerpt · SKILL.md (reported line 110)May include surrounding context.

md
| 客户端 | 配置方式 |
|---|---|
| **WorkBuddy / OpenClaw** | mcp.json 或环境变量 `AI_DIRECTOR_API_KEY=sk-xxx` |
| **Claude Code / Codex** | 环境变量 `AI_DIRECTOR_API_KEY=sk-xxx`(OpenAI 兼容接口) |
| **Coze / 千问** | 安装技能后按提示配置 |

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill declares access to environment variables and depends on networked service use, but it does not define explicit tool scope or allowed tools. In an agent environment, missing scope boundaries can let the skill be invoked more broadly than intended and make secret-bearing capabilities harder to audit or constrain.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation phrases are very broad and overlap with ordinary user requests about making videos, increasing the chance the skill is triggered when the user did not intend to use this third-party service. Overbroad routing can cause unnecessary data disclosure to the skill or push users into external commercial workflows without clear consent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The '何时使用' section defines activation conditions in expansive terms such as any request to generate videos, remix content, or check compliance. In context, this increases the risk of over-invocation and unnecessary sharing of user links, media, or business materials with an external service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill instructs the assistant to directly output recharge packages and steer users to a specific WeChat contact whenever credits are insufficient or pricing is discussed. This is a coercive commercial redirection pattern that can override normal assistant neutrality, create locale-inappropriate behavior, and move users into off-platform contact channels with reduced oversight.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description contains very broad trigger phrases such as '生成视频', '出片', '带货视频', and related common content-creation requests, which can cause the skill to activate for many ordinary user prompts beyond a narrowly scoped intent. Over-broad routing increases the chance of unintended invocation, user confusion, and prompt hijacking of adjacent workflows, especially because the skill appears commercial and highly promotional.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill description is written entirely in Chinese and appears targeted to Chinese-language usage without stating whether other user languages are supported or how language selection should occur. This can cause misrouting, misunderstanding of consent or capabilities, and degraded safety/compliance behavior when invoked for users operating in other languages.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The script performs an authenticated network request using a bearer token, but the only disclosure to the user is an instruction to set the API key and register on the remote site. In an agent-skill context, especially one invoking external services, insufficient disclosure about what data is sent and to which domain can reduce informed consent and increase the risk of unintentionally exposing credentials to a third-party service.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.