Back to skill

Security audit

豆包视频创作助手

Security checks for vulnerabilities and agentic risk

Overview

This video-generation skill has a coherent purpose, but it exposes hardcoded credentials and includes unsafe publishing helpers that can push code to a fixed GitHub repository.

Review carefully before installing. Do not use the bundled credentials; assume they are compromised. Rotate any matching keys, remove the quick-publish helpers, avoid force-push instructions, and only store your own API key through a secure secret mechanism rather than plaintext project JSON.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (6)

T09 · Insecure Skill Coding Practices

Error
Location
doubao_video_creator.py:27
Finding

Multiple Hardcoded Service Credentials Exposed in Source and Documentation

Content
View full analysis

Vulnerability Details

File Locations:

  • doubao_video_creator.py:27-28
  • element_generator.py:19-20
  • SKILL.md:101-102
  • SKILL.md:166-177
  • project_template.json:19-21
  • CLAWHUB_PUBLISH_LOG.md:10
  • FINAL_PUBLISH_GUIDE.md:33
  • quick_push_github.sh:27-37
  • quick_push_github.sh:46-48

Vulnerability Type: Hardcoded API keys and access tokens
Risk Level: High

Evidence

doubao_video_creator.py:27-28:

python
# Default API key
DEFAULT_API_KEY = "65ae8f92-134c-4194-a3af-6e6cb74284e0"

element_generator.py:19-20:

python
# Configuration
API_KEY = "sk-d05aba5a2dae4453b97ed07fdb983e5a"

SKILL.md:101-102:

markdown
**API Key**: `65ae8f92-134c-4194-a3af-6e6cb74284e0`
**API Endpoint**: `https://ark.cn-beijing.volces.com/api/v3/contents/generations/tasks`

quick_push_github.sh:27-37:

bash
echo "💡 提示:首次推送需要输入 GitHub 凭证"
echo "   用户名:465367@qq.com"
echo "   密码/令牌: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"
echo ""

# 使用 GIT_ASKPASS 自动提供凭证
export GIT_ASKPASS=/bin/echo
export GIT_USERNAME="465367@qq.com"
export GIT_PASSWORD="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"

Technical Analysis

The project contains credential-shaped values for Volcengine, an image-generation service, GitHub, and ClawHub. These values are embedded in executable source, templates, documentation, logs, and shell scripts.

Secrets committed to a distributed package must be treated as compromised because every package recipient can extract them. Removing the current files does not remove the values from existing copies or version-control history. The GitHub token is additionally exported into the process environment and printed to the terminal, potentially exposing it through logs, captured terminal output, or process-inspection mechanisms available to the same user.

The credentials were not validated against their corresponding services during this s ...[truncated 1123 chars]

Remediation
View remediation

Remediation Suggestions

  1. Revoke and rotate every exposed credential immediately.
  2. Purge the values from Git history using an appropriate history-rewriting tool, then coordinate replacement clones with all contributors.
  3. Remove credentials from source files, documentation, templates, examples, logs, and shell scripts.
  4. Obtain credentials at runtime from an OS keyring, secret manager, or protected environment variable.
  5. Do not provide a functional default credential. Fail closed when no user-supplied credential is available.
  6. Add automated secret scanning to pre-commit and CI workflows.
  7. Restrict replacement credentials to the smallest possible service scopes, quotas, and expiration periods.
  8. Ensure logs and error messages redact authorization headers and token values.

T09 · Insecure Skill Coding Practices

Error
Location
config_manager.py:55
Finding

API Keys Persisted in Plaintext Without Restrictive File Permissions

Content
View full analysis

Vulnerability Details

File Locations:

  • config_manager.py:55-69
  • config_manager.py:193-200
  • SKILL.md:29-40
  • SKILL.md:166-177

Vulnerability Type: Insecure local secret storage
Risk Level: High

Evidence

config_manager.py:55-69:

python
def save_global_config(self, api_key: str, text_model: str, image_model: str):
    """保存全局配置"""
    config = {
        "default_api_key": api_key,
        "default_text_to_video_model": text_model,
        "default_image_to_video_model": image_model,
        "last_updated": datetime.now().isoformat(),
        "is_configured": True
    }

    os.makedirs(os.path.dirname(GLOBAL_CONFIG_PATH), exist_ok=True)
    with open(GLOBAL_CONFIG_PATH, 'w', encoding='utf-8') as f:
        json.dump(config, f, ensure_ascii=False, indent=2)

    self.global_config = config
    print(f"✅ 全局配置已保存:{GLOBAL_CONFIG_PATH}")

config_manager.py:193-200:

python
def set_api_config(self, api_key: str, text_model: str, image_model: str):
    """设置 API 配置"""
    self.data["api_config"] = {
        "api_key": api_key,
        "text_to_video_model": text_model,
        "image_to_video_model": image_model,
        "configured_at": datetime.now().isoformat()
    }
    self.save()

Technical Analysis

The global configuration saves the API key directly in JSON at /root/.openclaw/workspace/doubao-config.json. Project-level configuration can save another plaintext copy inside each project's project.json.

Files are created using the process's default mode subject to the current umask. The code does not explicitly enforce mode 0600, verify ownership, use atomic creation, or prevent symbolic-link replacement. The project-level duplication also broadens the number of files that must be protected and increases the likelihood of accidental publication or backup exposure.

Attack Path

  1. A user provides an API key during initia ...[truncated 778 chars]
Remediation
View remediation

Remediation Suggestions

  1. Store credentials in an OS keyring or dedicated secret manager rather than project JSON.
  2. Store only a secret reference or account identifier in ordinary configuration files.
  3. If file-based storage is unavoidable, create the file atomically with mode 0600, verify ownership, reject symbolic links, and retain only one copy.
  4. Separate non-sensitive project settings from authentication material.
  5. Add explicit ignore rules for generated configuration and project files, while recognizing that ignore rules are not a substitute for secure storage.
  6. Redact API keys from diagnostics and prohibit configuration files from being included in publishing scripts or archives.
  7. Provide a credential-deletion function that removes all global and project-level copies.

T05 · Unauthorized Access and Privilege Escalation

Error
Location
config_manager.py:107
Finding

Project Identifier Allows Filesystem Path Traversal

Content
View full analysis

Vulnerability Details

File Locations:

  • config_manager.py:107-112
  • config_manager.py:154-166
  • config_manager.py:300-307
  • video_project.py:309-315

Vulnerability Type: Path traversal enabling out-of-scope file access
Risk Level: High

Evidence

config_manager.py:107-112:

python
def __init__(self, project_id: str, theme: str = ""):
    self.project_id = project_id
    self.project_dir = f"{PROJECTS_DIR}/{project_id}"
    self.config_path = f"{self.project_dir}/project.json"

config_manager.py:154-166:

python
def _ensure_directories(self):
    """创建项目目录结构"""
    os.makedirs(self.project_dir, exist_ok=True)
    os.makedirs(f"{self.project_dir}/references", exist_ok=True)
    os.makedirs(f"{self.project_dir}/characters", exist_ok=True)
    os.makedirs(f"{self.project_dir}/scenes", exist_ok=True)
    os.makedirs(f"{self.project_dir}/objects", exist_ok=True)
    os.makedirs(f"{self.project_dir}/videos", exist_ok=True)

def load(self) -> bool:
    """加载项目配置"""
    if os.path.exists(self.config_path):
        try:
            with open(self.config_path, 'r', encoding='utf-8') as f:
                self.data = json.load(f)

video_project.py:309-315:

python
def load(self, project_id):
    """加载项目"""
    project_file = f"{PROJECT_DIR}/{project_id}/project.json"
    if os.path.exists(project_file):
        with open(project_file, "r", encoding="utf-8") as f:
            data = json.load(f)
            self.__dict__.update(data)
            return True
    return False

Technical Analysis

project_id is interpolated directly into filesystem paths. No allowlist validation, canonicalization, or containment check is performed.

A value containing traversal components such as ../ can cause the resolved path to escape /root/.openclaw/workspace/doubao-video-projects. Project construction creates directories outside the int ...[truncated 1487 chars]

Remediation
View remediation

Remediation Suggestions

  1. Generate project IDs internally whenever possible.
  2. If external project IDs are required, enforce a strict allowlist such as ^[A-Za-z0-9_-]{1,64}$.
  3. Construct paths with pathlib.Path, resolve both the root and candidate path, and reject candidates not contained beneath the resolved root.
  4. Reject absolute paths, path separators, traversal components, null bytes, and platform-specific alternate separators.
  5. Open project directories and files using secure, no-follow semantics where supported to reduce symbolic-link attacks.
  6. Replace unrestricted self.__dict__.update(data) with explicit assignment of validated fields.
  7. Validate loaded JSON against a strict schema before applying it to an object.
  8. Add tests covering ../, absolute paths, symbolic links, Unicode separator variants, and overlong identifiers.

T09 · Insecure Skill Coding Practices

Error
Location
quick_push_github.sh:10
Finding

Publishing Helper Force-Pushes to a Hardcoded Remote Repository

Content
View full analysis

Vulnerability Details

File Location: quick_push_github.sh:10-37
Vulnerability Type: Destructive and unauthorized publishing behavior
Risk Level: High

Evidence

bash
cd /root/.openclaw/workspace/skills/doubao-video-creator

# 设置远程仓库
echo "📍 设置远程仓库..."
git remote remove origin 2>/dev/null || true
git remote add origin https://github.com/465367/doubao-video-creator.git
echo "✅ 远程仓库已设置"
echo ""

# 确保分支名为 main
echo "🔄 设置分支名..."
git branch -M main 2>/dev/null || true
echo "✅ 分支已设置为 main"
echo ""

# 推送代码
echo "📤 推送代码到 GitHub..."
echo "💡 提示:首次推送需要输入 GitHub 凭证"
echo "   用户名:465367@qq.com"
echo "   密码/令牌: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"
echo ""

# 使用 GIT_ASKPASS 自动提供凭证
export GIT_ASKPASS=/bin/echo
export GIT_USERNAME="465367@qq.com"
export GIT_PASSWORD="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"

git push -u origin main --force

Technical Analysis

The helper removes any existing origin, replaces it with a fixed repository owned by a hardcoded account, renames the current branch, and executes a force push.

These operations are not limited to the core video-generation functionality. They can publish all tracked repository content, including accidentally committed credentials or private materials. The --force option can overwrite remote branch history and remove commits that are not present locally.

The operation lacks destination confirmation, content review, secret scanning, branch protection awareness, and a non-destructive default.

Attack Path

  1. A user runs the advertised quick-publish helper.
  2. The script changes to a fixed workspace repository.
  3. The existing origin remote is removed without preserving its value.
  4. A hardcoded repository is installed as the new remote.
  5. The local branch is renamed to main.
  6. The script force-pushes all tracked content using the exposed credential.
  7. Existing remote history may be overwr ...[truncated 465 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the embedded username and token.
  2. Remove --force and use a normal push by default.
  3. Never delete or replace an existing remote without explicit confirmation.
  4. Require the user to supply and confirm the destination repository.
  5. Display the exact remote, branch, and commit range before publishing.
  6. Use Git's standard credential manager or an authenticated GitHub CLI session.
  7. Run secret scanning and show the staged file list before any push.
  8. Respect branch protection and use pull requests for updates to existing repositories.
  9. Add a dry-run mode and require a separate confirmation for any history-rewriting operation.

T08 · Insecure Dependencies

Error
Location
element_generator.py:96
Finding

Execution of an Untracked External Workspace Script

Content
View full analysis

Vulnerability Details

File Locations:

  • element_generator.py:19-20
  • element_generator.py:96-106
  • SKILL.md:158-162

Vulnerability Type: Unverified external code execution dependency
Risk Level: High

Evidence

element_generator.py:19-20:

python
# Configuration
API_KEY = "sk-d05aba5a2dae4453b97ed07fdb983e5a"
WANXIANG_SCRIPT = "/root/.openclaw/workspace/wanxiang_generate.py"

element_generator.py:96-106:

python
try:
    # 调用 wanxiang_generate.py 脚本
    result = subprocess.run(
        ["python3", WANXIANG_SCRIPT, prompt, output_path],
        capture_output=True,
        text=True,
        timeout=60
    )

Technical Analysis

The Skill executes /root/.openclaw/workspace/wanxiang_generate.py, but that script is not included in the audited project. Its content, provenance, version, ownership, and integrity therefore cannot be verified as part of this package.

The subprocess uses an argument array and does not invoke a shell, so the shown call does not directly expose shell-command injection through prompt. The security issue is instead the external executable trust boundary: whatever Python code exists at the fixed path is executed with the Agent process's privileges.

A writable shared workspace further increases the risk if another package, user, or process can create or replace that file.

Attack Path

  1. An attacker obtains write access to /root/.openclaw/workspace/wanxiang_generate.py, or places the file before the legitimate dependency is installed.
  2. The attacker inserts arbitrary Python code into that file.
  3. A user invokes character, scene, or object image generation.
  4. element_generator.py launches the external script using python3.
  5. The attacker-controlled code executes with the filesystem, network, and credential access available to the Agent process.

Impact Assessment

Successful exploitation provides arbitrar ...[truncated 364 chars]

Remediation
View remediation

Remediation Suggestions

  1. Include the required implementation in the reviewed package or use a version-pinned, trusted dependency.
  2. Verify the dependency's cryptographic digest before execution.
  3. Validate that the file is a regular file owned by the expected account and is not writable by untrusted users.
  4. Reject symbolic links and paths outside a dedicated, permission-restricted installation directory.
  5. Run the image-generation component in a sandbox with minimal filesystem and network access.
  6. Pass credentials through a narrowly scoped secret channel rather than leaving them in source or the general environment.
  7. Document the exact dependency version and installation source.
  8. Preserve the argument-array subprocess invocation and continue avoiding shell=True.

T09 · Insecure Skill Coding Practices

Warning
Location
doubao_video_creator.py:289
Finding

Direct Module Execution Automatically Attempts a Paid Remote Generation Task

Content
View full analysis

Vulnerability Details

File Location: doubao_video_creator.py:289-308
Vulnerability Type: Unconfirmed external side effect and API quota consumption
Risk Level: Medium

Evidence

python
def main():
    """测试函数"""
    creator = DoubaoVideoCreator()

    # 测试文生视频
    prompt = "一只可爱的小猫在草地上玩耍,阳光明媚,微风吹拂,高清写实风格"
    success, video_path = creator.generate_scene(prompt, duration=10, scene_id=1)

    if success:
        print(f"\n🎉 视频生成成功!")
        print(f"   路径:{video_path}")
    else:
        print(f"\n❌ 视频生成失败")


if __name__ == "__main__":
    main()

The invoked workflow ultimately performs the following authenticated request at doubao_video_creator.py:90-98:

python
try:
    response = requests.post(url, headers=headers, json=payload, timeout=30)

Technical Analysis

Executing the module as a program immediately enters a test routine that attempts to create a remote video-generation task. There is no explicit --submit option, interactive confirmation, cost warning, or dry-run mode.

Because the constructor falls back to the hardcoded default API key, an operator can trigger remote quota consumption merely by executing the file for testing or inspection. This behavior conflicts with the documented workflow's emphasis on confirming prompts before generation.

The current implementation also references self.base_url without initializing that attribute, which may prevent the request from succeeding in its present form. That reliability defect does not make the automatic network side effect safe; correcting the attribute would expose the paid operation immediately.

Attack Path

  1. A user or automated system executes python3 doubao_video_creator.py.
  2. main() creates a generator using the default credential.
  3. The fixed sample prompt is passed into generate_scene.
  4. The workflow attempts to submit an authenticated generation request.
  5. If the re ...[truncated 485 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the active network test with a non-networking example or unit test using mocked requests.
  2. Require an explicit command-line option such as --submit.
  3. Display the endpoint, model, duration, and estimated cost before submission.
  4. Require interactive confirmation unless a separately documented non-interactive flag is provided.
  5. Remove the embedded default API key and fail when no securely supplied credential is available.
  6. Add configurable per-run task and spending limits.
  7. Separate task creation from polling and downloading so each external side effect is visible and controllable.
  8. Correct initialization of the base URL only after the confirmation and credential controls are implemented.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (95)

Natural-Language Policy Violations

Critical
Category
Not specified by scanner
Confidence
100% confidence
Finding

A hard-coded GitHub personal access token appears directly in natural-language instructions, which is a direct secret disclosure. Because this is a repo publishing guide, the skill context materially increases risk: the file is likely to be stored, copied, or published alongside the project, making accidental broad exposure highly likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The document contains a live-looking bearer token directly in a login command, which exposes a credential to anyone who can read the file, logs, or repository history. If valid, an attacker could authenticate to the ClawHub account, publish or modify packages, impersonate the owner, or access associated private resources.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The document contains and instructs the use of a plaintext GitHub personal access token, which is a sensitive credential that should never be embedded in documentation. Anyone who can read this file can reuse the token to access the associated GitHub account or repositories, enabling unauthorized code access, tampering, or repository takeover depending on token scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This guide exposes a GitHub credential and explicitly tells the reader to enter it during authentication, without any warning that the value is secret or any safer handling instructions. In a publishing guide, this context makes the issue more dangerous because the document is meant to be followed and potentially shared, increasing the chance of credential compromise and reuse.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The guide instructs a reader to use a plaintext embedded personal access token during a GitHub push workflow. This is dangerous because the token can be harvested by any reader of the file and abused for unauthorized repository actions, and the surrounding context of public GitHub publication amplifies the likelihood of exposure.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · GITHUB_PUBLISH_GUIDE.md (reported line 208)May include surrounding context.

解决:

bash
# Ubuntu/Debian
curl -fsSL https://cli.github.com/packages/githubcli-archive-keyring.gpg | sudo dd of=/usr/share/keyrings/githubcli-archive-keyring.gpg
echo "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/githubcli-archive-keyring.gpg] https://cli.github.com/packages stable main" | sudo tee /etc/apt/sources.list.d/github-cli.list > /dev/null
sudo apt update
sudo apt install gh -y

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · GITHUB_PUBLISH_GUIDE.md (reported line 209)May include surrounding context.

解决:

bash
# Ubuntu/Debian
curl -fsSL https://cli.github.com/packages/githubcli-archive-keyring.gpg | sudo dd of=/usr/share/keyrings/githubcli-archive-keyring.gpg
echo "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/githubcli-archive-keyring.gpg] https://cli.github.com/packages stable main" | sudo tee /etc/apt/sources.list.d/github-cli.list > /dev/null
sudo apt update
sudo apt install gh -y

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · GITHUB_PUBLISH_GUIDE.md (reported line 208)May include surrounding context.

解决:

bash
# Ubuntu/Debian
curl -fsSL https://cli.github.com/packages/githubcli-archive-keyring.gpg | sudo dd of=/usr/share/keyrings/githubcli-archive-keyring.gpg
echo "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/githubcli-archive-keyring.gpg] https://cli.github.com/packages stable main" | sudo tee /etc/apt/sources.list.d/github-cli.list > /dev/null
sudo apt update
sudo apt install gh -y

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · GITHUB_PUBLISH_GUIDE.md (reported line 209)May include surrounding context.

解决:

bash
# Ubuntu/Debian
curl -fsSL https://cli.github.com/packages/githubcli-archive-keyring.gpg | sudo dd of=/usr/share/keyrings/githubcli-archive-keyring.gpg
echo "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/githubcli-archive-keyring.gpg] https://cli.github.com/packages stable main" | sudo tee /etc/apt/sources.list.d/github-cli.list > /dev/null
sudo apt update
sudo apt install gh -y

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

git push -u origin main --force is a destructive parameter choice because it can overwrite remote branch history and discard commits on the server. In a troubleshooting section, this kind of copy-pasteable command is dangerous even without malicious intent, especially if used by less experienced users or in shared repositories.

Content

Scanner excerpt · GITHUB_PUBLISH_GUIDE.md (reported line 242)May include surrounding context.

git remote add origin https://github.com/YOUR_USERNAME/doubao-video-creator.git

强制推送(谨慎使用)

git push -u origin main --force

text

## 🎊 总结

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The sample conversation instructs the user to paste an API key directly into chat and then confirms that it is saved. This normalizes credential exposure in conversational transcripts and persistent config files, making theft more likely through chat logging, screenshots, shared terminals, shell history, or later data export.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill asks the user to supply their own API key, but elsewhere embeds and persists a default hard-coded credential. Hard-coded secrets can be abused by anyone who reads the skill, and the mismatch between the UX and implementation increases the chance that a shared or unintended credential is used for billable external actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill solicits an API key and says the configuration will be saved, but gives no warning about storage, scope, plaintext persistence, or who can later access the credential. Collecting secrets without transparent handling guidance creates a substantial risk of credential exposure, account misuse, and unexpected billing.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script hardcodes a GitHub username and personal access token, prints them to the terminal, and exports them as environment variables for authentication. Embedded credentials are a severe secret-exposure issue and can enable unauthorized access, repository compromise, token reuse, and credential theft from logs, shell history, screenshots, or process inspection.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script explicitly instructs the user to enter a specific GitHub username and token, disclosing credentials in plaintext. This encourages unsafe credential handling and makes accidental leakage via terminal logs, shared sessions, recordings, and support transcripts highly likely.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script stores the GitHub username and token in environment variables and repeats them again in failure output, multiplying exposure points. This creates a broad secret-leak surface through process environments, terminal capture, crash logs, and copied troubleshooting steps.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

The use of git push -u origin main --force is a dangerous tool invocation because it performs a destructive remote update with no validation of repository ownership, branch safety, or user intent. In this skill, that risk is heightened by the preceding remote rewrite and embedded credentials, enabling immediate unauthorized or unintended repository modification.

Content

Scanner excerpt · quick_push_github.sh (reported line 38)May include surrounding context.

sh
export GIT_USERNAME="465367@qq.com"
export GIT_PASSWORD="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"

git push -u origin main --force 2>&1 || {
    echo ""
    echo "⚠️  自动推送失败,请手动输入凭证"
    echo ""

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SEEDANCE_ANALYSIS.md (reported line 230)May include surrounding context.

md
请回复 **A** 或 **B** 选择生成方式 📝"""
        
        return prompt
    
    def process_generation_choice(self, scene_id: int, choice: str) -> Tuple[bool, str]:
        """

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · config_manager.py (reported line 107)May include surrounding context.

python
请回复 **A** 或 **B** 选择生成方式 📝"""
        
        return prompt
    
    def process_generation_choice(self, scene_id: int, choice: str) -> Tuple[bool, str]:
        """

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · prompt_generator.py (reported line 191)May include surrounding context.

python
请回复 **A** 或 **B** 选择生成方式 📝"""
        
        return prompt
    
    def process_generation_choice(self, scene_id: int, choice: str) -> Tuple[bool, str]:
        """

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scene_confirmation.py (reported line 44)May include surrounding context.

python
请回复 **A** 或 **B** 选择生成方式 📝"""
        
        return prompt
    
    def process_generation_choice(self, scene_id: int, choice: str) -> Tuple[bool, str]:
        """

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scene_confirmation.py (reported line 105)May include surrounding context.

python
请回复 **A** 或 **B** 选择生成方式 📝"""
        
        return prompt
    
    def process_generation_choice(self, scene_id: int, choice: str) -> Tuple[bool, str]:
        """

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scene_confirmation.py (reported line 173)May include surrounding context.

python
请回复 **A** 或 **B** 选择生成方式 📝"""
        
        return prompt
    
    def process_generation_choice(self, scene_id: int, choice: str) -> Tuple[bool, str]:
        """

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scene_confirmation.py (reported line 224)May include surrounding context.

python
请回复 **A** 或 **B** 选择生成方式 📝"""
        
        return prompt
    
    def process_generation_choice(self, scene_id: int, choice: str) -> Tuple[bool, str]:
        """

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown guidance and all sample interactions are written only in Chinese, with no indication that users may choose another language or locale. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
doubao_video_creator.py:28

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
element_generator.py:20

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
FINAL_PUBLISH_GUIDE.md:33

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
quick_push_github.sh:36

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
UPDATE_v1.1.md:179