Back to skill

Security audit

HappyHorse 视频创作助手

Security checks for vulnerabilities and agentic risk

Overview

The skill is for video generation, but it includes and automatically uses an exposed API key and can submit external paid requests and write files without enough user control.

Install only after the exposed DashScope key is removed and rotated, the skill requires your own securely supplied API key, direct script execution cannot submit jobs without explicit confirmation, and downloads are restricted to trusted video URLs and safe output paths. Do not send private prompts or image URLs unless you are comfortable sharing them with Alibaba DashScope.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
happyhorse_video_creator.py:34
Finding

Hard-Coded DashScope API Credential in Documentation and Executable Code

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
happyhorse_video_creator.py:297
Finding

Direct Script Execution Automatically Submits an External Billable Task

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
happyhorse_video_creator.py:199
Finding

Unrestricted Video Download URL and Output Path

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose says the skill generates videos, but the content also embeds a hard-coded API credential and describes saving generated artifacts to the local filesystem without clearly declaring those behaviors. This mismatch reduces informed consent and hides sensitive capabilities that materially change the risk profile of the skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
100% confidence
Finding

The skill documentation includes a live-looking Alibaba DashScope API key directly in the file and in example Authorization headers. Exposed credentials can be copied and abused by anyone with access to the skill, leading to unauthorized API usage, billing fraud, quota exhaustion, and possible access to associated account resources.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill not only exposes a hard-coded API key but instructs the agent to use it as a default credential, without warning users that it is sensitive. This encourages insecure credential handling and normalizes redistribution of secrets, increasing the chance of unauthorized use and account compromise.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file embeds a default DashScope API key in source code and uses it automatically when no key is supplied. Hardcoded secrets are dangerous because they can be extracted by anyone with code access, abused for unauthorized API usage, billing fraud, and account compromise, and they encourage insecure secret distribution.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

A hardcoded API credential is used in outbound authenticated requests without secure handling or user disclosure. This creates an immediate secret-exposure risk and can let third parties impersonate the service account, consume paid resources, or access associated account capabilities.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill clearly documents network-capable behavior through direct HTTP requests to an external API, but it does not declare any tool scope such as permissions or allowed-tools. This weakens policy enforcement and user transparency, making it easier for the skill to perform outbound requests without explicit governance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The primary description fields are written only in Chinese, and the workflow text throughout the file is also exclusively Chinese. Under the language/locale policy, this is a violation unless the skill offers a language choice or clearly documents that it is intentionally restricted to a Chinese-speaking context, which it does not.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill asks users for prompts and image URLs and sends them to a third-party cloud API, but it does not clearly warn users that their content will leave the local environment. In a media-generation workflow, prompts and reference images may contain confidential or proprietary material, so lack of disclosure creates privacy and compliance risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 135)May include surrounding context.

} }

response = requests.post(url, headers=headers, json=payload, timeout=30) task_id = response.json()["output"]["task_id"]

text

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The module title and user-facing natural-language strings are written exclusively in Chinese, indicating a fixed language choice rather than offering locale selection. The file does not document that the language restriction is optional or region-specific, so it may violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · happyhorse_video_creator.py (reported line 101)May include surrounding context.

python
print(f"   提示词:{prompt[:50]}...")
        
        try:
            response = requests.post(VIDEO_ENDPOINT, headers=headers, json=payload, timeout=30)
            
            if response.status_code == 200:
                result = response.json()

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest says the skill generates videos using the HappyHorse model, including text-to-video and image-to-video modes. In addition to generation, the implementation retrieves the returned video URL and writes the video file under a local workspace directory, which is a broader behavior than the description states.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The download_video function fetches remote content and writes it to a local path under /root/.openclaw/workspace or a caller-supplied path. While it logs the destination path, there is no confirmation prompt or prior warning that the skill will create files on disk, which is a safety-relevant side effect for code handling user content.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.