Back to skill

Security audit

One-sentence video generation via chilltion

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Chilltion API wrapper for video generation and account checks, with expected credential and credit-spending implications.

Install only if you intend to use Chilltion and are comfortable providing a Chilltion API key. Keep CHILLTION_BASE_URL pointed at the official service unless you control the alternative, and confirm before creating video sessions or calling any unlisted API endpoint because those actions may expose account data or consume credits.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
77% confidence
Finding
The trigger list includes broad everyday phrases such as '做个视频', '生成视频', and 'create a video', which can cause the skill to activate in contexts where the user did not intend to use this specific third-party API. Mis-triggering is risky here because activation can lead to shell execution, outbound requests, and use of sensitive API credentials or billable actions.

Static analysis

No suspicious patterns detected.