Back to skill

Security audit

视频号拆解诊断助手

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly coherent for video analysis, but it needs review because it asks users to paste a paid API key into chat and saves it in plaintext.

Review this skill before installing. Use it only if you are comfortable sending selected videos and metadata to Mangu Cloud/related processing services, and avoid pasting valuable API keys into chat where possible. Prefer setting WM_API_KEY yourself through a local secret mechanism or environment variable, and delete or rotate the key if it was shared in conversation. Be aware that generated HTML reports can request the original cover image from finder.video.qq.com when viewed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (37)

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Content
---
name: 视频号拆解诊断助手
description: "基于曼格云 API 的视频号视频拆解。输入视频号分享链接或本地视频,两阶段产出:脚本采集作品元信息、互动数据与视觉深度拆解(镜头/运镜/转场/情绪/时间线/屏幕文字),再由 AI 注入深度分析层(受众画像、结构解读、爆款归因、爆款公式、六维评分、运营建议、总体评估),一键导出 Markdown / Excel / HTML 看板。"
metadata:
  slug: mglc-wx-video-decomposer
  version: v0.6.0
  author: WorkBuddy
  requires:
    bins:
      - python3
---

# 视频号拆解诊断助手

> 版本�
Confidence
80% confidence
Finding
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Ae1

High
Category
analysis-evasion
Content
基于曼格云 API 拆解微信视频号视频。支持两种输入:视频号分享链接,或本地视频文件。脚本 [scripts/analyze_wx_video.py](scripts/analyze_wx_video.py) 负责全部 HTTP 调用、ISAAC64 本机解密、报告渲染与多格式导出(Markdown / Excel /
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
基于曼格云 API 拆解微信视频号视频。支持两种输入:视频号分享链接,或本地视频文件。脚本 [scripts/analyze_wx_video.py](scripts/analyze_wx_video.py) 负责全部 HTTP 调用、ISAAC64 本机解密、报告渲染与多格式导出(Markdown / Excel /
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
基于曼格云 API 拆解微信视频号视频。支持两种输入:视频号分享链接,或本地视频文件。脚本 [scripts/analyze_wx_video.py](scripts/analyze_wx_video.py) 负责全部 HTTP 调用、ISAAC64 本机解密、报告渲染与多格式导出(Markdown / Excel /
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
基于曼格云 API 拆解微信视频号视频。支持两种输入:视频号分享链接,或本地视频文件。脚本 [scripts/analyze_wx_video.py](scripts/analyze_wx_video.py) 负责全部 HTTP 调用、ISAAC64 本机解密、报告渲染与多格式导出(Markdown / Excel /
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
基于曼格云 API 拆解微信视频号视频。支持两种输入:视频号分享链接,或本地视频文件。脚本 [scripts/analyze_wx_video.py](scripts/analyze_wx_video.py) 负责全部 HTTP 调用、ISAAC64 本机解密、报告渲染与多格式导出(Markdown / Excel /
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
基于曼格云 API 拆解微信视频号视频。支持两种输入:视频号分享链接,或本地视频文件。脚本 [scripts/analyze_wx_video.py](scripts/analyze_wx_video.py) 负责全部 HTTP 调用、ISAAC64 本机解密、报告渲染与多格式导出(Markdown / Excel /
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
基于曼格云 API 拆解微信视频号视频。支持两种输入:视频号分享链接,或本地视频文件。脚本 [scripts/analyze_wx_video.py](scripts/analyze_wx_video.py) 负责全部 HTTP 调用、ISAAC64 本机解密、报告渲染与多格式导出(Markdown / Excel /
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
基于曼格云 API 拆解微信视频号视频。支持两种输入:视频号分享链接,或本地视频文件。脚本 [scripts/analyze_wx_video.py](scripts/analyze_wx_video.py) 负责全部 HTTP 调用、ISAAC64 本机解密、报告渲染与多格式导出(Markdown / Excel /
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
基于曼格云 API 拆解微信视频号视频。支持两种输入:视频号分享链接,或本地视频文件。脚本 [scripts/analyze_wx_video.py](scripts/analyze_wx_video.py) 负责全部 HTTP 调用、ISAAC64 本机解密、报告渲染与多格式导出(Markdown / Excel /
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
基于曼格云 API 拆解微信视频号视频。支持两种输入:视频号分享链接,或本地视频文件。脚本 [scripts/analyze_wx_video.py](scripts/analyze_wx_video.py) 负责全部 HTTP 调用、ISAAC64 本机解密、报告渲染与多格式导出(Markdown / Excel /
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
基于曼格云 API 拆解微信视频号视频。支持两种输入:视频号分享链接,或本地视频文件。脚本 [scripts/analyze_wx_video.py](scripts/analyze_wx_video.py) 负责全部 HTTP 调用、ISAAC64 本机解密、报告渲染与多格式导出(Markdown / Excel /
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
基于曼格云 API 拆解微信视频号视频。支持两种输入:视频号分享链接,或本地视频文件。脚本 [scripts/analyze_wx_video.py](scripts/analyze_wx_video.py) 负责全部 HTTP 调用、ISAAC64 本机解密、报告渲染与多格式导出(Markdown / Excel /
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
基于曼格云 API 拆解微信视频号视频。支持两种输入:视频号分享链接,或本地视频文件。脚本 [scripts/analyze_wx_video.py](scripts/analyze_wx_video.py) 负责全部 HTTP 调用、ISAAC64 本机解密、报告渲染与多格式导出(Markdown / Excel /
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
基于曼格云 API 拆解微信视频号视频。支持两种输入:视频号分享链接,或本地视频文件。脚本 [scripts/analyze_wx_video.py](scripts/analyze_wx_video.py) 负责全部 HTTP 调用、ISAAC64 本机解密、报告渲染与多格式导出(Markdown / Excel /
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
基于曼格云 API 拆解微信视频号视频。支持两种输入:视频号分享链接,或本地视频文件。脚本 [scripts/analyze_wx_video.py](scripts/analyze_wx_video.py) 负责全部 HTTP 调用、ISAAC64 本机解密、报告渲染与多格式导出(Markdown / Excel /
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
基于曼格云 API 拆解微信视频号视频。支持两种输入:视频号分享链接,或本地视频文件。脚本 [scripts/analyze_wx_video.py](scripts/analyze_wx_video.py) 负责全部 HTTP 调用、ISAAC64 本机解密、报告渲染与多格式导出(Markdown / Excel /
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
基于曼格云 API 拆解微信视频号视频。支持两种输入:视频号分享链接,或本地视频文件。脚本 [scripts/analyze_wx_video.py](scripts/analyze_wx_video.py) 负责全部 HTTP 调用、ISAAC64 本机解密、报告渲染与多格式导出(Markdown / Excel /
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
基于曼格云 API 拆解微信视频号视频。支持两种输入:视频号分享链接,或本地视频文件。脚本 [scripts/analyze_wx_video.py](scripts/analyze_wx_video.py) 负责全部 HTTP 调用、ISAAC64 本机解密、报告渲染与多格式导出(Markdown / Excel /
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
基于曼格云 API 拆解微信视频号视频。支持两种输入:视频号分享链接,或本地视频文件。脚本 [scripts/analyze_wx_video.py](scripts/analyze_wx_video.py) 负责全部 HTTP 调用、ISAAC64 本机解密、报告渲染与多格式导出(Markdown / Excel /
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ssd 3

High
Confidence
99% confidence
Finding
The skill explicitly instructs the assistant to ask the user to paste an API key into chat and then store it in config.json. Collecting secrets through natural-language chat exposes credentials to conversation logs, model providers, transcript retention systems, and accidental disclosure, and then persists the secret locally without any described protection.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Content
{
  "schemaVersion": "1.0",
  "inputDesc": "https://weixin.qq.com/sph/Aepao1q3uS",
  "isLocal": false,
  "info": {
    "balance": 10011.744,
    "code": "OK",
    "consumption": 0.21,
    "data": {
      "accountAvatarUrl": "https://wx.qlogo.cn/finderhead/ver_1/gjMCBAbcUKJJVLRQjiaak8b86wfTYicXyq2d1ibmFN2Hxp7x3TwBYbria28pICDGiaa5j4KTic1UoaqWVYep03qje3LDrEAHc100gnQgF2tYtmvqyFJjUib3Wl3XdmY7UibEOUibia/132",
      "accountId": "v2_060000231003b20faec8c7e68110c7d2ca04eb36b0779fc6ba7a9c861641f285d0d15f05eff3@finder",
      "accountName": "果粒粒爱分享",
      "capabilities": {
        "decodeKey": true,
        "downloadable": true,
        "finderDetail": true,
        "mediaAddress": true,
        "metricPrecision": "exact",
        "preciseMetrics": true,
        "publicDetail": false,
        "shortUriToDynamicExportId": false,
Confidence
80% confidence
Finding
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Lp3

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding
The skill requests capabilities equivalent to reading environment variables, reading and writing local files, and making network calls, but it does not declare an explicit permission or allowed-tools boundary. That creates an overbroad, implicit trust model where an agent may exercise sensitive capabilities without a clear manifest-level restriction or user-visible scope review.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The markdown instructs the assistant to use a specific Chinese interaction style ("语气亲和自然") and all required guidance scripts are written only in Chinese, with no opt-in or alternative language path. This can violate language/locale policy because it constrains user-facing communication to one language without explicit user choice or documented regional justification.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The page loads a remote cover image from `finder.video.qq.com`, which causes the viewer's browser to make a direct request to a third-party host when the report is opened. That request can disclose IP address, user agent, access time, referrer context, and the existence of the report, which is more sensitive here because this skill generates analysis dashboards for user-supplied content and may be viewed in internal or private environments.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.