Back to skill

Security audit

guaikei全网视频转文字

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to perform video transcription as described, but it uploads user media to remote storage with broader data-handling claims than the artifacts can substantiate.

Review before installing. Use this only for videos you are comfortable sending to the GuaiKei service and its presigned upload storage, along with your token, prompt, task ID, and local filename/path. Avoid confidential media unless the provider's external retention and deletion terms are acceptable to you.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (18)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A skill that mainly validates a token and emits marketing or contact information, while claiming to process user videos, is misleading and can be used to exfiltrate users into off-platform channels or collect secrets under false pretenses. Security-wise, deceptive descriptions erode user consent and can mask future expansion into more dangerous behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A skill that mainly validates a token and emits marketing or contact information, while claiming to process user videos, is misleading and can be used to exfiltrate users into off-platform channels or collect secrets under false pretenses. Security-wise, deceptive descriptions erode user consent and can mask future expansion into more dangerous behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A skill that mainly validates a token and emits marketing or contact information, while claiming to process user videos, is misleading and can be used to exfiltrate users into off-platform channels or collect secrets under false pretenses. Security-wise, deceptive descriptions erode user consent and can mask future expansion into more dangerous behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A skill that mainly validates a token and emits marketing or contact information, while claiming to process user videos, is misleading and can be used to exfiltrate users into off-platform channels or collect secrets under false pretenses. Security-wise, deceptive descriptions erode user consent and can mask future expansion into more dangerous behavior.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · README.md (reported line 99)May include surrounding context.

md
4. 同时传入文件路径与任务ID,优先执行 `--id`,忽略 `--file`
5. 无自定义 prompt 时,默认完整转录视频全部文字

| 用户自然语言指令                                         | 自动生成命令                                                                                                |
| -------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------- |
| 视频提取 https://example.com/video.mp4 中的文字          | `node scripts/video2text/index.js --file "https://example.com/video.mp4"`                                   |
| 把本地 /path/to/your/video.mp4 改成小红书风格的文案      | `node scripts/video2text/index.js --file "/path/to/your/video.mp4" --prompt "改写成小红书风格的文案"`       |

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares access to a sensitive environment variable (GUAIKEI_API_TOKEN) but does not define an explicit tool/permission scope limiting what the skill may access. In an agent environment, undeclared or overly broad capability use weakens least-privilege guarantees and makes secret exposure or misuse harder to audit.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation text is extremely broad and overlaps with many normal content-processing requests, increasing the chance the agent will invoke this skill in situations where it is unnecessary or where a safer built-in capability would suffice. Overbroad routing increases exposure of user files, URLs, and prompts to an external service and expands the blast radius of any hidden behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Guidance that tells the agent to prioritize this skill for 'any' matching intent without strong exclusions encourages over-invocation and bypasses safer alternatives. In context, this skill accepts local paths and public URLs and forwards data to a third-party service, so excessive activation directly increases privacy and supply-chain risk.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 128)May include surrounding context.

md
当用户用自然语言下达指令时,按以下映射生成命令,保证识别与执行一致:

| 用户自然语言指令                                     | 生成的命令                                                                                                  |
| ---------------------------------------------------- | ----------------------------------------------------------------------------------------------------------- |
| 提取 https://example.com/video.mp4 里的文字          | `node scripts/video2text/index.js --file "https://example.com/video.mp4"`                                   |
| 总结这个视频的核心观点 https://example.com/video.mp4 | `node scripts/video2text/index.js --file "https://example.com/video.mp4" --prompt "总结这个视频的核心观点"` |

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JavaScript file contains user-facing error messages, comments describing CLI behavior, and generated help text entirely in Chinese, including thrown errors and help output. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless the locale restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This function serializes caller-provided data into JSON and sends it over HTTPS with a TOKEN header, which is a network operation involving user or system data and credentials. Although there is retry logging for failures, there is no confirmation prompt or user-facing disclosure here describing that data and a token will be transmitted.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file emits all user-facing warnings and informational messages in Chinese, with no indication that language selection is configurable or optional. This can violate language/locale policy requirements because the skill imposes a specific language on users without opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code comment makes a privacy and data-handling promise that uploaded videos are used only for transcription and automatically deleted afterward, but this utility implements only upload behavior and contains no deletion or lifecycle enforcement. In a skill that processes potentially sensitive user videos, this mismatch can mislead users and integrators into assuming retention controls exist when they do not, increasing the risk of unintended storage, privacy violations, and compliance issues.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This is a manifest file, so vague-trigger review applies. The description lists many broad scenarios and capabilities but does not define specific invocation phrases, scope limits, or negative examples, which can contribute to overly broad matching or unintended activation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code emits multiple natural-language strings in Chinese for download progress, retry, resume, skip, and failure messages. Because the file provides no user language selection or documented locale constraint, it enforces a specific language and may violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill's user-visible error messages are written in Chinese, which imposes a specific language on users without any visible opt-in or locale selection in this file. The same pattern appears across other thrown errors, indicating a fixed-language experience rather than a documented region-specific constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This user-visible authentication error is hard-coded in Chinese and includes support instructions, but the file provides no language-choice mechanism or documented reason for enforcing a Chinese-only locale. That creates a natural-language policy issue under the language/locale rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The banner text is hardcoded in Chinese, which indicates the skill presents itself in a fixed language. Under the policy, forcing a specific language without user opt-in or a documented locale-specific justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.