Back to skill

Security audit

可灵视频生成

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent Kling video API wrapper, but its shell script has unsafe parameter handling and an under-disclosed configurable API endpoint that can expose credentials.

Install only if you trust the publisher and runtime environment. Before use, review or patch the script to validate numeric options, restrict the API base URL to the intended HTTPS host, and avoid sending private prompts, internal URLs, confidential images, or sensitive videos unless you are comfortable sharing them with the configured provider.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate_video.sh:67
Finding

Command Injection Through Unvalidated Numeric Polling Parameters

Content
View full analysis
Remediation
View remediation
3600 )); then echo "Error: --poll-interval must be an integer between 1 and 3600" exit 1 fi if [[ ! "$TIMEOUT" =~ ^[0-9]+$ ]] || (( 10#$TIMEOUT < 1 || 10#$TIMEOUT > 86400 )); then echo "Error: --timeout must be an integer between 1 and 86400" exit 1 fi POLL_INTERVAL=$((10#$POLL_INTERVAL)) TIMEOUT=$((10#$TIMEOUT)) ``` Additional hardening should include: - Reject missing option values before accessing `$2`. - Apply strict allowlists to all enumerated parameters. - Avoid evaluating untrusted strings in arithmetic, conditional, or indirect-variable contexts. - Add negative tests containing arithmetic syntax, command substitutions, array expressions, whitespace, signs, and non-decimal prefixes. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate_video.sh:7
Finding

Bearer Credential Disclosure Through Unrestricted API Endpoint Override

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill invokes a shell script (scripts/generate_video.sh) but does not declare any tool scope, permissions, or allowed-tools boundaries. This creates unnecessary execution latitude for an agent runtime and weakens policy enforcement, making unintended shell execution or abuse of shell-capable behavior more likely if the skill is invoked in the wrong context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger description is broad enough that many general requests mentioning '可灵' or 'kling' and video generation/editing could activate the skill, even when the user did not clearly intend to run this shell-backed workflow. Because the skill performs networked media processing and can handle user-supplied URLs/Base64/video references, over-triggering increases the chance of unintended API usage, data handling, and shell-script execution in response to ambiguous prompts.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

This curl POST transmits user-controlled content and authentication credentials to an external network endpoint. In this skill, external transmission is expected for functionality, but it is still security-relevant because prompts, image/video references, and potentially sensitive internal resource URLs are sent off-box, and the endpoint is configurable via HSAI_BASE_URL.

Content

Scanner excerpt · scripts/generate_video.sh (reported line 158)May include surrounding context.

sh
[[ -n "$IMAGE" ]] && echo "  Image:   $IMAGE"
[[ -n "$VIDEO" ]] && echo "  Video:   $VIDEO ($VIDEO_REFER_TYPE)"

CREATE_RESP=$(curl -s -w "\n%{http_code}" \
  -X POST "${BASE_URL}${KLING_API_PATH}" \
  -H "$AUTH" \
  -H "Content-Type: application/json" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script sends the user's prompt and optional image/video references to a remote third-party API, but it provides no explicit consent prompt, warning, or data-handling notice before transmission. In an agent/skill context, users may assume local processing; this can expose sensitive prompts, internal URLs, or private media to an external service without informed approval.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.