Back to skill

Security audit

抖音民间诡异故事视频生成器

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it claims, but it handles account publishing and sends media through insecure FTP/HTTP paths that deserve review before installation.

Review this before installing. Only use it with non-sensitive stories and media, a dedicated low-privilege FTP account, and a Douyin account you are comfortable automating. Prefer replacing FTP/HTTP with HTTPS object storage or SFTP/FTPS, and require explicit confirmation before sending content to DashScope or publishing to Douyin.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate_videos.py:25
Finding

Plaintext FTP Credentials and Unencrypted Media Transport

Content
View full analysis
``` ### Technical Analysis The implementation uses `ftplib.FTP`, which does not encrypt authentication credentials, control commands, or uploaded files. Consequently, the FTP username and password and all generated images can be observed by an attacker with access to the network path. The documented retrieval URL uses unencrypted HTTP. There is no transport-level protection against interception or modification when the image-generation output is later retrieved for video generation. The implementation also does not verify file integrity after upload, apply access controls through short-lived signed URLs, or remove remote files after use. Environment variables prevent credentials from being hardcoded in source control, but they do not protect those credentials while FTP transmits them over the network. ### Attack Path 1. A user runs the video-generation workflow, causing generated images to be uploaded to the configured server. 2. The script connects to port 21 with standard FTP and transmits the configured username and password without encryption. 3. An attacke ...[truncated 1332 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The documented behavior and the declared description do not align: the skill references external configuration containing API keys/FTP/browser settings and implies external transfers and account automation that are not clearly disclosed in the top-level description. Behavior-description mismatch is dangerous because it hides data exfiltration and account-impacting operations behind a seemingly simple content-generation workflow, preventing informed user consent and security review.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill instructs the agent to write local files, invoke scripts that likely use networked model APIs, reference environment/config secrets, and automate browser-based publication, yet it declares no explicit tool scope or permission boundaries. This is dangerous because an agent may execute sensitive filesystem, network, and account-affecting actions without clear least-privilege constraints or user-visible authorization.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases include broad terms like 'AI视频制作' and similar generic requests that can overlap with ordinary conversation, increasing the chance the skill activates unintentionally. In this skill, accidental activation is more dangerous than usual because the workflow includes local file writes, external model/API calls, and potential publication steps tied to a real account.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill directs the system to save files locally, call external scripts/APIs, access configuration with secrets, use browser automation, and upload content to a platform account, but it does not clearly warn the user that these actions affect local data, transmit content externally, and can operate on their authenticated account. This is dangerous because users may provide story text or approve execution without understanding the privacy, cost, and account-integrity implications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script sends prompts to a third-party cloud image-generation API, and those prompts may be derived from user-provided story text. Without any explicit notice, consent flow, or data-handling warning, users may unknowingly transmit sensitive or personal content off-platform, creating a privacy and compliance risk rather than a memory-safety issue. The skill context increases concern because story inputs could contain personal anecdotes, private names, or sensitive folklore narratives that users may not expect to be shared with Alibaba Cloud services.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module docstring, runtime exceptions, status messages, and usage-related text are written in Chinese only, which imposes a specific language on users. The file does not offer a language/locale option or explain that the skill is intentionally restricted to a Chinese-speaking context.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script uploads local image assets to an FTP server before video generation, introducing an unnecessary external publication step for user-provided content. FTP is plaintext by default and the extra upload path broadens data exposure beyond local processing plus the stated downstream AI service, increasing risk of leakage of sensitive images and credentials in transit.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Publishing intermediate images to an FTP-accessible location is broader than what users would reasonably expect from a video-generation helper and creates an additional third-party distribution channel for input media. In this skill context, user inputs may be private story illustrations or custom assets, so silently exposing them externally increases confidentiality risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code sends local image content to an FTP server and then passes resulting URLs to an external video-generation API without any explicit warning or consent flow. This is dangerous because users may assume purely local processing or only direct Douyin publication, while their assets are actually transmitted to multiple remote services.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The function sends user-provided story text to a third-party cloud TTS service, which creates a real privacy and data-handling risk if the text contains personal, confidential, or regulated content. In this skill context, users may paste arbitrary story scripts and may not realize their input is being transmitted off-platform, so lack of disclosure and consent makes the issue more dangerous.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The request payload hard-codes language_type to Chinese, and the surrounding natural-language strings and docstrings indicate the skill is designed only in Chinese. This is a locale-policy concern because the skill enforces a specific language without presenting an opt-in, fallback, or documented justification for the restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file uses Chinese exclusively for headings and instructions, which can amount to a language/locale restriction if the broader skill environment does not explicitly require Chinese. The file does not provide an opt-in, alternative language, or justification that the skill is intended only for a Chinese-speaking or region-specific context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The natural-language descriptions and user-facing messages are entirely in Chinese, including setup/runtime guidance, without indicating that the skill is Chinese-only or offering a language choice. This can violate language/locale policy when a specific language is imposed without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The function creates the output directory and later saves downloaded MP4 files into it. Although saving output is part of the script's purpose, there is no explicit disclosure in the function docstring or startup messaging that files and directories will be created on disk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.