Back to skill

Security audit

HiAPI HappyHorse 1.0 Video

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but its installer and update flow create avoidable code-execution and credential-redirection risks.

Review this skill before installing. Prefer a pinned commit or trusted OpenClaw installation path, avoid running the npx GitHub installer with custom target paths, keep HIAPI_BASE_URL unset unless you fully trust the endpoint, and treat any printed update command as something to verify manually before running.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/lib/happyhorse-1-video.mjs:27
Finding

Arbitrary API endpoint can receive the HiAPI bearer credential

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/install.mjs:101
Finding

Shell command injection through the installer target path

Content
View full analysis
a.startsWith(prefix)); return hit ? hit.slice(prefix.length).replace(/^~(?=$|\/)/, homedir()) : null; } ``` ```js function installTo(target) { mkdirSync(target.dir, { recursive: true }); const destination = join(target.dir, SKILL_FOLDER); if (existsSync(destination)) { console.log(`[${DISPLAY_NAME}] ${destination} exists — replacing.`); rmSync(destination, { recursive: true, force: true }); } console.log(`[${DISPLAY_NAME}] Cloning into ${destination} …`); execSync(`git clone --depth 1 ${REPO_URL} "${destination}"`, { stdio: 'inherit' }); } ``` ### Technical Analysis The installation directory can originate from `--target`, `--skills-dir`, or `AGENT_SKILLS_DIR`. That value is incorporated into `destination` and interpolated into a command string passed to `execSync()`. `execSync()` executes string commands through a shell. Wrapping the destination in double quotes does not make it safe because a crafted path can contain a double quote followed by shell metacharacters. There is no escaping or validation that would prevent the value from terminating the quoted argument and adding another command. The preceding filesystem operations also use the attacker-controlled path, but the direct arbitrary-code-execution primitive is the shell interpolation at line 109. ### Attack Path 1. An attacker persuades the user or Agent to invoke the installer with a crafted `--target` or `--skills-dir` value, or controls `AGENT_SKILLS_DIR`. 2. The crafted path contains characters that close the quoted destination and append a shell command. 3. `flagValue()` returns the value without shell-safe validation. 4. `installTo()` builds a command such as `git clone ... "
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
scripts/lib/happyhorse-1-video.mjs:356
Finding

Unsigned remote manifest controls mandatory Agent-facing instructions

Content
View full analysis
controller.abort(), timeoutMs) : null; try { response = await fetchImpl(manifestUrl, { headers: { Accept: "application/json" }, signal: controller?.signal, }); } catch { return { status: "skipped" }; } finally { if (timer) clearTimeout(timer); } if (!response?.ok) return { status: "skipped" }; let manifest; try { manifest = await response.json(); } catch { return { status: "skipped" }; } const skill = Array.isArray(manifest.skills) ? manifest.skills.find((entry) => entry?.id === skillId) : null; const policy = skill?.updatePolicy; if (!policy) return { status: "current" }; const minimumVersion = policy.minimumVersion || skill.version || currentVersion; const latestVersion = policy.latestVersion || skill.version || minimumVersion; const updateCommand = policy.updateCommand || "npx -y github:HiAPIAI/hiapi-happyhorse-1-0-video-skill -y"; if (compareVersions(currentVersion, minimumVersion) < 0) { return { status: "required", message: [ policy.requiredNotice || "This HiAPI skill version is no longer compatible with the current HiAPI API.", `Installed version: ${curre ...[truncated 3345 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/lib/happyhorse-1-video.mjs:264
Finding

Unrestricted output URL fetching enables SSRF and unbounded resource consumption

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
scripts/install.mjs:11
Finding

Installer retrieves mutable unpinned code from a remote repository

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (42)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 95)May include surrounding context.

md
node scripts/check-config.mjs

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The README instructs users to execute npx -y github:HiAPIAI/hiapi-happyhorse-1-0-video-skill directly from GitHub without pinning a commit, tag, or package version. This creates a supply-chain risk: if the upstream repository is changed or compromised, future installs execute different code than was originally reviewed.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This line recommends running code from a GitHub repository via npx without a pinned version. Because the fetched installer can change over time, users and agents may execute unreviewed or malicious code if the repository or dependency chain is tampered with.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The installation command references a live GitHub source rather than a fixed version. In an agent-skill context, this is more dangerous because automated systems may execute the command non-interactively, amplifying supply-chain compromise impact.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

Using npx -y github:... against an unpinned repository allows silent code drift and possible execution of attacker-controlled updates. Since this README is an installation guide, the risk is actionable and not merely theoretical.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The command encourages users to run mutable remote code from GitHub. If the repository, account, or a transitive dependency is compromised, execution occurs at install time and may affect local agent skill directories or environment variables.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The auto-install prompt includes an unpinned npx -y github: command, which can cause an agent or user to execute whatever code is current in the repository at that moment. Embedding this in a copy-pasteable automation prompt raises exploitation likelihood.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The README's upgrade instruction again relies on an unpinned GitHub install command. Although framed as maintenance, it still exposes users to supply-chain compromise by pulling and executing the latest repo state during an upgrade.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The compatibility section recommends the same unpinned GitHub-based installer. Because this line targets Codex specifically, an AI-assisted environment may execute it automatically, increasing the operational risk of remote code execution from a compromised source.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This compatibility entry directs Claude Code users to execute an unpinned GitHub installer. The danger is the same supply-chain and remote code execution risk, with added concern that agent tooling may run it with access to user workspaces and secrets.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The OpenCode installation example also uses an unpinned npx -y github: source. Combined with an environment variable pointing to the skills directory, a compromised installer could write arbitrary skill content or modify agent behavior.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The generic 'Cursor / other' install command executes a mutable GitHub repository into a target directory. This is a true vulnerability because it normalizes running unaudited remote code in arbitrary local paths, which could be abused if the source changes maliciously.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The README instructs users to execute code directly from a GitHub repository via npx -y github:... without pinning a commit SHA, tag, or package version. This creates a supply-chain risk: if the upstream repository is compromised or its contents change, users may unknowingly execute attacker-controlled installation code.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.zh-CN.md (reported line 48)May include surrounding context.

安装脚本会自动检测 Codex(~/.codex/skills)和 Claude Code(~/.claude/skills)。如果两个都存在,-y 会同时装到两个目录。指定 Agent 或自定义目录:

bash
npx -y github:HiAPIAI/hiapi-happyhorse-1-0-video-skill --codex          # 只装到 ~/.codex/skills
npx -y github:HiAPIAI/hiapi-happyhorse-1-0-video-skill --claude         # 只装到 ~/.claude/skills
npx -y github:HiAPIAI/hiapi-happyhorse-1-0-video-skill --target=/path   # 自定义目录
AGENT_SKILLS_DIR=/path npx -y github:HiAPIAI/hiapi-happyhorse-1-0-video-skill -y

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

This command again tells users to run npx -y github:HiAPIAI/hiapi-happyhorse-1-0-video-skill --codex from an unpinned GitHub source. Because npx may fetch and execute the latest repository state, any malicious update or repo takeover could result in arbitrary code execution on the user's machine.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The install command for Claude uses the same unpinned npx -y github: pattern. In the context of an agent skill installer that writes into local skill directories, executing unreviewed latest code increases the blast radius to local files, agent behavior, and potentially secrets available in the shell environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

This custom target installation command still executes installer code from an unpinned GitHub repository. Because the script can write to an arbitrary target path, compromise of the upstream repo could allow file placement in sensitive directories chosen by the user.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The environment-variable form still uses npx -y github:... -y without version pinning, so it has the same supply-chain code execution risk. Since the command may run in a shell containing HIAPI_API_KEY or other credentials, a malicious installer could exfiltrate secrets.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The 'copy for your Agent' block instructs an agent or user to execute an unpinned GitHub npx command. Embedding this into agent-oriented automation makes it more dangerous because users may delegate execution without manually reviewing the fetched code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The FAQ's forced-update instruction tells users to rerun the same unpinned GitHub installer. This normalizes repeated execution of mutable remote code, increasing exposure over time and making compromise of the upstream repo especially impactful.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The Codex compatibility example again relies on direct execution from an unpinned GitHub source. In a security-sensitive developer environment, this can lead to arbitrary code execution with access to local repositories, credentials, and configuration files.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The Claude Code compatibility example repeats the same mutable remote execution pattern. Because this installs into agent skill directories, a malicious upstream change could both execute immediately and persist altered behavior in future agent sessions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The OpenCode compatibility example uses an environment-variable-directed install with unpinned GitHub execution. This combines mutable code execution with control over destination path, which could be abused to plant malicious files in user-selected locations if the upstream repo is compromised.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The generic 'other agents' example continues to recommend npx -y github: without pinning. Since it targets arbitrary skill directories across unknown agents, the unsafe pattern is broadly reusable and could impact many environments if exploited.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill instructs the agent to perform network-capable actions against external HiAPI endpoints, but it does not declare any explicit tool scope such as allowed-tools or permissions. This creates a mismatch between documented behavior and enforcement boundaries, increasing the risk that an agent runtime may allow broader-than-intended outbound access or execute the skill without clear authorization constraints.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access, suspicious.exposed_secret_literal

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/install.mjs:94

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/lib/happyhorse-1-video.mjs:27

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/lib/happyhorse-1-video.mjs:28